FedGAN-ID: Federated-Learning-Based Intrusion Detection for In-Vehicle Network Using GANs
Mingyang Chen, Biaobang Wu, Heng Sun, Zhaoxiang Wang · IEEE Internet of Things Journal · 2025
With the rapid advancement of intelligent connected vehicles (ICVs), in-vehicle networks (IVNs) have increasingly become active targets for cyberattacks. The controller area network (CAN), a widely used IVN, lacks security mechanisms, making it vulnerable to attacks that may lead to system failures and even endanger passenger safety. Existing intrusion detection models depend on centralized data processing and limited real attack data, which raises privacy concerns and restricts detection capabilities. Therefore, we propose a novel federated learning (FL)-based solution, called FedGAN-ID, which aims to generate realistic attack data to enhance the intrusion detection performance using generative adversarial networks (GANs) in ICVs. This article generates CAN message graph within given interval based on CAN ID, message content, and timestamps, enabling comprehensive detection of various attacks that existing models can only partially detect, such as DoS, spoofing, fuzzy, replay, and masquerade attacks. Considering there are few known real attack signatures for IVNs, this article develops a two-level cascade detector. Specifically, we first propose a novel GAN model that is trained to mimic the normal data distribution to enable detection of both known and unknown attacks. Subsequently, we introduce a FL scheme in which each vehicle generates differentially private synthetic data and uploads these data to the cloud server to improve the attack classification ability of FedGAN-ID without sharing real data. Extensive experiments have been conducted on three real vehicles supported by XPeng, demonstrating that FedGAN-ID can accurately detect all these attacks in 1.96 milliseconds.