{"status":"ok","message-type":"work","message-version":"1.0.0","message":{"indexed":{"date-parts":[[2026,7,10]],"date-time":"2026-07-10T19:27:03Z","timestamp":1783711623983,"version":"3.55.0"},"reference-count":59,"publisher":"Association for Computing Machinery (ACM)","issue":"4","license":[{"start":{"date-parts":[[2022,7,31]],"date-time":"2022-07-31T00:00:00Z","timestamp":1659225600000},"content-version":"vor","delay-in-days":0,"URL":"https:\/\/www.acm.org\/publications\/policies\/copyright_policy#Background"}],"funder":[{"DOI":"10.13039\/501100001809","name":"NSFC","doi-asserted-by":"crossref","award":["61902185"],"award-info":[{"award-number":["61902185"]}],"id":[{"id":"10.13039\/501100001809","id-type":"DOI","asserted-by":"crossref"}]},{"name":"Jiangsu Provincial NSF","award":["BK20190448"],"award-info":[{"award-number":["BK20190448"]}]},{"name":"NSF","award":["2038960"],"award-info":[{"award-number":["2038960"]}]}],"content-domain":{"domain":["dl.acm.org"],"crossmark-restriction":true},"short-container-title":["ACM Trans. Embed. Comput. Syst."],"published-print":{"date-parts":[[2022,7,31]]},"abstract":"<jats:p>The Controller Area Network (CAN) is a ubiquitous bus protocol present in the Electrical\/Electronic (E\/E) systems of almost all vehicles. It is vulnerable to a range of attacks once the attacker gains access to the bus through the vehicle\u2019s attack surface. We address the problem of Intrusion Detection on the CAN bus and present a series of methods based on two classifiers trained with Auxiliary Classifier Generative Adversarial Network (ACGAN) to detect and assign fine-grained labels to Known Attacks and also detect the Unknown Attack class in a dataset containing a mixture of (Normal + Known Attacks + Unknown Attack) messages. The most effective method is a cascaded two-stage classification architecture, with the multi-class Auxiliary Classifier in the first stage for classification of Normal and Known Attacks, passing Out-of-Distribution (OOD) samples to the binary Real-Fake Classifier in the second stage for detection of the Unknown Attack class. Performance evaluation demonstrates that our method achieves both high classification accuracy and low runtime overhead, making it suitable for deployment in the resource-constrained in-vehicle environment.<\/jats:p>","DOI":"10.1145\/3540198","type":"journal-article","created":{"date-parts":[[2022,6,3]],"date-time":"2022-06-03T08:50:21Z","timestamp":1654246221000},"page":"1-30","update-policy":"https:\/\/doi.org\/10.1145\/crossmark-policy","source":"Crossref","is-referenced-by-count":48,"title":["CAN Bus Intrusion Detection Based on Auxiliary Classifier GAN and Out-of-distribution Detection"],"prefix":"10.1145","volume":"21","author":[{"ORCID":"https:\/\/orcid.org\/0000-0003-4880-7148","authenticated-orcid":false,"given":"Qingling","family":"Zhao","sequence":"first","affiliation":[{"name":"Nanjing University of Science and Technology, Nanjing, Jiangsu, China"}],"role":[{"vocabulary":"crossref","role":"author"}]},{"ORCID":"https:\/\/orcid.org\/0000-0002-7467-4628","authenticated-orcid":false,"given":"Mingqiang","family":"Chen","sequence":"additional","affiliation":[{"name":"Nanjing University of Science and Technology, Nanjing, Jiangsu, China"}],"role":[{"vocabulary":"crossref","role":"author"}]},{"ORCID":"https:\/\/orcid.org\/0000-0003-4228-2774","authenticated-orcid":false,"given":"Zonghua","family":"Gu","sequence":"additional","affiliation":[{"name":"Ume\u00e5 University, Ume\u00e5, Sweden"}],"role":[{"vocabulary":"crossref","role":"author"}]},{"ORCID":"https:\/\/orcid.org\/0000-0002-6955-4445","authenticated-orcid":false,"given":"Siyu","family":"Luan","sequence":"additional","affiliation":[{"name":"Ume\u00e5 University, Ume\u00e5, Sweden"}],"role":[{"vocabulary":"crossref","role":"author"}]},{"ORCID":"https:\/\/orcid.org\/0000-0003-1162-759X","authenticated-orcid":false,"given":"Haibo","family":"Zeng","sequence":"additional","affiliation":[{"name":"Virginia Tech, Blacksburg, VA, USA"}],"role":[{"vocabulary":"crossref","role":"author"}]},{"ORCID":"https:\/\/orcid.org\/0000-0002-0503-6235","authenticated-orcid":false,"given":"Samarjit","family":"Chakrabory","sequence":"additional","affiliation":[{"name":"The University of North Carolina at Chapel Hill, Chapel Hill, NC, USA"}],"role":[{"vocabulary":"crossref","role":"author"}]}],"member":"320","published-online":{"date-parts":[[2022,9,5]]},"reference":[{"key":"e_1_3_4_2_2","first-page":"508","volume-title":"IEEE Intelligent Vehicles Symposium (IV)","author":"Abualhoul Mohammad Y.","year":"2016","unstructured":"Mohammad Y. Abualhoul, Oyunchimeg Shagdar, and Fawzi Nashashibi. 2016. Visible light inter-vehicle communication for platooning of autonomous vehicles. In IEEE Intelligent Vehicles Symposium (IV). IEEE, 508\u2013513."},{"key":"e_1_3_4_3_2","first-page":"622","volume-title":"Asian Conference on Computer Vision","author":"Akcay Samet","year":"2018","unstructured":"Samet Akcay, Amir Atapour-Abarghouei, and Toby P. Breckon. 2018. GANomaly: Semi-supervised anomaly detection via adversarial training. In Asian Conference on Computer Vision. Springer, 622\u2013637."},{"key":"e_1_3_4_4_2","doi-asserted-by":"publisher","DOI":"10.1109\/IJCNN.2019.8851808"},{"key":"e_1_3_4_5_2","doi-asserted-by":"publisher","DOI":"10.4236\/wet.2018.94007"},{"key":"e_1_3_4_6_2","doi-asserted-by":"publisher","DOI":"10.1109\/TITS.2020.3017882"},{"key":"e_1_3_4_7_2","doi-asserted-by":"publisher","DOI":"10.3390\/app10155062"},{"key":"e_1_3_4_8_2","volume-title":"Workshop on Automotive and Autonomous Vehicle Security (AutoSec)","author":"Bloom Gedare","year":"2021","unstructured":"Gedare Bloom. 2021. WeepingCAN: A stealthy CAN bus-off attack. In Workshop on Automotive and Autonomous Vehicle Security (AutoSec)."},{"key":"e_1_3_4_9_2","doi-asserted-by":"publisher","DOI":"10.1109\/ICIT.2017.7915557"},{"key":"e_1_3_4_10_2","doi-asserted-by":"publisher","DOI":"10.1109\/ACCESS.2020.3010274"},{"key":"e_1_3_4_11_2","doi-asserted-by":"publisher","DOI":"10.1109\/MDAT.2016.2573598"},{"key":"e_1_3_4_12_2","article-title":"Deep learning for anomaly detection: A survey","author":"Chalapathy Raghavendra","year":"2019","unstructured":"Raghavendra Chalapathy and Sanjay Chawla. 2019. Deep learning for anomaly detection: A survey. arXiv preprint arXiv:1901.03407 (2019).","journal-title":"arXiv preprint arXiv:1901.03407"},{"key":"e_1_3_4_13_2","first-page":"578","volume-title":"13th USENIX Symposium on Operating Systems Design and Implementation (OSDI\u201918)","author":"Chen Tianqi","year":"2018","unstructured":"Tianqi Chen, Thierry Moreau, Ziheng Jiang, Lianmin Zheng, Eddie Yan, Haichen Shen, Meghan Cowan, Leyuan Wang, Yuwei Hu, Luis Ceze, et\u00a0al. 2018. TVM: An automated End-to-End optimizing compiler for deep learning. In 13th USENIX Symposium on Operating Systems Design and Implementation (OSDI\u201918). 578\u2013594."},{"key":"e_1_3_4_14_2","doi-asserted-by":"publisher","DOI":"10.1145\/2976749.2978302"},{"key":"e_1_3_4_15_2","first-page":"911","volume-title":"25th USENIX Security Symposium (USENIX Security\u201916)","author":"Cho Kyong-Tak","year":"2016","unstructured":"Kyong-Tak Cho and Kang G. Shin. 2016. Fingerprinting electronic control units for vehicle intrusion detection. In 25th USENIX Security Symposium (USENIX Security\u201916). 911\u2013927."},{"key":"e_1_3_4_16_2","article-title":"Requirements on Intrusion Detection System. R20-11. Foundation. AUTOSAR. Nov. 2020","author":"Consortium The AUTOSAR","year":"2020","unstructured":"The AUTOSAR Consortium. 2020. Requirements on Intrusion Detection System. R20-11. Foundation. AUTOSAR. Nov. 2020. Retrieved from: https:\/\/www.autosar.org\/fileadmin\/user_upload\/standards\/foundation\/20-11\/AUTOSAR_RS_IntrusionDetectionSystem.pdf.","journal-title":"Retrieved from: https:\/\/www.autosar.org\/fileadmin\/user_upload\/standards\/foundation\/20-11\/AUTOSAR_RS_IntrusionDetectionSystem.pdf"},{"key":"e_1_3_4_17_2","doi-asserted-by":"publisher","DOI":"10.1109\/ACCESS.2018.2826522"},{"key":"e_1_3_4_18_2","article-title":"Adversarial feature learning","author":"Donahue Jeff","year":"2016","unstructured":"Jeff Donahue, Philipp Kr\u00e4henb\u00fchl, and Trevor Darrell. 2016. Adversarial feature learning. arXiv preprint arXiv:1605.09782 (2016).","journal-title":"arXiv preprint arXiv:1605.09782"},{"key":"e_1_3_4_19_2","doi-asserted-by":"publisher","DOI":"10.1109\/MVT.2017.2647814"},{"key":"e_1_3_4_20_2","article-title":"Generative adversarial nets","volume":"27","author":"Goodfellow Ian","year":"2014","unstructured":"Ian Goodfellow, Jean Pouget-Abadie, Mehdi Mirza, Bing Xu, David Warde-Farley, Sherjil Ozair, Aaron Courville, and Yoshua Bengio. 2014. Generative adversarial nets. Adv. Neural Inf. Process. Syst. 27 (2014).","journal-title":"Adv. Neural Inf. Process. Syst."},{"key":"e_1_3_4_21_2","article-title":"Metrics for multi-class classification: An overview","author":"Grandini Margherita","year":"2020","unstructured":"Margherita Grandini, Enrico Bagli, and Giorgio Visani. 2020. Metrics for multi-class classification: An overview. arXiv preprint arXiv:2008.05756 (2020).","journal-title":"arXiv preprint arXiv:2008.05756"},{"key":"e_1_3_4_22_2","doi-asserted-by":"publisher","DOI":"10.1109\/TPDS.2016.2520949"},{"key":"e_1_3_4_23_2","doi-asserted-by":"publisher","DOI":"10.1109\/ACCESS.2020.2982544"},{"key":"e_1_3_4_24_2","doi-asserted-by":"publisher","DOI":"10.1109\/CVPR.2016.90"},{"key":"e_1_3_4_25_2","article-title":"A baseline for detecting misclassified and out-of-distribution examples in neural networks","author":"Hendrycks Dan","year":"2016","unstructured":"Dan Hendrycks and Kevin Gimpel. 2016. A baseline for detecting misclassified and out-of-distribution examples in neural networks. arXiv preprint arXiv:1610.02136 (2016).","journal-title":"arXiv preprint arXiv:1610.02136"},{"key":"e_1_3_4_26_2","doi-asserted-by":"publisher","DOI":"10.1109\/COMPSAC48688.2020.00011"},{"key":"e_1_3_4_27_2","article-title":"A Survey of Attacks on Controller Area Networks and Corresponding Countermeasures","author":"Jo Hyo Jin","year":"2021","unstructured":"Hyo Jin Jo and Wonsuk Choi. 2021. A Survey of Attacks on Controller Area Networks and Corresponding Countermeasures. IEEE Trans. Intell. Transport. Syst. 23, 7 (2021), 6123\u20136141.","journal-title":"IEEE Trans. Intell. Transport. Syst"},{"key":"e_1_3_4_28_2","doi-asserted-by":"publisher","DOI":"10.1371\/journal.pone.0155781"},{"key":"e_1_3_4_29_2","doi-asserted-by":"publisher","DOI":"10.1109\/VTCSpring.2016.7504089"},{"key":"e_1_3_4_30_2","article-title":"OpenGAN: Open-set recognition via open data generation","author":"Kong Shu","year":"2021","unstructured":"Shu Kong and Deva Ramanan. 2021. OpenGAN: Open-set recognition via open data generation. arXiv preprint arXiv:2104.02939 (2021).","journal-title":"arXiv preprint arXiv:2104.02939"},{"key":"e_1_3_4_31_2","first-page":"195","volume-title":"IEEE Symposium on Security and Privacy (SP)","author":"Kulandaivel Sekar","year":"2021","unstructured":"Sekar Kulandaivel, Shalabh Jain, Jorge Guajardo, and Vyas Sekar. 2021. Cannon: Reliable and stealthy remote shutdown attacks via unaltered automotive microcontrollers. In IEEE Symposium on Security and Privacy (SP). IEEE, 195\u2013210."},{"key":"e_1_3_4_32_2","doi-asserted-by":"publisher","DOI":"10.1109\/MCE.2019.2941392"},{"key":"e_1_3_4_33_2","article-title":"PyTorch Implementations of Generative Adversarial Networks","author":"Linder-Nor\u00e9n Erik","year":"2019","unstructured":"Erik Linder-Nor\u00e9n. 2019. PyTorch Implementations of Generative Adversarial Networks. Retrieved from: https:\/\/github.com\/eriklindernoren\/PyTorch-GAN.","journal-title":"Retrieved from: https:\/\/github.com\/eriklindernoren\/PyTorch-GAN"},{"issue":"4","key":"e_1_3_4_34_2","first-page":"375","article-title":"Stacked sparse autoencodersbased outlier discovery for in-vehicle controller area network (CAN)","volume":"7","author":"Lokman Siti Farhana","year":"2018","unstructured":"Siti Farhana Lokman, Abu Talib Othman, Muhamad Husaini Abu Bakar, and Rizal Razuwan. 2018. Stacked sparse autoencodersbased outlier discovery for in-vehicle controller area network (CAN). Int. J. Eng. Technol. 7, 4.33 (2018), 375\u2013380.","journal-title":"Int. J. Eng. Technol."},{"key":"e_1_3_4_35_2","article-title":"CANnolo: An anomaly detection system based on LSTM autoencoders for controller area network","author":"Longari Stefano","year":"2020","unstructured":"Stefano Longari, Daniel Humberto Nova Valcarcel, Mattia Zago, Michele Carminati, and Stefano Zanero. 2020. CANnolo: An anomaly detection system based on LSTM autoencoders for controller area network. IEEE Trans. Netw. Serv. Manag. 18, 2 (2020), 1913\u20131924.","journal-title":"IEEE Trans. Netw. Serv. Manag"},{"key":"e_1_3_4_36_2","doi-asserted-by":"publisher","DOI":"10.1109\/ACCESS.2021.3108451"},{"key":"e_1_3_4_37_2","article-title":"Softwarization, virtualization, & machine learning for intelligent & effective V2X communications","author":"Moubayed Abdallah","year":"2020","unstructured":"Abdallah Moubayed and Abdallah Shami. 2020. Softwarization, virtualization, & machine learning for intelligent & effective V2X communications. arXiv preprint arXiv:2006.04595 (2020).","journal-title":"arXiv preprint arXiv:2006.04595"},{"key":"e_1_3_4_38_2","article-title":"SIG CAN XL","author":"Mutter Arthur","year":"2021","unstructured":"Arthur Mutter. 2021. SIG CAN XL. Retrieved from: https:\/\/www.can-cia.org\/groups\/technical-groups\/technical-committee-tc\/ig-lower-layers\/sig-can-xl\/.","journal-title":"Retrieved from: https:\/\/www.can-cia.org\/groups\/technical-groups\/technical-committee-tc\/ig-lower-layers\/sig-can-xl\/"},{"key":"e_1_3_4_39_2","first-page":"2642","volume-title":"International Conference on Machine Learning","author":"Odena Augustus","year":"2017","unstructured":"Augustus Odena, Christopher Olah, and Jonathon Shlens. 2017. Conditional image synthesis with auxiliary classifier gans. In International Conference on Machine Learning. PMLR, 2642\u20132651."},{"key":"e_1_3_4_40_2","doi-asserted-by":"publisher","DOI":"10.1109\/TVT.2019.2961344"},{"key":"e_1_3_4_41_2","article-title":"CANintelliIDS: Detecting in-vehicle intrusion attacks on a controller area network using CNN and attention-based GRU","author":"Rehman Abdul","year":"2021","unstructured":"Abdul Rehman, Saif Ur Rehman, Mohib Ullah Khan, Mamoun Alazab, and Thippa Reddy. 2021. CANintelliIDS: Detecting in-vehicle intrusion attacks on a controller area network using CNN and attention-based GRU. IEEE Trans. Netw. Sci. Eng. 8, 2 (2021), 1456\u20131466.","journal-title":"IEEE Trans. Netw. Sci. Eng"},{"key":"e_1_3_4_42_2","doi-asserted-by":"publisher","DOI":"10.1007\/978-3-319-59050-9_12"},{"key":"e_1_3_4_43_2","doi-asserted-by":"publisher","DOI":"10.1109\/PST.2018.8514157"},{"key":"e_1_3_4_44_2","doi-asserted-by":"publisher","DOI":"10.1109\/TVT.2021.3051026"},{"key":"e_1_3_4_45_2","doi-asserted-by":"publisher","DOI":"10.1109\/ICOIN.2016.7427089"},{"key":"e_1_3_4_46_2","doi-asserted-by":"publisher","DOI":"10.1016\/j.vehcom.2019.100198"},{"key":"e_1_3_4_47_2","doi-asserted-by":"publisher","DOI":"10.23919\/AEIT.2017.8240550"},{"key":"e_1_3_4_48_2","doi-asserted-by":"publisher","DOI":"10.1109\/DSN.2009.5270342"},{"key":"e_1_3_4_49_2","first-page":"45","volume-title":"World Congress on Industrial Control Systems Security (WCICSS\u201915)","author":"Taylor Adrian","year":"2015","unstructured":"Adrian Taylor, Nathalie Japkowicz, and Sylvain Leblanc. 2015. Frequency-based anomaly detection for the automotive CAN bus. In World Congress on Industrial Control Systems Security (WCICSS\u201915). IEEE, 45\u201349."},{"key":"e_1_3_4_50_2","doi-asserted-by":"publisher","DOI":"10.1109\/DSAA.2016.20"},{"key":"e_1_3_4_51_2","article-title":"Car-Hacking Dataset for the Intrusion Detection","author":"University Korea","year":"2018","unstructured":"Korea University. 2018. Car-Hacking Dataset for the Intrusion Detection. Retrieved from: https:\/\/ocslab.hksecurity.net\/Datasets\/car-hacking-dataset.","journal-title":"Retrieved from: https:\/\/ocslab.hksecurity.net\/Datasets\/car-hacking-dataset"},{"key":"e_1_3_4_52_2","doi-asserted-by":"publisher","DOI":"10.1109\/ACCESS.2018.2865169"},{"key":"e_1_3_4_53_2","doi-asserted-by":"publisher","DOI":"10.1109\/TITS.2019.2908074"},{"key":"e_1_3_4_54_2","doi-asserted-by":"publisher","DOI":"10.1109\/TCAD.2020.2979457"},{"key":"e_1_3_4_55_2","doi-asserted-by":"publisher","DOI":"10.1109\/TVT.2021.3061746"},{"key":"e_1_3_4_56_2","doi-asserted-by":"publisher","DOI":"10.1109\/TITS.2021.3055351"},{"key":"e_1_3_4_57_2","doi-asserted-by":"publisher","DOI":"10.1002\/spe.2965"},{"key":"e_1_3_4_58_2","doi-asserted-by":"publisher","DOI":"10.1109\/JIOT.2021.3084796"},{"key":"e_1_3_4_59_2","doi-asserted-by":"publisher","DOI":"10.1142\/S0218126621500079"},{"key":"e_1_3_4_60_2","doi-asserted-by":"publisher","DOI":"10.1109\/ACCESS.2020.3046862"}],"container-title":["ACM Transactions on Embedded Computing Systems"],"original-title":[],"language":"en","link":[{"URL":"https:\/\/dl.acm.org\/doi\/10.1145\/3540198","content-type":"unspecified","content-version":"vor","intended-application":"text-mining"},{"URL":"https:\/\/dl.acm.org\/doi\/pdf\/10.1145\/3540198","content-type":"application\/pdf","content-version":"vor","intended-application":"syndication"},{"URL":"https:\/\/dl.acm.org\/doi\/pdf\/10.1145\/3540198","content-type":"unspecified","content-version":"vor","intended-application":"similarity-checking"}],"deposited":{"date-parts":[[2025,6,17]],"date-time":"2025-06-17T17:51:01Z","timestamp":1750182661000},"score":1,"resource":{"primary":{"URL":"https:\/\/dl.acm.org\/doi\/10.1145\/3540198"}},"subtitle":[],"short-title":[],"issued":{"date-parts":[[2022,7,31]]},"references-count":59,"journal-issue":{"issue":"4","published-print":{"date-parts":[[2022,7,31]]}},"alternative-id":["10.1145\/3540198"],"URL":"https:\/\/doi.org\/10.1145\/3540198","relation":{},"ISSN":["1539-9087","1558-3465"],"issn-type":[{"value":"1539-9087","type":"print"},{"value":"1558-3465","type":"electronic"}],"subject":[],"published":{"date-parts":[[2022,7,31]]},"assertion":[{"value":"2021-12-01","order":0,"name":"received","label":"Received","group":{"name":"publication_history","label":"Publication History"}},{"value":"2022-05-01","order":1,"name":"accepted","label":"Accepted","group":{"name":"publication_history","label":"Publication History"}},{"value":"2022-09-05","order":2,"name":"published","label":"Published","group":{"name":"publication_history","label":"Publication History"}}]}}