Skip to content
Conference

SEPIV-IDS: A Structured Evaluation Pipeline for In-Vehicle Intrusion Detection Systems

Jul 2026 · International Conference on Computer, Information and Telecommunication Systems · pp. 1-8 · 0 citations · 47 references

Abstract

Critical safety functions in modern vehicles rely heavily on intra-vehicle networks (IVNs), primarily via the Controller Area Network (CAN) protocol. The inherent vulnerabilities of CAN require robust intrusion detection systems (IDS) to mitigate adversarial threats. However, state-of-the-art IDS, especially AI-based approaches, often lack a comprehensive, well-defined performance analysis method. This work proposes and evaluates a structured pipeline for in-vehicle IDS, analyzing an autoencoder semi-supervised IDS as a practical case study. The method is validated on publicly available datasets, covering multiple attack types, with additional analysis of generalization capabilities. Performance is rigorously assessed using precision, recall, F1-score, and the Matthews Correlation Coefficient (MCC), chosen for its robustness in imbalanced scenarios. Results demonstrated highly efficient identification of DoS attacks (MCC 1.00), though Fuzzy DoS detection showed lower performance (MCC 0.214 in CAN-MIRGU and 0.074 in CAN-MODES). These findings support the viability of the proposed pipeline for IDS analysis focusing on enhancing CAN network security, consistent with recent research trends.

View source

Similar papers

Review Open access Jul 2026

DEEP LEARNING-BASED INTRUSION DETECTION IN COMPUTER SYSTEMS AND NETWORKS: ADVANCES, HYBRIDS, AND CHALLENGES 2022–2026

The work is devoted to a comprehensive systematic review of advances in identifying the state of computer systems and networks in the context of cybersecurity for the period 2022–2026. The study analyzes the evolution of intrusion detection systems (IDS), provides categorization and synthesis of key approaches, including supervised, unsupervised, and semi-supervised learning, as well as statistical and temporal analysis methods. Particular attention is paid to deep learning models (CNN, RNN/LSTM, Transformers, GNN) and their hybrid combinations, which demonstrate accuracy above 95% in detecting complex multi-stage attacks and zero-day threats. The experience of implementing identification methods in specific domains such as IoT, SCADA, automotive networks, and maritime transportation systems is summarized. Critical challenges for the scientific community are identified, including the problem of explainable artificial intelligence (XAI), resilience to adversarial attacks, and optimization for real-time operation on resource-constrained devices. Conclusions. The study revealed a trend of transition from classical static signature-based methods to dynamic intelligent algorithms. The analysis of available sources made it possible to classify the considered approaches according to their mathematical foundations and operational characteristics. For each group of methods, their main advantages, disadvantages, and key prospects for application were identified. It was found that hybrid and ensemble models provide the highest accuracy in complex environments (over 99%), while the combination of convolutional neural networks with recurrent networks or Transformers is the most effective solution for detecting multi-stage attacks. In addition, the growing role of federated learning in the development and implementation of intrusion detection systems was emphasized.

V. Chelak, Oleksii Hornostal, Yehor Chelak et al. · 0 citations
Conference Aug 2026

A Progressive Machine Learning Framework for Intrusion Prevention in Controller Area Networks: Multi-Scenario Evaluation for Secure Automotive Systems

Modern vehicles rely heavily on in-vehicle Controller Area Network (CAN) communication to coordinate safety-critical electronic control units (ECUs). However, the CAN protocol was not originally designed with authentication, encryption, or message integrity mechanisms, making it vulnerable to injection, spoofing, fuzzy, and denial-of-service attacks. Although machine learning-based intrusion detection systems have achieved high detection accuracy on CAN traffic, detection alone is not sufficient for safety-critical automotive environments where malicious messages may affect ECUs before a response is triggered. This paper presents a progressive machine learning-based framework for prevention-oriented CAN bus security. The framework analyzes statistical and temporal CAN traffic features and evaluates multiple machine learning models under three scenarios: binary attack detection, attack-type classification, and prevention-oriented allow/block decision evaluation. The study uses the Car-Hacking dataset and compares several supervised and anomaly-detection models, including tree-based ensembles, linear models, probabilistic models, neural models, and anomaly detectors. The results show that tree-based models achieve the strongest overall performance, with Random Forest reaching 99.6% accuracy in binary detection. The proposed prevention layer is evaluated as a software-level decision mechanism that converts model outputs into allow/block decisions, while CAN-aware blocking mechanisms are discussed only as architectural deployment options for future inline gateway implementation. The findings indicate that lightweight tree-based machine learning models can support real-time prevention-oriented decisions in CAN security, while further validation on hardware testbeds, realistic CAN bus-load conditions, and cross-dataset settings remains necessary.

Younis A. M. Al Shojaa, Redhwan M. A. Saad, Khaled A. M. Al Soufy · 0 citations
Conference Jul 2026

An Intelligent Intrusion Detection Framework for Cyber Security in Hybrid Network Environments

In the era of contemporary data traffic routing, the concept of Intrusion Detection Systems (IDS) is substantially utilized. However, the efficacy of IDS is often decreased because of the reality that high-concentration traffic postfixes, sophisticated cyber criminals, and more and more stringent demands are tending to decrease in resource-limited environments. The paper presents the enhanced intrusion detection system based on deep learning architecture, which can be flexible, adaptive and as well maintain the high detection capability with confidence under changing or to-be changed network settings. The objectives of this and aforementioned also address the issue of avoiding strong overtting behavior by models during the transfer learning and even rich feature representation through the first-stage operation: moving to address and ideally preventing attacks rather than supporting other attacks. The work is tailored to the deployment of the light-weight and adaptive IDS design which is supposed to be large enough to work in real time on low-powered devices such as IoTs and edge devices that are nondominated in energy and computationally less demanding. Real-time adaptability of the model will be examined through operational deployment simulations. It is also expected that such simulations would take into account latency, throughput, and energy consumption of the IDS model. On the one hand, In a stage nested within the very last period of this research, the IDS model has been merged with Explainable AI technologies; now LIME and SHAP are also preserved to improve the interpretability of the model decisions and the level of decision-making. What kind of feature attributions are made with the intrusion data? How is Interpretability of the model evaluated in terms of fidelity, comprehensibility, and expert belief? Therefore, all the above-mentioned events will be a perfect example of how the technologically ingrained tasks, particularly in the technical discipline of security studies, can be wrapped into the very cognitive resource of human beings.

Krishna Kumar Tiwari · 0 citations
Review Open access Jul 2026

A Systematic Review of AI-Driven Intrusion Detection and Performance Optimization in Wireless Sensor Networks

The safety and reliability of Wireless Sensor Networks (WSNs) depend on the crucial function that Intrusion Detection Systems (IDS) perform in their operations. The current security systems face major obstacles because attackers continuously launch cyber operations against increasingly complex networks. Through the development of Artificial Intelligence (AI) technologies, which include Machine Learning (ML) and Deep Learning (DL) methods, IDS systems could now identify both standard and novel cyber threats. The study analyzes the most recent progress in ML and DL methods used to develop IDS that operate in WSNs through analysis of their primary algorithms and algorithmic combinations. The study conducted an extensive literature review by accessing the SCOPUS database to identify relevant studies published between 2021 and 2026. The systematic review follows the Preferred Reporting Items for Systematic Reviews and Meta-Analyses (PRISMA) guidelines. As revealed by the results, the DL and hybrid approaches are superior to conventional ML algorithms in handling complicated and imbalanced datasets. Some of the accuracy rates observed are 99.94% when using KMeans-SMOTE, and 99.76% when using K-nearest neighbor (KNN). However, Deep Neural Networks (DNN) and Convolutional Neural Network–Long Short-Term Memory (CNN-LSTM) networks demonstrate relatively low accuracy levels of 96.23% and 97%, respectively. Most approaches use specific datasets, including WSN-DS and NSL-KDD, which makes the results environment-specific. Besides, issues such as high computational power, data imbalance, absence of standardized datasets, and implementation constraints underscore the need for a scalable and adaptable IDS for WSN.

Priyanka Sharma, Mohd Suhaib Kidwai, Piyush Charan · 0 citations
Open access Jul 2026

A High-Performance Deep Learning-Based Intrusion Detection System for Accurate Identification of Sophisticated Cyberattacks in Modern Network Environments

Purpose: The purpose of this study is to design a reliable and high-performance intrusion detection system (IDS) that can effectively identify various sophisticated cyber-attacks in network environments using a hybrid deep learning approach. Design/Methodology/Approach: A descriptive and experimental research methodology was used based on the UNSW NB15 benchmark dataset, which includes real and synthetic network data and various types of attacks. Data preprocessing includes handling missing values, encoding features, normalisation, and selecting features for dimensionality reduction. The performance of the models is evaluated using metrics such as accuracy, precision, recall, F1-score, and ROC-AUC. Research Limitation: The study is limited to experiments conducted on the UNSW-NB15 dataset, and real-time deployment constraints such as computational overhead and resource limitations were not extensively evaluated. Findings: The experimental results show that the hybrid deep learning architecture outperforms individual models in network intrusion detection. The hybrid model combining CNN, LSTM, and GRU achieved near-perfect accuracy in network intrusion detection, with extremely low false-positive and false-negative rates. The performance of recurrent models, such as LSTM, is superior in identifying network intrusion patterns, and the hybrid model performs best. Practical Implication: The proposed hybrid IDS framework can be effectively used in real-world network infrastructures to improve proactive threat detection, minimise false negatives, and enhance cybersecurity defences against evolving attack patterns. Social Implication: Improved intrusion detection systems help create a safer digital ecosystem by ensuring data safety, service availability, and trust in services delivered through networks, which is important for modern society. Originality / Value: The current research provides a comprehensive hybrid deep learning framework for intrusion detection that leverages both feedforward and recurrent neural networks. It emphasises the power of fusion models in developing accurate and reliable intrusion detection systems, making it a valuable contribution for researchers and practitioners in this field.

S. S. Goje, S. Asutkar, G. Asutkar · 0 citations
Open access Jul 2026

Evaluation Framework for Cross-Layer Intrusion Detection Based on ML Approaches

Internet of Things networks evolve as a rapidly growing field for security threats, such as Denial-of-Service cross-layer attacks, due to their heterogeneous and resource-constrained environment. Intrusion detection systems (IDSs) serve as a vital defense mechanism in modern cybersecurity. However, the adoption of such a system, especially one that adopts a cross-layer strategy, requires a standardized, multifaceted evaluation framework that accounts for both detection capability and operational overhead. To address these challenges, we proposed a modular weight-based framework that evaluates cross-layer Machine Learning (ML) IDS across multiple dimensions, namely, detection effectiveness and generalizability, data quality, and attack coverage and practical deployability. We then applied this framework to the state-of-the-art cross-layer ML IDSs identified through the PRISMA framework. This proof-of-concept application illustrates how current evaluation practices generate disparate, fragmented results, while also highlighting the limitations inherent in retrospective literature-based scoring.

Dimitrios Tasiopoulos, A. Xenakis, A. Lekidis et al. · 0 citations