A Scalable Hierarchical Intrusion Detection System for Internet of Vehicles

Md. Ashraf Uddin, Nam H. Chu, Reza Rafeh, Mutaz Barika · IEEE Internet of Things Journal · 2025

Due to its nature of dynamic, mobility, and wireless data transfer, the Internet of Vehicles (IoV) is susceptible to a wide range of cyber threats, including spoofing, Distributed Denial of Service (DDoS) attacks, and malware. intrusion detection systems (IDS) play a vital role in protecting the IoV ecosystem by continuously monitoring network traffic to detect and respond to intrusions, malicious activities, and policy violations in real time. However, most existing research has focused on centralized, machine learning (ML)-based IDS solutions for IoV, often overlooking its inherently distributed architecture. Due to their high computational demands, these centralized systems often depend on Cloud resources to detect cyber threats, which can lead to increased response delays. On the other hand, Edge nodes typically lack the necessary resources to train and deploy complex ML and deep learning algorithms. To address this issue, this article proposes an effective hierarchical classification framework designed for IoV networks. Hierarchical classification enables classifiers to be trained and deployed across multiple levels. This allows Edge nodes to independently identify specific types of attacks. With this approach, Edge nodes can conduct targeted attack detection while utilizing Cloud nodes for more comprehensive threat analysis and coordination. Considering the resource limitations of Edge nodes, we employ the Boruta feature selection method to reduce data dimensionality and enhance processing efficiency. To evaluate our proposed framework, we utilize the latest IoV security dataset CIC-IoV2024 and CIC-DDoS2019 datasets, achieving promising results that demonstrate the feasibility and effectiveness of our models in securing IoV networks. This hierarchical framework might improve the scalability and responsiveness of intrusion detection in distributed IoV environments. By offloading lightweight detection tasks to Edge nodes and reserving deeper analysis for the Cloud, the model can reduce latency and network load, making real-time threat response more feasible. The proposed approach can offer a practical solution for deploying effective, resource-aware cybersecurity mechanisms in real-world vehicular networks, where traditional centralized systems fall short.

Read the paper · More papers on PaperTik