NeuroCAN: Contextual Anomaly Detection in Controller Area Networks
Bibliographic record
Abstract
The Controller Area Network (CAN) is an established standard for inter-connecting onboard Electronic Control Units (ECUs) in a vehicle. Through sensors and actuators, ECUs maintain critical vehicle functions such as transmission and engine control. However, security was never a part of CAN design and hence ECUs are susceptible to a wide range of attacks. Thus, in recent years, several anomaly detection systems have been proposed for the CAN bus in order to detect anomalies caused by adversarial attacks or misbehaving sensors. These systems generally try to detect deviations from individual sensor's expected behavior. As such, they are ineffective against attacks that target multiple sensors to accomplish a collective desired behavior without changing the expected behavior of each individual sensor. In this paper, we focus on detecting such attacks by identifying contextual CAN anomalies in realtime. To this end, we present NeuroCAN, a deep learning-based detection system that utilizes Linear embeddings and Long Short Term Memory (LSTM) units to learn the spatio-temporal correlations among sensor data on the CAN bus at a frame level. By exploiting such correlations, NeuroCAN is able to detect contextual anomalies that are otherwise difficult to detect by analyzing individual sensor data. We evaluate NeuroCAN using two publicly available CAN datasets and compare it against existing approaches. Our results show that NeuroCAN achieves over 95% detection accuracy and performs significantly better than the existing baselines.
Fetched live from OpenAlex and de-inverted. Abstracts are not stored in this database: the inverted indexes are 8.6 GB of the frame’s 9.3 GB of text, and the host has 13 GB free.
How this classification was reachedexpand
Full frame distilled prediction
Teacher imitationNot calibrated prevalence, not ground truth. Human validation pending. Learned from the 10,348 direct Codex labels and 10,348 direct Gemma labels. Candidate is the union of thresholded teacher heads; consensus is their intersection. These outputs are machine_predicted_unvalidated and are not human labels or direct frontier model labels.
Codex and Gemma teacher scores by category
| Category | Codex | Gemma |
|---|---|---|
| Metaresearch | 0.000 | 0.000 |
| Meta-epidemiology (narrow) | 0.000 | 0.000 |
| Meta-epidemiology (broad) | 0.000 | 0.000 |
| Bibliometrics | 0.000 | 0.000 |
| Science and technology studies | 0.000 | 0.000 |
| Scholarly communication | 0.000 | 0.000 |
| Open science | 0.000 | 0.000 |
| Research integrity | 0.000 | 0.000 |
| Insufficient payload (model declined to judge) | 0.000 | 0.000 |
Machine scores (provisional)
The two teacher heads of the student model, read on this work. A score orders the frame for review; it never asserts a category, and the validation status ships verbatim with every row.
Baseline scores from an immature model (maturity gate not passed, 7 training rounds). Scores rank; they never assert a category.
score_only:v0-immature-baseline · verbatim from the scoring run: score_only means the number may rank works, and no category label ships from itClassification
machine, unvalidatedMachine predicted; a candidate call from one teacher head, not a consensus.
How this classification was reached, model by model and score by score, is at the end of the page under "How this classification was reached".