Network Traffic Anomaly Detection in CAN Bus Based on Ensemble Learning

Yu‐Xi Wu, Xiaodong Tao · 2024

As the transportation and information industries continue to advance, the increasing variety of application scenarios, devices with computing capabilities, and a growing number of open ports have heightened security risks for vehicle networks. To improve the accuracy of detecting abnormal traffic in vehicle networks, we propose a model based on ensemble learning with a Stacking model integration approach. This method includes a meta-classifier composed of decision trees, extremely randomized trees, and extreme gradient boosting. The final classification prediction results are obtained by linearly stacking input features and weights into a SoftMax meta-learner. Additionally, the research enhances the classification accuracy of network flow data through parameter optimization. Testing results on the real automotive hacker attack dataset, Car-Hacking, show that this method achieves an accuracy rate of up to 99.2% in detecting denial of service, gear spoofing, and RPM spoofing attack types, and up to 97.5% accuracy in Fuzzy attack types. The study indicates that this model has a low false positive rate, high detection accuracy, and high detection rate, significantly outperforming traditional detection methods based on other machine learning technologies.

Read the paper · More papers on PaperTik