Adversarial Robustness of Intrusion Detection Systems for the In-Vehicle Networks of Connected and Autonomous Vehicles
No Thumbnail Available
Date
2026
Authors
Journal Title
Journal ISSN
Volume Title
Publisher
Saudi Digital Library
Abstract
Connected and autonomous vehicles (CAVs) rely on machine learning (ML)-based intrusion
detection systems (IDSs) to secure in-vehicle network (IVN) communications. However, ML
models are inherently vulnerable to adversarial attacks. While prior adversarial research in
CAVs has predominantly focused on perception models, particularly object detection, the
robustness of IVN-based IDSs remains largely underexplored. This thesis addresses this gap
by investigating the adversarial robustness of IVN-based IDSs, introducing an IVN-specific
threat taxonomy, and developing an attack method capable of generating adversarial IVN
frames under varying levels of attacker knowledge of the deployed IDS model. Experimental
results demonstrate that adversarial manipulation poses a severe threat to IVN-based IDSs.
Under complete attacker knowledge of the deployed IDS model, detection performance drops
from an F1-score of 99%toaslowas19%, withattacksuccess rates reaching up to 89%. Even
under limited knowledge, detection performance decreases from 95% to 38%, with success
rates of up to 60%. To mitigate these vulnerabilities, this thesis proposes Explainability
guided Counterfactual Adversarial Training (EXCAT), a novel defense mechanism that
leverages model explainability to generate more representative adversarial training examples.
EXCAT restores detection performance to up to 94% and reduces attack success rates to as
low as 7.55%, demonstrating that explainability-guided training offers a promising direction
for strengthening IVN-based IDS robustness and improving the safety of deployed CAV
systems.
Description
Keywords
Connected and autonomous vehicles, Cybersecurity, Adversarial machine learning, Artificial intelligence, Intrusion Detection Systems
