Intrusion Detection System for In-vehicle Networks with Incremental Learning Based on Cloud-Edge Collaborative Architecture*

Jiaying Lin, Yehua Wei, Haoran Jiang, Jing Long · 2022

The development of vehicle networking and self-driving technology has increased the integration of communication interfaces into modern vehicles and the interaction between the connected vehicles and roadside unites. This situation also brings security threats. Controller area network (CAN) is the main bus system in modern automobiles. It easily suffers from cyberattacks because it lacks security protection mechanisms. Intrusion detection system is an effective method to defend cyberattacks. However, the detection accuracy may be affected by the change in driving environment and the occurrence of unknown attacks. A detection model based on incremental learning is used to improve detection performance. In addition, a cloud-edge collaborative architecture is designed to implement the detection model for reducing the burden of calculation and storage of on-board system and maintaining the timeliness of detection. Deep Neural Network(DNN) is applied in the offline training stage to obtain a basic classification model using marked actual CAN data. Then, the trained model is stored in the cloud server. After the edge server receives detection request from a vehicle, it will download the model from the cloud server and perform intrusion detection. At the same time, it will update the model with incremental learning technology based on new unlabeled data. Experimental results show the effectiveness of the proposed method.

Read the paper · More papers on PaperTik