arXiv:2608. 05548v1 Announce Type: cross Abstract: Modern vehicles rely on the Controller Area Network (CAN) bus, whose design prioritizes low cost and real-time performance but provides no message authentication or encryption.
By Chandan Hegde, Mukundh R Reddy
SPADE is a labelled, multi‑modal, simulation‑based dataset for detecting attacks on Signal Phase and Timing (SPaT) messages from the perspective of connected vehicles. It contains 1.89 million timestep records generated by injecting six classes of application‑layer attacks and one benign class into the SAE J2735 SPaT protocol, across multiple intersection geometries, operating conditions, and random seeds. Each record fuses SPaT fields, onboard camera confidence scores, and cooperative V2V peer data into 40 features, enabling deep‑learning intrusion detection systems to distinguish deliberate attacks from environmental noise.
The paper introduces SPADE, a labelled, multi‑modal dataset for detecting attacks on Signal Phase and Timing (SPaT) messages from the perspective of connected vehicles. Generated via Eclipse MOSAIC, SPADE includes 1.89 million timestep records across six attack classes and one benign class, combining SPaT fields, camera confidence scores, and V2V peer data over 40 features. The dataset, along with generation code and scenario configurations, is publicly released on GitHub to enable reproducible deep‑learning intrusion detection research in C‑V2X security.
By James Di Novo, Hany Ragab, Sylvain P. Leblanc
Existing automotive intrusion detection systems (IDSs) for the Controller Area Network (CAN) largely target discrepancies in message timing, frequency, or sequencing and cannot detect attacks that pre...
The paper presents a digital‑twin (DT) based intrusion detection system (IDS) for vehicle powertrain CAN bus traffic, modeling physical relationships among decoded signals to detect payload‑manipulation attacks that preserve normal timing and sequencing. Using a shared‑encoder LSTM trained on 17 Hyundai/Kia CAN signals, the DT flags anomalies when residuals exceed a threshold, achieving high detection rates (up to 94.6%) for stealthy attacks such as continuous drift and masquerade, while a range‑and‑plausibility baseline fails to detect them. The study demonstrates that learning coupled vehicle dynamics enables detection of payload‑level attacks that evade traditional timing‑based IDSs, though false positives remain a challenge.
By Araf Rahman, M Sabbir Salek, Mashrur Chowdhury
arXiv:2606. 18599v1 Announce Type: cross Abstract: The Controller Area Network (CAN) protocol is the primary communication standard for Electronic Control Units (ECUs) in modern vehicles, but its lack of encryption and authentication exposes it to a range of security threats.
By Qiqi Liu, Runhan Song, Lei Cui, Heng Zhang, Yuyan Sun, Limin Sun
arXiv:2608. 01454v1 Announce Type: cross Abstract: Provenance-based intrusion detection systems (PIDS) frequently report strong performance, but the conclusions drawn from these results can be highly sensitive to benchmarking choices and evaluation protocols.
By Lorenzo Guerra, Thomas Chapuis, Guillaume Duc, Pavlo Mozharovskyi, Van-Tam Nguyen
arXiv:2609.36039v1 Announce Type: cross
Abstract: Machine learning (ML) and deep learning (DL) have dominated Intrusion Detection System (IDS) research in recent years. Unfortunately, many existing s...
By Yufeng Xin, Bryant Goseland, Mohamed Rahouti
arXiv:2606. 28625v1 Announce Type: cross Abstract: Connected Vehicles (CVs) rely extensively on communication technologies to enable data-driven predictive analyses for enhancing performance and safety.
By Mohammad Imtiaz Hasan, Abyad Enan, Jean Michel Tine, Araf Rahman, M Sabbir Salek, Mashrur Chowdhury
JEV-IDS is an open experimental general network intrusion detection system that uses the Jev System One Model to detect zero‑day intrusions even when labeled data are scarce. The system processes one flow per request and asks the model two questions: a binary attack probability and a finite‑choice traffic category. In tests on a 300‑flow NSL‑KDD pilot split, JEV-IDS achieved an F1‑score of 0.859, precision of 0.941, recall of 0.790, and a novel‑attack recall of 0.838, while being 4.8 times faster and 3.8 times cheaper than GPT‑5.6 Luna and producing 15 times fewer false alarms than a low‑data Random Forest.
By Paulo Severo, Silvio E. Quincozes, Amanda Dias
arXiv:2606. 05844v1 Announce Type: cross Abstract: Rule-based Intrusion Detection and Prevention Systems (IDPS) offer precise attack detection as well as mitigation, however their manually crafted, signature-driven rules limit adaptability to emerging and zero-day threats.
By Hassan Jalil Hadi, Rehana Yasmin, Ali Shoker
arXiv:2606. 11098v1 Announce Type: cross Abstract: Recent deep learning approaches for network intrusion detection increasingly incorporate temporal architectures such as recurrent networks and Transformers, often reporting near-perfect performance on CIC-IDS2017.
By Zach Moczkodan (Royal Military College of Canada, Kingston, Canada), Hany Ragab (Royal Military College of Canada, Kingston, Canada)