CANTransfer: Transfer learning based intrusion detection on a controller area network using convolutional LSTM network

Research output: Chapter in Book/Report/Conference proceedingConference contributionpeer-review

108 Scopus citations

Abstract

In-vehicle communications, due to simplicity and reliability, a Controller Area Network (CAN) bus is widely used as the de facto standard to provide serial communications between Electronic Control Units (ECUs). However, prior research exhibits several network-level attacks can be easily performed and exploited in the CAN bus. Additionally, new types of intrusion attacks are discovered very frequently. However, unless we have a large amount of data about an intrusion, developing an efficient deep neural network-based detection mechanism is not easy. To address this challenge, we propose CANTransfer, an intrusion detection method using Transfer Learning for CAN bus, where a Convolutional LSTM based model is trained using known intrusion to detect new attacks. By applying one-shot learning, the model can be adaptable to detect new intrusions with a limited amount of new datasets. We performed extensive experimentation and achieved a performance gain of 26.60% over the best baseline model for detecting new intrusions.

Original languageEnglish
Title of host publication35th Annual ACM Symposium on Applied Computing, SAC 2020
PublisherAssociation for Computing Machinery
Pages1048-1055
Number of pages8
ISBN (Electronic)9781450368667
DOIs
StatePublished - 30 Mar 2020
Event35th Annual ACM Symposium on Applied Computing, SAC 2020 - Brno, Czech Republic
Duration: 30 Mar 20203 Apr 2020

Publication series

NameProceedings of the ACM Symposium on Applied Computing

Conference

Conference35th Annual ACM Symposium on Applied Computing, SAC 2020
Country/TerritoryCzech Republic
CityBrno
Period30/03/203/04/20

Keywords

  • Controller area network
  • Convolutional LSTM
  • In-vehicle network
  • Intrusion detection
  • Transfer learning

Fingerprint

Dive into the research topics of 'CANTransfer: Transfer learning based intrusion detection on a controller area network using convolutional LSTM network'. Together they form a unique fingerprint.

Cite this