Skip to main navigation Skip to search Skip to main content

XIPHOS: Adaptive In-Vehicle Intrusion Detection via Unsupervised Graph Contrastive Learning

  • School of Computer Science and Technology, Harbin Institute of Technology
  • Shandong Key Laboratory of Industrial Network Security
  • Harbin Institute of Technology Weihai
  • Qingdao Research Institute

Research output: Contribution to journalArticlepeer-review

Abstract

As vehicles have become increasingly connected and intelligent, attacks against in-vehicle networks (IVNs) are becoming more prevalent and pose a great threat to vehicle security and occupant safety. Intrusion detection techniques utilizing deep learning models have become a common approach to secure IVNs. However, existing work has shown some weaknesses. 1) They are unable to directly extract the rich information hidden in the data behavioral patterns. 2) The effectiveness of most supervised models depends on balanced data distributions and high-quality labels, whereas the current state of real-world datasets does not match these demands. 3) The performance of unsupervised learning models is inferior to supervised methods, accompanied by unstable or unpredictable results. In this paper, we design and implement XIPHOS, a novel and adaptive IVN intrusion detection mechanism that is capable of achieving efficient detection performance in the unsupervised environment. XIPHOS utilizes the principle of mutual information maximization to extract as many potential data invariants as possible. By detecting abnormal system behaviors through error offsets of clustered combinations of feature units, XIPHOS is able to perform both graph-level representation and node-level representation from IVN data. In addition, the adaptiveness of XIPHOS is indicated by its ability to update the model parameters over time at different detection scenarios. Experimental results on widely used datasets show that XIPHOS has greater advantages over existing methods in terms of both detection performance and freedom from attack labeling data dependences. The code is available at https://github.com/wangkai-tech23/XIPHOS

Original languageEnglish
Pages (from-to)10419-10433
Number of pages15
JournalIEEE Transactions on Information Forensics and Security
Volume20
DOIs
StatePublished - 2025
Externally publishedYes

Keywords

  • Controller area network
  • graph contrastive learning
  • graph-theory
  • in-vehicle network
  • unsupervised intrusion detection

Fingerprint

Dive into the research topics of 'XIPHOS: Adaptive In-Vehicle Intrusion Detection via Unsupervised Graph Contrastive Learning'. Together they form a unique fingerprint.

Cite this