高级搜索

留言板

尊敬的读者、作者、审稿人, 关于本刊的投稿、审稿、编辑和出版的任何问题, 您可以本页添加留言。我们将尽快给您答复。谢谢您的支持!

姓名
邮箱
手机号码
标题
留言内容
验证码

融合时序图重参数化的车载网轻量级入侵检测方法

王凯 刘恒旸 王佰玲

王凯, 刘恒旸, 王佰玲. 融合时序图重参数化的车载网轻量级入侵检测方法[J]. 电子与信息学报. doi: 10.11999/JEIT260403
引用本文: 王凯, 刘恒旸, 王佰玲. 融合时序图重参数化的车载网轻量级入侵检测方法[J]. 电子与信息学报. doi: 10.11999/JEIT260403
WANG Kai, LIU Hengyang, WANG Bailing. RepCAN: A Lightweight Intrusion Detection Method for In-Vehicle Networks Integrating Temporal Graph Re-parameterization[J]. Journal of Electronics & Information Technology. doi: 10.11999/JEIT260403
Citation: WANG Kai, LIU Hengyang, WANG Bailing. RepCAN: A Lightweight Intrusion Detection Method for In-Vehicle Networks Integrating Temporal Graph Re-parameterization[J]. Journal of Electronics & Information Technology. doi: 10.11999/JEIT260403

融合时序图重参数化的车载网轻量级入侵检测方法

doi: 10.11999/JEIT260403 cstr: 32379.14.JEIT260403
基金项目: 国家自然科学基金(62272129),山东省泰山学者人才计划项目(tsqn202408112)
详细信息
    作者简介:

    王凯:男,教授、博士生导师,研究方向为网络与人工智能安全, dr.wangkai@hit.edu.cn

    刘恒旸:女,硕士生,研究方向为车载网络安全, hengyang_liu@163.com

    王佰玲:男,教授、博士生导师,研究方向为信息内容安全, wbl@hit.edu.cn

    通讯作者:

    王凯 dr.wangkai@hit.edu.cn (通信和一作均需唯一)

  • 中图分类号: TP393.081; TP183

RepCAN: A Lightweight Intrusion Detection Method for In-Vehicle Networks Integrating Temporal Graph Re-parameterization

Funds: The National Natural Science Foundation of China(62272129), Taishan Scholar Foundation of Shandong Province, China (tsqn202408112)
  • 摘要: 随着智能网联汽车(ICV)的快速普及,原本封闭的车载网(IVN)与外部环境的交互日益频繁,面临消息注入、语义操纵等诸多外部恶意攻击风险。该文提出了一种融合时序图重参数化的车载网轻量级入侵检测技术(RepCAN) ,通过 “ 幽灵节点 ” 机制与架构无损变换,实现了高泛化检测能力与低资源占用的均衡。具体而言,该技术首先在图构建阶段将攻击引发的突发流量或时序偏差统一映射至幽灵节点,并结合实时流量统计特征生成动态连接权重,使得模型在保留静态通信拓扑先验的同时对节点间的动态关联过程进行建模,从而提升对复杂通信模式变化的表达能力;其次,利用结构重参数化技术构建了 “ 训练态多分支、推理态单路径 ” 的模型架构,大幅降低了边缘端的访存成本与推理延迟。在 Car-Hacking Dataset 上的实验结果表明, RepCAN在攻击下的整体区分能力 AUC (判别阈值无关)高达0.9942,且单条报文推理延迟低至 0.004827 ms。以1 Mbps满载车载网通信环境为基准,该延迟远低于单条报文的最短物理传输时间极限(约为0.1–0.15 ms),有效避免了与核心驾驶任务的算力争夺,具备良好的实车部署潜力。
  • 图  1  RepCAN整体架构图

    图  2  基于NVIDIA Jetson Orin Nano的TW-T206车载计算设备(实拍)

    图  3  不同模型推理时间

    图  4  不同模型运行内存

    1  幽灵节点构建与动态路由

     输入:正常训练集CAN ID集合$ {\boldsymbol{I}}_{\text{known}} $;时间片$ {\boldsymbol{S}}_{t}=\left\{\left({c}_{i},{\tau }_{i},{p}_{i}\right)\right\}_{i=1}^{W} $
     输出:节点特征矩阵$ {\boldsymbol{X}}^{t} $和动态邻接矩阵$ \boldsymbol{A}_{\text{dynamic}}^{t} $
     1: 保留节点$ {v}_{0} $作为幽灵节点,为合法ID $ c\in {\boldsymbol{I}}_{\text{known}} $分配编号$ r\left(c\right)\in \{1{,}2,\cdots ,N\} $;
     2: 初始化消息桶$ \boldsymbol{B}_{v}^{t}=\varnothing $与转移集合$ D_{uv}^{t}=\varnothing $, $ \forall u,v $;
     3: for $ i=1 $ to $ W $ do
     4: $ {v}_{i}\leftarrow \left({c}_{i}\in {\boldsymbol{I}}_{\text{known}}\right)?r\left({c}_{i}\right)\colon 0; $ //ID $ {v}_{0} $
     5: 将报文$ \left({c}_{i},{\tau }_{i},{p}_{i}\right) $加入$ \boldsymbol{B}_{{v}_{i}}^{t} $;
     6: if $ i> 1 $ then 将 $ {\tau }_{i}-{\tau }_{i-1} $ 加入$ D_{{v}_{i-1},{v}_{i}}^{t} $;
     7: end
     8: for $ v=0 $ to $ N $ do $ \boldsymbol{x}_{v}^{t}=\left[H_{v}^{t},\mu _{\Delta\tau ,v}^{t},\sigma _{\Delta \tau ,v}^{t},\rho _{v}^{t},d_{v}^{t},w_{v}^{t}\right] $;
     9: for 每个节点对$ (u,v) $ do $ A_{uv}^{t}\leftarrow \left(D_{uv}^{t}\neq \varnothing \right)?\dfrac{|D_{uv}^{t}|}{\text{mean}\left(D_{uv}^{t}\right)+\text{std}\left(D_{uv}^{t}\right)+\epsilon }\colon 0 $;
     10: return $ {\boldsymbol{X}}^{t}=\left[\boldsymbol{x}_{0}^{t},\ldots ,\boldsymbol{x}_{N}^{t}\right] $ 和 $ \boldsymbol{A}_{\text{dynamic}}^{t} $;
    下载: 导出CSV

    表  1  Car-Hacking数据集的分布

    类型正常样本数攻击样本数攻击占比样本总数
    Normal98898700988987
    DoS30782505875210.163665771
    Fuzzy33470134918470.133838860
    Gear38458905972520.134443142
    RPM39668056548970.144621702
    下载: 导出CSV

    表  2  RepCAN与各方法的对比结果

    类型方法AccuracyPrecisionAUCF1RecallFPR
    监督G-IDCS0.92690.87590.92590.87350.87110.1450
    RF0.97330.98070.94630.93030.82080.0033
    MLP0.93140.92220.83170.77820.67310.0094
    LSTM0.94150.75210.95120.80550.86720.0000
    EfficientNet0.06880.25260.96260.10180.80150.1868
    MobileNet0.28150.24740.98510.24740.84850.1865
    CANet0.90500.64470.99420.73470.97250.0727
    无监督DAGMM0.94170.00000.50000.00000.00000.0000
    MSFlow0.93640.50920.59100.53440.56210.0000
    MTGFlow0.68480.52390.63980.51910.51440.0075
    DCdetector0.78550.34630.61420.36090.54980.1362
    TFMAE0.76060.31040.75870.39870.55720.2056
    RepCAN(Ours)0.98400.98230.99420.97980.97740.0117
    下载: 导出CSV

    表  3  带有特征消融变体的详细性能比较

    特征变体AccuracyPrecisionAUCF1RecallFPR
    RepCAN(Ours)0.98400.98230.99420.97980.97740.0117
    STAT-only0.96240.96570.98550.95210.93890.0221
    Phys-only0.95390.97800.94230.93990.90460.0135
    下载: 导出CSV

    表  4  RepCAN 架构组件的消融研究

    模块架构变体攻击类型AccuracyPrecisionAUCF1RecallFPR
    完整模型RepCAN(Ours)-0.98400.98230.99420.97980.97740.0117
    节点表示w/o Ghost NodeDoS0.98340.98290.99370.97340.96400.0077
    Fuzzy0.89240.92930.85070.83170.75270.0313
    Gear0.98420.99470.99040.98190.96930.0040
    RPM0.87590.90910.93310.85820.81270.0698
    Overall0.91810.95650.93760.89020.83240.0251
    图结构w/o Dual-Stream-0.77520.75280.79410.69720.64930.1413
    重参数化Conv (K=3)-0.88450.89230.94230.84780.80750.0646
    Conv (K=5)-0.83820.87630.83760.77320.61980.0647
    下载: 导出CSV

    表  5  模型推理效率与资源消耗对比

    评估指标多路训练单路推理降幅(%)
    参数量(M)0.42940.1540↓64.15
    FLOPs(M)2.78241.1318↓59.32
    存储占用(MB)1.70040.6013↓64.64
    内存占用(MB)2.05400.8982↓56.27
    下载: 导出CSV

    表  6  重参数化前后输出一致性与误差评估

    攻击类型样本数深层特征平均绝对误差异常得分训练态AUC推理态AUC$ \Delta \text{AUC} $
    DoS1466215.33×10–44.15×10–30.976460.976581.23×10–4
    Fuzzy1535457.52×10–44.15×10–30.963770.963847.43×10–5
    Gear1777167.00×10–43.70×10–30.931550.930896.59×10–4
    RPM1848599.02×10–44.09×10–30.990900.990932.48×10–5
    Overall6627417.31×10–44.01×10–3---
    下载: 导出CSV

    表  7  RepCAN在ROAD数据集Masquerade Attack下的定量评估结果

    评估子项攻击场景AccuracyAUCF1
    correlated_signal_attack多相关信号协同篡改0.36480.79910.0000
    max_engine_coolant_temp_attack动力系统传感信号超限篡改0.23930.64030.0000
    max_speedometer_attack车载仪表感知信号篡改0.29660.94470.0068
    reverse_light_off_attack执行器信号强制关闭0.75630.63630.0000
    reverse_light_on_attack执行器虚假触发0.48600.75780.0011
    Overall-0.52370.76800.0015
    下载: 导出CSV
  • [1] 韩乔妮, 马建国, 李鹏, 等. 混合网络攻击下车辆队列的无模型自适应弹性控制[J]. 电子与信息学报, 2026, 48(5): 2066–2076. doi: 10.11999/JEIT251135.

    HAN Qiaoni, MA Jianguo, LI Peng, et al. Model-free adaptive resilient control of vehicle platoons against hybrid cyberattacks[J]. Journal of Electronics & Information Technology, 2026, 48(5): 2066–2076. doi: 10.11999/JEIT251135.
    [2] WANG Kai, ZHANG Aiheng, SUN Haoran, et al. Analysis of recent deep-learning-based intrusion detection methods for in-vehicle network[J]. IEEE Transactions on Intelligent Transportation Systems, 2023, 24(2): 1843–1854. doi: 10.1109/TITS.2022.3222486.
    [3] YING Xuhang, SAGONG S U, CLARK A, et al. Shape of the cloak: Formal analysis of clock skew-based intrusion detection system in controller area networks[J]. IEEE Transactions on Information Forensics and Security, 2019, 14(9): 2300–2314. doi: 10.1109/TIFS.2019.2895957.
    [4] MÜTER M and ASAJ N. Entropy-based anomaly detection for in-vehicle networks[C]. 2011 IEEE Intelligent Vehicles Symposium (IV), Baden-Baden, Germany, 2011: 1110–1115. doi: 10.1109/IVS.2011.5940552.
    [5] CHO K T and SHIN K G. Fingerprinting electronic control units for vehicle intrusion detection[C]. Proceedings of the 25th USENIX Conference on Security Symposium, Austin, USA, 2016: 911–927.
    [6] GROZA B and MURVAY P S. Efficient intrusion detection with bloom filtering in controller area networks[J]. IEEE Transactions on Information Forensics and Security, 2019, 14(4): 1037–1051. doi: 10.1109/TIFS.2018.2869351.
    [7] 张瑞丰, 杨荣妮. 拒绝服务攻击下信息物理系统的数据驱动安全控制: 一种在线模态依赖的切换-Q-学习策略[J]. 电子与信息学报, 2026, 48(4): 1424–1433. doi: 10.11999/JEIT250746.

    ZHANG Ruifeng and YANG Rongni. Data-driven secure control for cyber-physical systems under denial-of-service attacks: An online mode-dependent switching-Q-learning algorithm[J]. Journal of Electronics & Information Technology, 2026, 48(4): 1424–1433. doi: 10.11999/JEIT250746.
    [8] XIE Guoqi, YANG L T, YANG Yuanda, et al. Threat analysis for automotive CAN networks: A GAN model-based intrusion detection technique[J]. IEEE Transactions on Intelligent Transportation Systems, 2021, 22(7): 4467–4477. doi: 10.1109/TITS.2021.3055351.
    [9] MCHERGUI A, MOULAHI T, and ZEADALLY S. Survey on artificial intelligence (AI) techniques for vehicular ad-hoc networks (VANETs)[J]. Vehicular Communications, 2022, 34: 100403. doi: 10.1016/j.vehcom.2021.100403.
    [10] RAJAPAKSHA S, KALUTARAGE H, AL-KADRI M O, et al. AI-based intrusion detection systems for in-vehicle networks: A survey[J]. ACM Computing Surveys, 2023, 55(11): 237. doi: 10.1145/3570954.
    [11] LAMPE B and MENG Weizhi. A survey of deep learning-based intrusion detection in automotive applications[J]. Expert Systems with Applications, 2023, 221: 119771. doi: 10.1016/j.eswa.2023.119771.
    [12] AL-AQL N and AL-SHAMMARI A. Hybrid RNN-LSTM networks for enhanced intrusion detection in vehicle CAN systems[J]. Journal of Electrical Systems, 2024, 20(6s): 3019–3031. doi: 10.52783/jes.3318.
    [13] XU He, WU Di, LU Yufeng, et al. Models on the move: Towards feasible embedded AI for intrusion detection on vehicular CAN bus[C]. Proceedings of the 2024 USENIX Conference on Usenix Annual Technical Conference, Santa Clara, USA, 2024: 64.
    [14] HOSSAIN M D, INOUE H, OCHIAI H, et al. An effective in-vehicle CAN bus intrusion detection system using CNN deep learning approach[C]. GLOBECOM 2020-2020 IEEE Global Communications Conference, Taipei, China, 2020: 1–6. doi: 10.1109/GLOBECOM42002.2020.9322395.
    [15] JAVED A R, UR REHMAN S, KHAN M U, et al. CANintelliIDS: Detecting in-vehicle intrusion attacks on a controller area network using CNN and attention-based GRU[J]. IEEE Transactions on Network Science and Engineering, 2021, 8(2): 1456–1466. doi: 10.1109/TNSE.2021.3059881.
    [16] ZHANG Hengrun, ZENG Kai, and LIN Shuai. Federated graph neural network for fast anomaly detection in controller area networks[J]. IEEE Transactions on Information Forensics and Security, 2023, 18: 1566–1579. doi: 10.1109/TIFS.2023.3240291.
    [17] HE Yaru, GAO Jiaqi, FAN Mingrui, et al. A&D graph-based graph neural network intrusion detection for in-vehicle controller area network[C]. 2024 IEEE/CIC International Conference on Communications in China (ICCC), Hangzhou, China, 2024: 1281–1286. doi: 10.1109/ICCC62479.2024.10681772.
    [18] ALKHATIB N, MUSHTAQ M, GHAUCH H, et al. CAN-BERT do it? Controller area network intrusion detection system based on BERT language model[C]. 2022 IEEE/ACS 19th International Conference on Computer Systems and Applications (AICCSA), Abu Dhabi, United Arab Emirates, 2022: 1–8. doi: 10.1109/AICCSA56895.2022.10017800.
    [19] WU Zhongqiang and LI Mengting. ResNet-Swin Transformer based intrusion detection system for in-vehicle network[J]. Expert Systems with Applications, 2025, 279: 127547. doi: 10.1016/j.eswa.2025.127547.
    [20] 谈名名, 张恒, 王鑫, 等. 一种融合时序与深度特征的二阶段CAN总线攻击识别方法[J]. 电子与信息学报, 2026, 48(4): 1444–1453. doi: 10.11999/JEIT250651.

    TAN Mingming, ZHANG Heng, WANG Xin, et al. A two-stage framework for CAN bus attack detection by fusing temporal and deep features[J]. Journal of Electronics & Information Technology, 2026, 48(4): 1444–1453. doi: 10.11999/JEIT250651.
    [21] WANG Yingqing, QIN Guihe, ZOU Mi, et al. A lightweight intrusion detection system for internet of vehicles based on transfer learning and MobileNetV2 with hyper-parameter optimization[J]. Multimedia Tools and Applications, 2024, 83(8): 22347–22369. doi: 10.1007/s11042-023-15771-6.
    [22] WANG Shaoqiang, WANG Yizhe, ZHENG Baosen, et al. Intrusion detection system for vehicular networks based on MobileNetV3[J]. IEEE Access, 2024, 12: 106285–106302. doi: 10.1109/ACCESS.2024.3437416.
    [23] JEONG S, LEE S, LEE H, et al. X-CANIDS: Signal-aware explainable intrusion detection system for controller area network-based in-vehicle network[J]. IEEE Transactions on Vehicular Technology, 2024, 73(3): 3230–3246. doi: 10.1109/TVT.2023.3327275.
    [24] WANG Kai, JIANG Qiguang, WANG Bailing, et al. StatGraph: Effective in-vehicle intrusion detection via multi-view statistical graph learning[J]. IEEE Transactions on Mobile Computing, 2026, 25(5): 6335–6351. doi: 10.1109/TMC.2025.3636517.
    [25] ZHANG Aiheng, SUN Zhen, JIANG Qiguang, et al. LiPar: A lightweight parallel learning model for practical in-vehicle network intrusion detection[J]. IEEE Transactions on Intelligent Transportation Systems, 2025, 26(12): 23358–23373. doi: 10.1109/TITS.2025.3605465.
    [26] JIANG Qiguang, WANG Kai, WEI Yuliang, et al. XIPHOS: Adaptive in-vehicle intrusion detection via unsupervised graph contrastive learning[J]. IEEE Transactions on Information Forensics and Security, 2025, 20: 10419–10433. doi: 10.1109/TIFS.2025.3616624.
    [27] LI Sifan, CAO Yue, ZHANG Yu’ang, et al. A cloud collaborative-based intrusion detection and prevention system for IVN[J]. IEEE Transactions on Cognitive Communications and Networking, 2025, 11(4): 2768–2785. doi: 10.1109/TCCN.2024.3516052.
    [28] ALTHUNAYYAN M, JAVED A, and RANA O. A robust multi-stage intrusion detection system for in-vehicle network security using hierarchical federated learning[J]. Vehicular Communications, 2024, 49: 100837. doi: 10.1016/j.vehcom.2024.100837.
    [29] CAO Jinhui, DI Xiaoqiang, LIU Xu, et al. Anomaly detection for in-vehicle network using self-supervised learning with vehicle-cloud collaboration update[J]. IEEE Transactions on Intelligent Transportation Systems, 2024, 25(7): 7454–7466. doi: 10.1109/TITS.2024.3351438.
    [30] DING Xiaohan, ZHANG Xiangyu, MA Ningning, et al. RepVGG: Making VGG-style ConvNets great again[C]. Proceedings of the 2021 IEEE/CVF Conference on Computer Vision and Pattern Recognition (CVPR), Nashville, USA, 2021: 13728–13737. doi: 10.1109/CVPR46437.2021.01352.
    [31] WANG Junyi, LI Zi’ao, LIU Bangli, et al. High-performance inference graph convolutional networks for skeleton-based action recognition[J]. Neurocomputing, 2025, 653: 131078. doi: 10.1016/j.neucom.2025.131078.
    [32] RUFF L, VANDERMEULEN R A, GÖRNITZ N, et al. Deep one-class classification[C]. Proceedings of the 35th International Conference on Machine Learning, Stockholm, Sweden, 2018: 4393–4402.
    [33] DENG Zhouyan, XUN Yijie, LIU Jiajia, et al. A novel intrusion detection system for next generation in-vehicle networks[C]. GLOBECOM 2022-2022 IEEE Global Communications Conference, Rio de Janeiro, Brazil, 2022: 2098–2103. doi: 10.1109/GLOBECOM48099.2022.10000766.
    [34] SONG H M, WOO J, and KIM H K. In-vehicle network intrusion detection using deep convolutional neural network[J]. Vehicular Communications, 2020, 21: 100198. doi: 10.1016/j.vehcom.2019.100198.
    [35] SONG Jiaru, QIN Guihe, LIANG Yanhua, et al. DGIDS: Dynamic graph-based intrusion detection system for CAN[J]. Computers & Security, 2024, 147: 104076. doi: 10.1016/j.cose.2024.104076.
    [36] KALKAN S C and SAHINGOZ O K. In-vehicle intrusion detection system on controller area network with machine learning models[C]. 2020 11th International Conference on Computing, Communication and Networking Technologies (ICCCNT), Kharagpur, India, 2020: 1–6. doi: 10.1109/ICCCNT49239.2020.9225442.
    [37] GOLOVKO V and VAITSEKHOVICH L. Neural network approaches for intrusion detection and recognition[J]. International Journal of Computing, 2014, 5(3): 118–125. doi: 10.47839/ijc.5.3.416.
    [38] BERGER I, RIEKE R, KOLOMEETS M, et al. Comparative study of machine learning methods for in-vehicle intrusion detection[C]. ESORICS 2018 International Workshops Computer Security, Barcelona, Spain, 2018: 85–101. doi: 10.1007/978-3-030-12786-2_6.
    [39] TAN Mingxing and LE Q. EfficientNet: Rethinking model scaling for convolutional neural networks[C]. Proceedings of the 36th International Conference on Machine Learning, Long Beach, USA, 2019: 6105–6114.
    [40] HOWARD A, SANDLER M, CHEN Bo, et al. Searching for MobileNetV3[C]. Proceedings of the 2019 IEEE/CVF International Conference on Computer Vision (ICCV), Seoul, Korea (South), 2019: 1314–1324. doi: 10.1109/ICCV.2019.00140.
    [41] HANSELMANN M, STRAUSS T, DORMANN K, et al. CANet: An unsupervised intrusion detection system for high dimensional CAN bus data[J]. IEEE Access, 2020, 8: 58194–58205. doi: 10.1109/ACCESS.2020.2982544.
    [42] ZONG Bo, SONG Qi, MIN M R, et al. Deep autoencoding gaussian mixture model for unsupervised anomaly detection[C]. 6th International Conference on Learning Representations, Vancouver, Canada, 2018.
    [43] ZHOU Yixuan, XU Xing, SONG Jingkuan, et al. MSFlow: Multiscale flow-based framework for unsupervised anomaly detection[J]. IEEE Transactions on Neural Networks and Learning Systems, 2025, 36(2): 2437–2450. doi: 10.1109/TNNLS.2023.3344118.
    [44] ZHOU Qihang, HE Shibo, LIU Haoyu, et al. Label-free multivariate time series anomaly detection[J]. IEEE Transactions on Knowledge and Data Engineering, 2024, 36(7): 3166–3179. doi: 10.1109/TKDE.2024.3349613.
    [45] YANG Yiyuan, ZHANG Chaoli, ZHOU Tian, et al. DCdetector: Dual attention contrastive representation learning for time series anomaly detection[C]. Proceedings of the 29th ACM SIGKDD Conference on Knowledge Discovery and Data Mining, Long Beach, USA, 2023: 3033–3045.
    [46] FANG Yuchen, XIE Jiandong, ZHAO Yan, et al. Temporal-frequency masked autoencoders for time series anomaly detection[C]. 2024 IEEE 40th International Conference on Data Engineering (ICDE), Utrecht, Netherlands, 2024: 1228–1241. doi: 10.1109/ICDE60146.2024.00099.
    [47] 苗金钊, 刘金良, 孙乐, 等. 基于虚假数据检测的信息物理系统安全学习控制方法[J]. 电子与信息学报, 2026, 48(4): 1434–1443. doi: 10.11999/JEIT250537.

    MIAO Jinzhao, LIU Jinliang, SUN Le, et al. A learning-based security control method for cyber-physical systems based on false data detection[J]. Journal of Electronics & Information Technology, 2026, 48(4): 1434–1443. doi: 10.11999/JEIT250537.
  • 加载中
图(4) / 表(8)
计量
  • 文章访问数:  11
  • HTML全文浏览量:  1
  • PDF下载量:  0
  • 被引次数: 0
出版历程
  • 收稿日期:  2026-04-07
  • 修回日期:  2026-09-17
  • 录用日期:  2026-09-17
  • 网络出版日期:  2026-09-24

目录

    /

    返回文章
    返回