Electronic Thesis/Dissertation
 

Real-time Lightweight Intrusion Detection System for In-Vehicle Network

Open Access Deposited

The evolution of automotive technology has seen a rapid shift towards highly connected and autonomous vehicles, which rely heavily on intricate intra-vehicle networks. This network, primarily managed by the Controller Area Network (CAN) bus, coordinates communication among numerous electronic control units (ECUs) that control various functions within the vehicle. Despite its widespread use and efficiency, the CAN bus protocol lacks fundamental security features, making it vulnerable to cyberattacks that can lead to unauthorized control and disruption of vehicle systems.This praxis presents the development and evaluation of a real-time, lightweight Intrusion Detection System (IDS) specifically designed for in-vehicle networks. The primary focus is creating a solution that not only detects and classifies malicious activities with high accuracy but also meets the stringent real-time and resource constraints typical of automotive environments. Unlike previous studies that primarily focus on detection accuracy, this research also emphasizes detection time, which must be less than two milliseconds to be considered real-time (Avatefipour et al., 2019) , and model size, which should be under 1MB to be considered lightweight in this context (Rolfsmeier et al., 2003) to ensure the IDS can be practically deployed within the limited computational resources of a vehicle. The research utilizes the Car-Hacking Dataset, a comprehensive compilation of normal and attack data generated from CAN bus traffic, to train and evaluate the IDS. This praxis explores and compares the performance of three machine learning models: Random Forest (RF), eXtreme Gradient Boosting (XGBoost), and Bidirectional Long Short-Term Memory (Bi-LSTM), with a particular emphasis on balancing detection accuracy, processing speed, and model size. The XGBoost model emerged as the superior choice, offering the best balance of high accuracy, low false alarm rate, and minimal detection latency, making it ideal for real-time applications in automotive networks. The proposed IDS improves upon existing solutions by addressing both the performance and practical deployment challenges in the context of in-vehicle networks. This research advances the field of automotive cybersecurity by providing a robust system for real-time CAN bus intrusion detection, paving the way for enhanced security measures in modern vehicles. Future work could extend this system to include more advanced detection techniques and the broader scope of inter-vehicle network communications, further strengthening vehicle security against evolving cyber threats.

Author Language Keyword Date created Type of Work License
  • All rights reserved
Rights statement GW Unit Degree Advisor Committee Member(s) Persistent URL

Notice to Authors

If you are the author of this work and you have any questions about the information on this page, please use the Contact form to get in touch with us.

Thumbnail Title Date Uploaded Visibility Actions
Preview of Rachidi_gwu_0075A_16986.pdf File 2025-04-11 Embargo