Cardiff University | Prifysgol Caerdydd ORCA
Online Research @ Cardiff 
WelshClear Cookie - decide language by browser settings

Adversarial robustness of intrusion detection systems for the in-vehicle networks of connected and autonomous vehicles

Aloraini, Fatimah ORCID: https://orcid.org/0000-0001-5494-0661 2025. Adversarial robustness of intrusion detection systems for the in-vehicle networks of connected and autonomous vehicles. PhD Thesis, Cardiff University.
Item availability restricted.

[thumbnail of 2026alorainifphd.pdf]
Preview
PDF - Accepted Post-Print Version
Available under License Creative Commons Attribution Non-commercial No Derivatives.

Download (5MB) | Preview
[thumbnail of Cardiff University Electronic Publication Form] PDF (Cardiff University Electronic Publication Form) - Supplemental Material
Restricted to Repository staff only

Download (295kB) | Request a copy

Abstract

Connected and autonomous vehicles (CAVs) rely on machine learning (ML)-based intrusion detection systems (IDSs) to secure in-vehicle network (IVN) communications. However, ML models are inherently vulnerable to adversarial attacks. While prior adversarial research in CAVs has predominantly focused on perception models, particularly object detection, the robustness of IVN-based IDSs remains largely underexplored. This thesis addresses this gap by investigating the adversarial robustness of IVN-based IDSs, introducing an IVN-specific threat taxonomy, and developing an attack method capable of generating adversarial IVN frames under varying levels of attacker knowledge of the deployed IDS model. Experimental results demonstrate that adversarial manipulation poses a severe threat to IVN-based IDSs. Under complete attacker knowledge of the deployed IDS model, detection performance drops from an F1-score of 99% to as low as 19%, with attack success rates reaching up to 89%. Even under limited knowledge, detection performance decreases from 95% to 38%, with success rates of up to 60%. To mitigate these vulnerabilities, this thesis proposes Explainability guided Counterfactual Adversarial Training (EXCAT), a novel defense mechanism that leverages model explainability to generate more representative adversarial training examples. EXCAT restores detection performance to up to 94% and reduces attack success rates to as low as 7.55%, demonstrating that explainability-guided training offers a promising direction for strengthening IVN-based IDS robustness and improving the safety of deployed CAV systems.

Item Type: Thesis (PhD)
Date Type: Completion
Status: Unpublished
Schools: Schools > Computer Science & Informatics
Subjects: Q Science > QA Mathematics > QA75 Electronic computers. Computer science
Date of First Compliant Deposit: 29 April 2026
Date of Acceptance: 28 April 2026
Last Modified: 29 Apr 2026 10:54
URI: https://orca.cardiff.ac.uk/id/eprint/186697

Actions (repository staff only)

Edit Item Edit Item

Downloads

Downloads per month over past year

View more statistics