A lightgbm algorithm-based in-vehicle network intrusion detection method for intelligent connected vehicles
Abstract
The security of in-vehicle networks has become an essential issue for intelligent connected vehicles due to the increasing integration of electronic control units, vehicle-to-everything communication, and software-defined automotive functions. Conventional intrusion detection methods often suffer from limited feature representation capability, high computational complexity, or insufficient adaptability to complex attack patterns in controller area network traffic. To address these problems, this paper proposes a Light Gradient Boosting Machine (LightGBM)-based in-vehicle network intrusion detection method for intelligent connected vehicles. In the proposed method, controller area network (CAN) bus messages are first collected and preprocessed to extract key traffic features, including message identifiers, data field variations, transmission intervals, frequency characteristics, and statistical behavior patterns. Then, a feature selection and normalization strategy is introduced to reduce redundant information and improve model training efficiency. Based on the LightGBM algorithm, a gradient boosting decision tree model is constructed to identify abnormal communication behaviors and classify typical in-vehicle network attacks, such as spoofing attacks, replay attacks, flooding attacks, and denial-of-service attacks. The leaf-wise growth strategy and histogram-based optimization mechanism of LightGBM are utilized to improve detection accuracy while maintaining low computational overhead. Experimental results on in-vehicle network traffic datasets demonstrate that the proposed method achieves effective intrusion detection performance in terms of accuracy, precision, recall, F1-score, and detection latency. Compared with conventional machine learning models, the proposed method provides better classification robustness and real-time applicability. The proposed approach offers a feasible technical solution for enhancing the cybersecurity protection and active safety capability of intelligent connected vehicles.