GNN-Based in-Vehicle Network Intrusion Detection System

Wen-Chi Lu, Bo-Chao Cheng · 2025

With the increasing degree of automation and connectivity in modern cars, the security of the vehicle's internal network has become an important issue. This study aims to analyze and detect security threat behaviors in the Controller Area Network (CAN) within the vehicle's intra-vehicle networks (IVNs). To overcome this problem, this study proposes a CAN Intrusion Detection System (IDS) based on the Graph Neural Network (GNN) model. The GNN is trained and classified based on the timestamp changes of the CAN frame arbitration ID as edge attributes in the graph, which is called gIDS-CAN (GNN based Intrusion Detection System in Controller Area Network). This method is designed to implement a gIDS-CAN that can monitor the packet analysis of the vehicle CAN protocol, detect any malicious or abnormal messages, and effectively identify CAN attacks through a comprehensive analysis of edge features and topological information. The gIDSCAN provides a novel solution for the security of the vehicle's internal network.

Read the paper · More papers on PaperTik