Driveshield: Unmasking stealthy attacks on CAN bus via adversarial spatiotemporal feature learning
摘要
Modern vehicles rely on the Controller Area Network (CAN) for inter-module communication, yet its inherent lack of security exposes it to cyber-attacks that can compromise vehicle safety. Among these, stealthy attacks, such as masquerade and sophisticated injection attacks, are particularly pernicious as they mimic normal traffic patterns, evading many conventional detection systems. To address this critical challenge, this paper introduces DriveShield, a novel unsupervised intrusion detection framework designed to unmask such evasive threats. The core of DriveShield is its unique approach to adversarial spatiotemporal feature learning. It begins by fusing granular time-interval data with physical signal data to create a rich, comprehensive representation of network behavior. This fused data is then fed into an adversarial autoencoder, which is trained not only to precisely reconstruct normal data but also to fool a discriminator. This adversarial process compels the model to learn the intricate, underlying distribution of legitimate traffic, making it highly sensitive to subtle anomalies that signal an attack. Extensive experiments on public CAN datasets demonstrate that DriveShield significantly outperforms state-of-the-art methods, especially in its ability to identify complex, stealthy attacks. This research provides a robust defense mechanism for in-vehicle networks, advancing the state of automotive cybersecurity against modern, adaptive threats.