[{"data":1,"prerenderedAt":-1},["ShallowReactive",2],{"doc-detail-118239-en":3,"doc-seo-118239-105":30,"detail-sidebar-cat-0-en-105":83},{"code":4,"msg":5,"data":6},0,"success",{"doc_id":7,"user_id":8,"nickname":9,"user_avatar":10,"doc_module":4,"category_id":11,"category_name":12,"doc_title":13,"doc_description":14,"doc_content":15,"file_id":16,"file_url":17,"file_type":18,"file_size":19,"view_count":4,"is_deleted":4,"is_public":20,"is_downloadable":20,"audit_status":20,"page_count":21,"language":22,"language_code":23,"site_id":24,"html_lang":23,"table_of_contents":25,"faqs":26,"seo_title":27,"seo_description":14,"update_tm":28,"read_time":29},118239,1099514068035,"Ezra","https://ap-avatar.wpscdn.com/davatar_276721f389ce27ea32af1340a28f341c",8,"Research & Report","CANEDERLI - On The Impact of Adversarial Training and Transferability on CAN Intrusion Detection Systems","The growing integration of vehicles with external networks has increased attacks targeting the Controller Area Network (CAN) internal bus. To mitigate these threats, CAN-based Intrusion Detection Systems (IDSs) increasingly rely on data-driven Machine Learning and Deep Learning models trained on growing datasets from V2V and V2I communications. Such systems, however, remain vulnerable to adversarial evasion attacks. This paper introduces CANEDERLI, a framework with a realistic threat model, analyzing adversarial transferability across attack methods and model architectures, and evaluating adversarial training via an adaptive online technique that improves detection robustness beyond traditional fine-tuning, reaching F1 up to 0.941.","CANEDERLI: On The Impact of Adversarial Training and Transferability on CAN Intrusion Detection Systems  \nFrancesco Marchiori University of Padova  \nPadua, Italy [francesco.marchiori.4@phd.unipd.it](francesco.marchiori.4@phd.unipd.it)  \nMauro Conti  \nUniversity of Padova Padua, Italy  \nDelft University of Technology Delft, Netherlands [mauro.conti@unipd.it](mauro.conti@unipd.it)  \nABSTRACT  \nThe growing integration of vehicles with external networks has led to a surge in attacks targeting their Controller Area Network (CAN) internal bus. As a countermeasure, various Intrusion Detection Systems (IDSs) have been suggested in the literature to prevent and mitigate these threats. With the increasing volume of data facilitated by the integration of Vehicle-to-Vehicle (V2V) and Vehicle-to-Infrastructure (V2I) communication networks, most of these systems rely on data-driven approaches such as Machine Learning (ML) and Deep Learning (DL) models. However, these systems are susceptible to adversarial evasion attacks. While many researchers have explored this vulnerability, their studies often involve unrealistic assumptions, lack consideration for a realistic threat model, and fail to provide effective solutions.  \nIn this paper, we present CANEDERLI (CAN Evasion Detection ResiLIence), a novel framework for securing CAN-based IDSs. Our system considers a realistic threat model and addresses the impact of adversarial attacks on DL-based detection systems. Our findings highlight strong transferability properties among diverse attack methodologies by considering multiple state-of-the-art attacks and model architectures. We analyze the impact of adversarial training in addressing this threat and propose an adaptive online adversarial training technique outclassing traditional fine-tuning methodologies with F1 scores up to 0.941. By making our framework publicly available, we aid practitioners and researchers in assessing the resilience ofIDSs to a varied adversarial landscape.  \nCCS CONCEPTS  \n• Security and privacy → Intrusion detection systems; • Computing methodologies → Machine learning.  \nKEYWORDS  \nController Area Network; Intrusion Detection Systems; Adversarial Attacks; Adversarial Transferability; Adversarial Training  \nACM Reference Format:  \nFrancesco Marchiori and Mauro Conti. 2024. CANEDERLI: On The Impact of Adversarial Training and Transferability on CAN Intrusion Detection Systems. In Proceedings of the 2024 ACM Workshop on Wireless Security and  \nThis work is licensed under a Creative Commons AttributionNonCommercial International 4 .0 License.  \nWiseML’24, May 31, 2024, Seoul, Republic of Korea © 2024 Copyright held by the owner/author(s) . ACM ISBN 979-8-4007-0602-8/24/05 . [https://doi.org/10.1145/3649403.3656486](https://doi.org/10.1145/3649403.3656486)  \nMachine Learning (WiseML’24), May 31, 2024, Seoul, Republic of Korea. ACM, New York, NY, USA, 6 pages. [https://doi.org/10.1145/3649403.3656486](https://doi.org/10.1145/3649403.3656486)  \n1 INTRODUCTION  \nThe proliferation of advanced functionalities in modern vehicles necessitates an increased number of Electronic Control Units (ECUs) . As such, communication between these components becomes vital for ensuring the reliable operation of the vehicle’s systems and features. This heightened communication underscores the critical role of the Controller Area Network (CAN) bus in facilitating seamless interaction among ECUs. Furthermore, the scope of communication extends beyond the confines of the vehicle itself, including interactions with external entities such as other vehicles (V2V) and infrastructures (V2I) . These communication protocols enable various functionalities, including cooperative driving, real-time traffic management, and advanced driver assistance systems [8] .  \nThis heightened connectivity also increases potential security threats, prompting the need for robust Intrusion Detection Systems (IDSs) . These security tools are designed to monitor network or ","cbCaib9Cq8oweiYC","https://ap.wps.com/l/cbCaib9Cq8oweiYC","pdf",1368985,1,6,"English","en",105,"# Abstract\n# Introduction\n## Vehicle connectivity and the role of CAN\n## IDSs and data-driven detection\n## Adversarial attacks and threat-model limitations\n## Contribution: CANEDERLI framework","[{\"question\":\"What defense approach does CANEDERLI propose, and how effective is it?\",\"answer\":\"It proposes adaptive online adversarial training that outperforms traditional fine-tuning, achieving F1 scores up to 0.941.\"}]","CANEDERLI - On The Impact of Adversarial Training and Transferability on CAN Intrusion Detection Systems | PDF",1785682572,15,{"code":4,"msg":31,"data":32},"ok",{"site_id":24,"language":23,"slug":33,"title":13,"keywords":34,"description":14,"schema_data":35,"social_meta":78,"head_meta":80,"extra_data":82,"updated_unix":28},"canederli-on-the-impact-of-adversarial-training-and-transferability-on-can-intrusion-detection-systems","",{"@graph":36,"@context":77},[37,54,68],{"@type":38,"itemListElement":39},"BreadcrumbList",[40,44,48,51],{"item":41,"name":42,"@type":43,"position":20},"https://docshare.wps.com","Home","ListItem",{"item":45,"name":46,"@type":43,"position":47},"https://docshare.wps.com/document/","Document",2,{"item":49,"name":12,"@type":43,"position":50},"https://docshare.wps.com/document/research-report/",3,{"item":52,"name":13,"@type":43,"position":53},"https://docshare.wps.com/document/canederli-on-the-impact-of-adversarial-training-and-transferability-on-can-intrusion-detection-systems/118239/",4,{"url":52,"name":13,"@type":55,"author":56,"headline":13,"publisher":58,"fileFormat":61,"inLanguage":23,"description":14,"dateModified":62,"datePublished":62,"encodingFormat":61,"isAccessibleForFree":63,"interactionStatistic":64},"DigitalDocument",{"name":9,"@type":57},"Person",{"url":41,"name":59,"@type":60},"DocShare","Organization","application/pdf","2026-08-02",true,{"@type":65,"interactionType":66,"userInteractionCount":4},"InteractionCounter",{"@type":67},"ViewAction",{"@type":69,"mainEntity":70},"FAQPage",[71],{"name":72,"@type":73,"acceptedAnswer":74},"What defense approach does CANEDERLI propose, and how effective is it?","Question",{"text":75,"@type":76},"It proposes adaptive online adversarial training that outperforms traditional fine-tuning, achieving F1 scores up to 0.941.","Answer","https://schema.org",{"og:url":52,"og:type":79,"og:title":13,"og:site_name":59,"og:description":14},"article",{"robots":81,"canonical":52},"index,follow",{"doc_id":7,"site_id":24},{"code":4,"msg":5,"data":84},[85,89,93,97,102,106,111,114,119,122,126],{"id":20,"doc_module":4,"doc_module_name":46,"category_name":86,"show_sort_weight":87,"slug":88},"Story & Novel",90,"story-novel",{"id":47,"doc_module":4,"doc_module_name":46,"category_name":90,"show_sort_weight":91,"slug":92},"Literature",80,"literature",{"id":53,"doc_module":4,"doc_module_name":46,"category_name":94,"show_sort_weight":95,"slug":96},"Exam",70,"exam",{"id":98,"doc_module":4,"doc_module_name":46,"category_name":99,"show_sort_weight":100,"slug":101},5,"Comic",60,"comic",{"id":21,"doc_module":4,"doc_module_name":46,"category_name":103,"show_sort_weight":104,"slug":105},"Technology",50,"technology",{"id":107,"doc_module":4,"doc_module_name":46,"category_name":108,"show_sort_weight":109,"slug":110},7,"Healthcare",40,"healthcare",{"id":11,"doc_module":4,"doc_module_name":46,"category_name":12,"show_sort_weight":112,"slug":113},30,"research-report",{"id":115,"doc_module":4,"doc_module_name":46,"category_name":116,"show_sort_weight":117,"slug":118},9,"Religion & Spirituality",20,"religion-spirituality",{"id":117,"doc_module":4,"doc_module_name":46,"category_name":120,"show_sort_weight":117,"slug":121},"World Cup","world-cup",{"id":123,"doc_module":4,"doc_module_name":46,"category_name":124,"show_sort_weight":123,"slug":125},10,"Lifestyle","lifestyle",{"id":127,"doc_module":4,"doc_module_name":46,"category_name":128,"show_sort_weight":98,"slug":129},19,"General","general"]