Detecting Intrusions in CBTC Systems with Mixed-Mode Operations
Bibliographic record
Abstract
Communication-Based Train Control (CBTC) systems are automatic train control systems that rely on wireless data transmissions to provide safe and efficient railway operations. However, integrating wireless technologies has rendered railways vulnerable to cyber attacks. The current body of research concerning CBTC security does not consider that most railway operators deploy this system alongside a secondary train control system, known as external interlocking. The integration of these two train control systems allows for the operation of both CBTC-capable and CBTC-incapable trains along the same railway. This integration is termed a mixed-mode operation in the IEEE 1474.1 standard for CBTC performance and functional requirements. This work proposes a machine learning-based intrusion detection system for wireless communications in mixedmode operations to address the aforementioned gap in the literature. The detection methods proposed in this work were evaluated in a simulated railway environment that integrated the CBTC system with an external interlocking. Multiple machine learning models have been trained on the resultant data transmissions of both systems under normal and attack conditions. The experimental results provide valuable insights into which models can best meet the requirements of an integrated CBTC-external interlocking railway to ensure the integrity and availability of wireless transmissions.
Fetched live from OpenAlex and de-inverted. Abstracts are not stored in this database: the inverted indexes are 8.6 GB of the frame’s 9.3 GB of text, and the host has 13 GB free.
How this classification was reachedexpand
Full frame machine prediction
Teacher imitationNot calibrated prevalence, not ground truth. Human validation pending. The Gemma side is a direct model label for every work in the frame, read from the title-only record. The Codex side is a classifier learned from the 10,348 direct Codex labels and calibrated to design-weighted sample rates; fields without enough sample support carry no Codex call. Candidate is the union of the two sides; consensus is their intersection. These outputs are machine_predicted_unvalidated and are not human labels.
Distilled classifier scores by category (both heads)
| Category | Codex | Gemma |
|---|---|---|
| Metaresearch | 0.001 | 0.004 |
| Meta-epidemiology (narrow) | 0.001 | 0.000 |
| Meta-epidemiology (broad) | 0.001 | 0.000 |
| Bibliometrics | 0.001 | 0.000 |
| Science and technology studies | 0.000 | 0.001 |
| Scholarly communication | 0.001 | 0.001 |
| Open science | 0.001 | 0.001 |
| Research integrity | 0.001 | 0.001 |
| Insufficient payload (model declined to judge) | 0.000 | 0.000 |
Machine scores (provisional)
The two teacher heads of the student model, read on this work. A score orders the frame for review; it never asserts a category, and the validation status ships verbatim with every row.
Baseline scores from an immature model (maturity gate not passed, 7 training rounds). Scores rank; they never assert a category.
score_only:v0-immature-baseline · verbatim from the scoring run: score_only means the number may rank works, and no category label ships from itClassification
machine, unvalidatedMachine predicted; a candidate call from one source (direct Gemma or distilled Codex), not a consensus.
How this classification was reached, model by model and score by score, is at the end of the page under "How this classification was reached".