Detecting and Mitigating Adversarial Machine Learning Attacks in Autonomous Vehicles Within the Internet of Vehicles

Mahmood Safaei, Ahmad Soleymani, Shahla Asadi, Mitra Safaei, Shidrokh Goudarzi · IEEE Transactions on Intelligent Transportation Systems · 2026

Adversarial Machine Learning (AML), particularly model poisoning, presents a critical threat to Autonomous Vehicles (AVs) in the Internet of Vehicles (IoV) environment. To address this challenge, we propose a framework that integrates Federated Learning (FL) with a Deep Learning-based Intrusion Detection and Behavior Monitoring (DL-based IBM) system, a vehicle scoring mechanism, Digital Twin (DT), and Generative AI (Gen-AI) to enhance security in IoV environments. Each AV employs a DL-based IBM as its local model, which is trained on vehicle-local operational data and contributes to a global model through FL aggregation. A vehicle scoring system is responsible for identifying and flagging compromised AVs (Zombies) exhibiting suspicious behavior. When the DT detects that the Zombie’s model has been manipulated through poisoning attacks, the DT updates the compromised model with the correct global model to restore normal operation. Furthermore, DT leverages Gen-AI to simulate and learn from novel attack scenarios that AVs have not previously encountered, ensuring that the framework adapts to evolving threats. The simulation results demonstrate significant improvements in resilience and detection accuracy, with F1 scores reaching 99% for known attacks and exceeding 87% for new unseen threats. This integrated approach ensures robust and adaptive protection for AVs, maintaining high trust and performance in the dynamic and adversarial IoV network.

Read the paper · More papers on PaperTik