[{"data":1,"prerenderedAt":-1},["ShallowReactive",2],{"doc-detail-123220-en":3,"doc-seo-123220-105":30,"detail-sidebar-cat-0-en-105":92},{"code":4,"msg":5,"data":6},0,"success",{"doc_id":7,"user_id":8,"nickname":9,"user_avatar":10,"doc_module":4,"category_id":11,"category_name":12,"doc_title":13,"doc_description":14,"doc_content":15,"file_id":16,"file_url":17,"file_type":18,"file_size":19,"view_count":20,"is_deleted":4,"is_public":20,"is_downloadable":20,"audit_status":20,"page_count":21,"language":22,"language_code":23,"site_id":24,"html_lang":23,"table_of_contents":25,"faqs":26,"seo_title":27,"seo_description":14,"update_tm":28,"read_time":29},123220,1099514067415,"Rowan","https://ap-avatar.wpscdn.com/avatar/100002539d78ffe74a7?x-image-process=image/resize,m_fixed,w_180,h_180&k=1779092875211072502",8,"Research & Report","Machine Learning with Real-time and Small Footprint Anomaly Detection System for In-Vehicle Gateway - arXiv 2406.16369v1 - Abstract","Anomaly Detection System (ADS) is critical for a vehicle gateway ECU to identify abnormal behaviors and cyberattacks under tight real-time constraints and very limited code footprint. “One-time” attacks are especially difficult because they manipulate CAN payload content only once while remaining within valid ranges. The proposed solution uses self-information theory with logarithm-based value generation to enable real-time unsupervised detection without anomaly labels. Comparisons with HMM, SVDD, and LSTM show 8.7× lower FPR, 1.77× faster testing, and 4.88× smaller footprint.","Machine Learning with Real-time and Small Footprint Anomaly Detection System for In-Vehicle  \nGateway  \narXiv :2406 . 16369v1 [ cs .CR] 24 Jun 2024  \nYi Wang  \nProduct Cybersecurity & Privacy Of􀀂ce Continental Automotive Singapore Singapore [estelle.wang@continental.com](estelle.wang@continental.com)  \nYuanjin Zheng  \nSchool of EEE Nanyang Technological University  \nSingapore [YJZHENG@ntu.edu.sg](YJZHENG@ntu.edu.sg)  \nYajun Ha  \nSchool of Information Science and Technology ShanghaiTech University Shanghai, China [hayj@shanghaitech.edu.cn](hayj@shanghaitech.edu.cn)  \nAbstract—Anomaly Detection System (ADS) is an essential part of a modern gateway Electronic Control Unit (ECU) to detect abnormal behaviors and attacks in vehicles. Among the existing attacks,“one-time” attack is the most challenging to be detected, together with the strict gateway ECU constraints of both microsecond or even nanosecond level real-time budget and limited footprint of code. To address the challenges, we propose to use the self-information theory to generate values for training and testing models, aiming to achieve real-time detection performance for the “one-time” attack that has not been well studied in the past. Second, the generation of self-information is based on logarithm calculation, which leads to the smallest footprint to reduce the cost in Gateway. Finally, our proposed method uses an unsupervised model without the need of training data for anomalies or attacks. We have compared different machine learning methods ranging from typical machine learning models to deep learning models, e.g., Hidden Markov Model (HMM), Support Vector Data Description (SVDD), and Long Short Term Memory (LSTM). Experimental results show that our proposed method achieves 8.7 times lower False Positive Rate (FPR), 1.77 times faster testing time, and 4.88 times smaller footprint.  \nIndex Terms—ADS, Machine Learning, Gateway  \nI. INTRODUCTION  \nWith the emerging requirement of the Arti􀀂cial Intelligence of Things (AIoT) in vehicular applications, consumers pay more and more attention to personal privacy and con􀀂dentiality, apart from the safety, compatibility, and performance of a modern vehicle [1] . The in-vehicle network consists of Electronic Control Units (ECUs) to construct various subsystems. In contrast with the point to point connections, several peripherals have been connected using the same set of wires, enabling different controllers to share the same signals of a single sensor. However, the basic protocol of the in-vehicle network, Controller Area Network (CAN) [2], only provides the address dependability and fault detection.  \nThere are existing security threads and holes to be used by the attackers to retrieve sensitive information of the critical components, such as the engine ECU, the brake ECU, etc. [3]  \n[4] . These lead to possible security vulnerabilities, e.g., spoofing, manipulation, man-in-the-middle attacks. These attacks can be successful when the adversaries compromise the pri-  \nmary interfaces and the gateway system. For instance, Miller and Valasek [5] have successfully penetrated the wireless interfaces of the entertainment system in the Jeep Cherokee and took over the central controller of the car. This attack can cause a severe safety concern with a million of losses, which affects all the stakeholders, such as OEMs and automotive tierone suppliers. There are also existing typical attacks of CAN bus in-vehicle networks, which are message 􀀃ooding, cyclic message, replay, and “one-time” attacks. Among them,“onetime” attack is the most challenging and dif􀀂cult to be detected by Anomaly Detection System (ADS) . This type of attack only manipulates the data payload or the content once using one malicious CAN message (the data payload or content is still within the valid data range after hacking) . This kind of attack could be severe for the CAN bus message with sensitive information to critical ECUs, e.g., braking control, air-bag control, ","cbCaiaE94acBc12V","https://ap.wps.com/l/cbCaiaE94acBc12V","pdf",329404,1,5,"English","en",105,"# Introduction\n## Background: in-vehicle networks and CAN limitations\n## Threats and the challenge of “one-time” attacks\n## Existing ML and non-ML approaches\n## Proposed approach and objectives","[{\"question\":\"Why are “one-time” attacks hard to detect with an in-vehicle ADS?\",\"answer\":\"They modify the CAN payload or content only once using a malicious message while the manipulated data still stays within the valid range, making traditional detection difficult.\"},{\"question\":\"What key constraint motivates the proposed small-footprint design?\",\"answer\":\"The gateway ECU requires extremely fast real-time detection budgets (microsecond or even nanosecond level) and limited available space for additional code.\"},{\"question\":\"How does the method avoid the need for labeled anomaly datasets?\",\"answer\":\"It employs an unsupervised machine learning approach based on self-information theory to generate training/testing values without requiring labeled anomalies or attacks.\"}]","Machine Learning with Real-time and Small Footprint Anomaly Detection System for In-Vehicle Gateway - arXiv 2406.16369v1 - Abstract | PDF",1785815296,13,{"code":4,"msg":31,"data":32},"ok",{"site_id":24,"language":23,"slug":33,"title":13,"keywords":34,"description":14,"schema_data":35,"social_meta":87,"head_meta":89,"extra_data":91,"updated_unix":28},"machine-learning-with-real-time-and-small-footprint-anomaly-detection-system-for-in-vehicle-gateway-arxiv-240616369v1-abstract","",{"@graph":36,"@context":86},[37,54,69],{"@type":38,"itemListElement":39},"BreadcrumbList",[40,44,48,51],{"item":41,"name":42,"@type":43,"position":20},"https://docshare.wps.com","Home","ListItem",{"item":45,"name":46,"@type":43,"position":47},"https://docshare.wps.com/document/","Document",2,{"item":49,"name":12,"@type":43,"position":50},"https://docshare.wps.com/document/research-report/",3,{"item":52,"name":13,"@type":43,"position":53},"https://docshare.wps.com/document/machine-learning-with-real-time-and-small-footprint-anomaly-detection-system-for-in-vehicle-gateway-arxiv-240616369v1-abstract/123220/",4,{"url":52,"name":13,"@type":55,"author":56,"headline":13,"publisher":58,"fileFormat":61,"inLanguage":23,"description":14,"dateModified":62,"datePublished":63,"encodingFormat":61,"isAccessibleForFree":64,"interactionStatistic":65},"DigitalDocument",{"name":9,"@type":57},"Person",{"url":41,"name":59,"@type":60},"DocShare","Organization","application/pdf","2026-08-05","2026-08-04",true,{"@type":66,"interactionType":67,"userInteractionCount":20},"InteractionCounter",{"@type":68},"ViewAction",{"@type":70,"mainEntity":71},"FAQPage",[72,78,82],{"name":73,"@type":74,"acceptedAnswer":75},"Why are “one-time” attacks hard to detect with an in-vehicle ADS?","Question",{"text":76,"@type":77},"They modify the CAN payload or content only once using a malicious message while the manipulated data still stays within the valid range, making traditional detection difficult.","Answer",{"name":79,"@type":74,"acceptedAnswer":80},"What key constraint motivates the proposed small-footprint design?",{"text":81,"@type":77},"The gateway ECU requires extremely fast real-time detection budgets (microsecond or even nanosecond level) and limited available space for additional code.",{"name":83,"@type":74,"acceptedAnswer":84},"How does the method avoid the need for labeled anomaly datasets?",{"text":85,"@type":77},"It employs an unsupervised machine learning approach based on self-information theory to generate training/testing values without requiring labeled anomalies or attacks.","https://schema.org",{"og:url":52,"og:type":88,"og:title":13,"og:site_name":59,"og:description":14},"article",{"robots":90,"canonical":52},"index,follow",{"doc_id":7,"site_id":24},{"code":4,"msg":5,"data":93},[94,98,102,106,110,115,120,123,128,131,135],{"id":20,"doc_module":4,"doc_module_name":46,"category_name":95,"show_sort_weight":96,"slug":97},"Story & Novel",90,"story-novel",{"id":47,"doc_module":4,"doc_module_name":46,"category_name":99,"show_sort_weight":100,"slug":101},"Literature",80,"literature",{"id":53,"doc_module":4,"doc_module_name":46,"category_name":103,"show_sort_weight":104,"slug":105},"Exam",70,"exam",{"id":21,"doc_module":4,"doc_module_name":46,"category_name":107,"show_sort_weight":108,"slug":109},"Comic",60,"comic",{"id":111,"doc_module":4,"doc_module_name":46,"category_name":112,"show_sort_weight":113,"slug":114},6,"Technology",50,"technology",{"id":116,"doc_module":4,"doc_module_name":46,"category_name":117,"show_sort_weight":118,"slug":119},7,"Healthcare",40,"healthcare",{"id":11,"doc_module":4,"doc_module_name":46,"category_name":12,"show_sort_weight":121,"slug":122},30,"research-report",{"id":124,"doc_module":4,"doc_module_name":46,"category_name":125,"show_sort_weight":126,"slug":127},9,"Religion & Spirituality",20,"religion-spirituality",{"id":126,"doc_module":4,"doc_module_name":46,"category_name":129,"show_sort_weight":126,"slug":130},"World Cup","world-cup",{"id":132,"doc_module":4,"doc_module_name":46,"category_name":133,"show_sort_weight":132,"slug":134},10,"Lifestyle","lifestyle",{"id":136,"doc_module":4,"doc_module_name":46,"category_name":137,"show_sort_weight":21,"slug":138},19,"General","general"]