ACHILLES: A Machine Learning Framework for Explainable and Generalized Automotive Intrusion Detection System
Nishat I Mowla, Kyi Thar, Sarder Fakhrul Abedin, Aamir Mahmood, Zhu Han, Mikael Gidlund, Kabir Fahria, Konstantinos Giapantzis, Antonios X. Lalas, Joakim Rosell, Mahshid Helali Moghadam · IEEE Transactions on Intelligent Transportation Systems · 2026
This paper addresses the need for an explainable and generalized intrusion detection system (IDS) for the in-vehicle networks (IVNs). While machine learning (ML)-based IDS solutions show promising performance, there are still some challenges, such as the lack of trustworthiness and scarcity of attack representing data, hindering their adoption in the automotive cybersecurity. To address these issues, this paper proposes a centralized ML model training and decentralized execution-based framework, namely ACHILLES, that facilitates an explainable and generalizable automotive IDS. Under ACHILLES, different ML models can be trained centrally to enhance decentralized and onboard intrusion detection performance with multiple automotive datasets. In addition, we generate standard feature formats to assess the ML model’s generalization efficacy, where the quality of generalization and explainability is evaluated with SHapley Additive exPlanations (SHAP) by identifying the importance of the feature. We also propose a meta-learning scheme to construct suitable ML models trained by the proposed standard feature formats. The proposed feature format exhibits significant performance gain during ML model training and testing with four state-of-the-art controller area network (CAN)-bus datasets containing real, advanced attacks. The experimental results indicate that developing ML models using the generated generalized features and the meta learning-based model building process leads to enhanced performance. In particular, under the dataset cross train-test setting, the proposed feature format enhances the average accuracy by 40.1% for the baseline model, 32.4% for the meta-learned DNN, and 23.6% for the meta-learned Random Forest, compared with the baseline feature format.