{"status":"ok","message-type":"work","message-version":"1.0.0","message":{"indexed":{"date-parts":[[2026,6,4]],"date-time":"2026-06-04T21:58:16Z","timestamp":1780610296125,"version":"3.54.1"},"reference-count":47,"publisher":"Association for Computing Machinery (ACM)","issue":"3","content-domain":{"domain":["dl.acm.org"],"crossmark-restriction":true},"short-container-title":["ACM Trans. Cyber-Phys. Syst."],"published-print":{"date-parts":[[2025,7,31]]},"abstract":"<jats:p>The security of modern vehicles has become increasingly important, with the controller area network (CAN) bus serving as a critical communication backbone for various electronic control units (ECUs). The absence of robust security measures in CAN, coupled with the increasing connectivity of vehicles, makes them susceptible to cyberattacks. While intrusion detection systems (IDSs) have been developed to counter such threats, they are not foolproof. Adversarial attacks, particularly evasion attacks, can manipulate inputs to bypass detection by IDSs. This article extends our previous work by investigating the feasibility and impact of gradient-based adversarial attacks performed with different degrees of knowledge against automotive IDSs. We consider three scenarios: white-box (attacker with full system knowledge), grey-box (partial system knowledge), and\u2014the more realistic\u2014black-box (no knowledge of the IDS\u2019s internal workings or data). We evaluate the effectiveness of the proposed attacks against state-of-the-art IDSs on two publicly available datasets. Additionally, we study the effect of the adversarial perturbation on the attack impact and evaluate real-time feasibility by precomputing evasive payloads for timed injection based on bus traffic. Our results demonstrate that, besides attacks being challenging due to the automotive domain constraints, their effectiveness is strongly dependent on the dataset quality, the target IDS, and the attacker\u2019s degree of knowledge.<\/jats:p>","DOI":"10.1145\/3737294","type":"journal-article","created":{"date-parts":[[2025,5,29]],"date-time":"2025-05-29T11:15:29Z","timestamp":1748517329000},"page":"1-27","update-policy":"https:\/\/doi.org\/10.1145\/crossmark-policy","source":"Crossref","is-referenced-by-count":4,"title":["Assessing the Resilience of Automotive Intrusion Detection Systems to Adversarial Manipulation"],"prefix":"10.1145","volume":"9","author":[{"ORCID":"https:\/\/orcid.org\/0000-0002-7533-4510","authenticated-orcid":false,"given":"Stefano","family":"Longari","sequence":"first","affiliation":[{"name":"Dipartimento di Elettronica, Informazione e Bioingegneria, Politecnico di Milano, Milano, Italy"}],"role":[{"vocabulary":"crossref","role":"author"}]},{"ORCID":"https:\/\/orcid.org\/0009-0001-0108-9524","authenticated-orcid":false,"given":"Paolo","family":"Cerracchio","sequence":"additional","affiliation":[{"name":"Dipartimento di Elettronica, Informazione e Bioingegneria, Politecnico di Milano, Milano, Italy"}],"role":[{"vocabulary":"crossref","role":"author"}]},{"ORCID":"https:\/\/orcid.org\/0000-0001-8284-6074","authenticated-orcid":false,"given":"Michele","family":"Carminati","sequence":"additional","affiliation":[{"name":"Dipartimento di Elettronica, Informazione e Bioingegneria, Politecnico di Milano, Milano, Italy"}],"role":[{"vocabulary":"crossref","role":"author"}]},{"ORCID":"https:\/\/orcid.org\/0000-0003-4710-5283","authenticated-orcid":false,"given":"Stefano","family":"Zanero","sequence":"additional","affiliation":[{"name":"Dipartimento di Elettronica, Informazione e Bioingegneria, Politecnico di Milano, Milano, Italy"}],"role":[{"vocabulary":"crossref","role":"author"}]}],"member":"320","published-online":{"date-parts":[[2025,8,4]]},"reference":[{"key":"e_1_3_2_2_2","unstructured":"Omid Avatefipour and Malik Hafiz. 2018. State-of-the-art survey on in-vehicle network communication (CAN-Bus) security and vulnerabilities. arXiv:1802.01725. Retrieved from https:\/\/arxiv.org\/abs\/1802.01725"},{"key":"e_1_3_2_3_2","volume-title":"Symposium on Vehicles Security and Privacy (VehicleSec \u201924)","author":"Cerracchio Paolo","year":"2024","unstructured":"Paolo Cerracchio, Stefano Longari, Michele Carminati, and Stefano Zanero. 2024. Investigating the impact of evasion attacks against automotive intrusion detection systems. In Symposium on Vehicles Security and Privacy (VehicleSec \u201924)."},{"key":"e_1_3_2_4_2","unstructured":"Anirban Chakraborty Manaar Alam Vishal Dey Anupam Chattopadhyay and Debdeep Mukhopadhyay. 2018. Adversarial attacks and defences: A survey. arXiv:1810.00069. Retrieved from https:\/\/arxiv.org\/abs\/1810.00069"},{"key":"e_1_3_2_5_2","doi-asserted-by":"publisher","DOI":"10.1109\/WTS.2018.8363930"},{"issue":"7","key":"e_1_3_2_6_2","article-title":"Detecting attacks on the CAN protocol with machine learning","volume":"558","author":"Chockalingam Valliappa","year":"2016","unstructured":"Valliappa Chockalingam, Ian Larson, Daniel Lin, and Spencer Nofzinger. 2016. Detecting attacks on the CAN protocol with machine learning. Annu EECS 558, 7 (2016).","journal-title":"Annu EECS"},{"key":"e_1_3_2_7_2","unstructured":"Cia. 2025. CAN: From physical layer to application layer and beyond. Retrieved from https:\/\/www.can-cia.org\/can-knowledge"},{"key":"e_1_3_2_8_2","doi-asserted-by":"publisher","DOI":"10.1145\/3548606.3560618"},{"key":"e_1_3_2_9_2","doi-asserted-by":"publisher","DOI":"10.1109\/TSE.1987.232894"},{"key":"e_1_3_2_10_2","unstructured":"Eric Evenchick. 2025 CANtact: Open Source Car Tool. Retrieved March 21 2025 from https:\/\/cantact.io\/"},{"key":"e_1_3_2_11_2","unstructured":"Ian J. Goodfellow Jonathon Shlens and Christian Szegedy. 2014. Explaining and harnessing adversarial examples. arXiv:1412.6572. Retrieved from https:\/\/arxiv.org\/abs\/1412.6572"},{"key":"e_1_3_2_12_2","volume-title":"3rd International Conference on Learning Representations (ICLR \u201915)","author":"Goodfellow Ian J.","year":"2015","unstructured":"Ian J. Goodfellow, Jonathon Shlens, and Christian Szegedy. 2015. Explaining and harnessing adversarial examples. In 3rd International Conference on Learning Representations (ICLR \u201915). Yoshua Bengio and Yann LeCun (Eds.). arXiv:1412.6572. Retrieved from http:\/\/arxiv.org\/abs\/1412.6572"},{"key":"e_1_3_2_13_2","unstructured":"Chuan Guo Mayank Rana Moustapha Ciss\u00e9 and Laurens van der Maaten. 2017. Countering adversarial images using input transformations. arXiv:1711.00117. Retrieved from http:\/\/arxiv.org\/abs\/1711.00117"},{"key":"e_1_3_2_14_2","doi-asserted-by":"publisher","DOI":"10.1109\/ACCESS.2020.2982544"},{"key":"e_1_3_2_15_2","doi-asserted-by":"publisher","DOI":"10.1109\/GLOBECOM42002.2020.9322395"},{"key":"e_1_3_2_16_2","unstructured":"HPL Steve Corrigan. 2002. Introduction to the controller area network (CAN). Application Report SLOA101 (2002) 1\u201317."},{"key":"e_1_3_2_17_2","doi-asserted-by":"publisher","DOI":"10.1371\/journal.pone.0155781"},{"key":"e_1_3_2_18_2","unstructured":"Zadid Khan Mashrur Chowdhury Mhafuzul Islam Chin-Ya Huang and Mizanur Rahman. 2019. Long short-term memory neural networks for false information attack detection in software-defined in-vehicle network. arXiv:1906.10203. Retrieved from https:\/\/arxiv.org\/abs\/1906.10203"},{"key":"e_1_3_2_19_2","doi-asserted-by":"publisher","DOI":"10.1201\/9781351251389-8"},{"key":"e_1_3_2_20_2","doi-asserted-by":"publisher","DOI":"10.1016\/j.eswa.2023.119771"},{"key":"e_1_3_2_21_2","doi-asserted-by":"publisher","DOI":"10.1109\/CCNC49032.2021.9369569"},{"key":"e_1_3_2_22_2","doi-asserted-by":"crossref","unstructured":"Stefano Longari Alessandro Nichelini Carlo Alberto Pozzoli Michele Carminati and Stefano Zanero. 2022. CANdito: Improving payload-based detection of attacks on controller area networks. arXiv:2208.06628. Retrieved from https:\/\/arxiv.org\/abs\/2208.06628","DOI":"10.1007\/978-3-031-34671-2_10"},{"key":"e_1_3_2_23_2","doi-asserted-by":"publisher","DOI":"10.1007\/978-3-031-34671-2_24"},{"issue":"2","key":"e_1_3_2_24_2","doi-asserted-by":"crossref","first-page":"1913","DOI":"10.1109\/TNSM.2020.3038991","article-title":"CANnolo: An anomaly detection system based on LSTM autoencoders for controller area network","volume":"18","author":"Longari Stefano","year":"2020","unstructured":"Stefano Longari, Daniel Humberto Nova Valcarcel, Mattia Zago, Michele Carminati, and Stefano Zanero. 2020. CANnolo: An anomaly detection system based on LSTM autoencoders for controller area network. IEEE Transactions on Network and Service Management 18, 2 (2020), 1913\u20131924.","journal-title":"IEEE Transactions on Network and Service Management"},{"key":"e_1_3_2_25_2","doi-asserted-by":"publisher","DOI":"10.1109\/TIFS.2018.2870826"},{"key":"e_1_3_2_26_2","volume-title":"Remote Exploitation of an Unaltered Passenger Vehicle","author":"Miller Charlie","year":"2015","unstructured":"Charlie Miller and Chris Valasek. 2015. Remote Exploitation of an Unaltered Passenger Vehicle. Black Hat, USA."},{"key":"e_1_3_2_27_2","unstructured":"Charlie Miller and Chris Valasek. 2016. CAN Message Injection. Retrieved October 1 2022 from https:\/\/illmatics.com\/can%20message%20injection.pdf"},{"key":"e_1_3_2_28_2","first-page":"1","volume-title":"12th Annual Conference on Cyber and Information Security Research","author":"Moore Michael R.","year":"2017","unstructured":"Michael R. Moore, Robert A. Bridges, Frank L. Combs, Michael S. Starr, and Stacy J. Prowell. 2017. Modeling inter-signal arrival times for accurate detection of can bus signal injection attacks: A data-driven approach to in-vehicle intrusion detection. In 12th Annual Conference on Cyber and Information Security Research, 1\u20134."},{"key":"e_1_3_2_29_2","doi-asserted-by":"publisher","DOI":"10.1109\/CVPR.2016.282"},{"key":"e_1_3_2_30_2","doi-asserted-by":"publisher","DOI":"10.1016\/j.cose.2023.103166"},{"key":"e_1_3_2_31_2","doi-asserted-by":"publisher","DOI":"10.1145\/3052973.3053009"},{"key":"e_1_3_2_32_2","doi-asserted-by":"crossref","first-page":"582","DOI":"10.1109\/SP.2016.41","volume-title":"2016 IEEE Symposium on Security and Privacy (SP)","author":"Papernot Nicolas","year":"2016","unstructured":"Nicolas Papernot, Patrick McDaniel, Xi Wu, Somesh Jha, and Ananthram Swami. 2016. Distillation as a defense to adversarial perturbations against deep neural networks. In 2016 IEEE Symposium on Security and Privacy (SP). IEEE, 582\u2013597."},{"key":"e_1_3_2_33_2","first-page":"11","article-title":"AI-based intrusion detection systems for in-vehicle networks: A survey","volume":"55","author":"Rajapaksha Sampath","year":"2023","unstructured":"Sampath Rajapaksha, Harsha Kalutarage, M. Omar Al-Kadri, Andrei Petrovski, Garikayi Madzudzo, and Madeline Cheah. 2023. AI-based intrusion detection systems for in-vehicle networks: A survey. Computing Surveys 55 (2023), 11.","journal-title":"Computing Surveys"},{"key":"e_1_3_2_34_2","first-page":"730","volume-title":"2021 Intelligent Systems Conference and Applications (IntelliSys)","volume":"3","author":"Rafi Ud Daula","year":"2022","unstructured":"Daula Rafi Ud, Abdulrahman Refat, Elkhail Abu, Hafeez Azeem, and Hafiz Malik. 2022. Detecting CAN bus intrusion by applying machine learning method to graph based features. In 2021 Intelligent Systems Conference and Applications (IntelliSys), Vol. 3. Springer, 730\u2013748."},{"key":"e_1_3_2_35_2","doi-asserted-by":"publisher","DOI":"10.3390\/app12136451"},{"key":"e_1_3_2_36_2","doi-asserted-by":"publisher","DOI":"10.1109\/PST.2018.8514157"},{"key":"e_1_3_2_37_2","doi-asserted-by":"publisher","DOI":"10.1109\/SPW50608.2020.00028"},{"key":"e_1_3_2_38_2","doi-asserted-by":"publisher","DOI":"10.1016\/j.vehcom.2019.100198"},{"key":"e_1_3_2_39_2","unstructured":"Christian Szegedy Wojciech Zaremba Ilya Sutskever Joan Bruna Dumitru Erhan Ian Goodfellow and Rob Fergus. 2013. Intriguing properties of neural networks. arXiv:1312.6199. Retrieved from https:\/\/arxiv.org\/abs\/1312.6199"},{"key":"e_1_3_2_40_2","volume-title":"2nd International Conference on Learning Representations (ICLR \u201914)","author":"Szegedy Christian","year":"2014","unstructured":"Christian Szegedy, Wojciech Zaremba, Ilya Sutskever, Joan Bruna, Dumitru Erhan, Ian J. Goodfellow, and Rob Fergus. 2014. Intriguing properties of neural networks. In 2nd International Conference on Learning Representations (ICLR \u201914). Yoshua Bengio and Yann LeCun (Eds.)."},{"key":"e_1_3_2_41_2","doi-asserted-by":"publisher","DOI":"10.1109\/OJITS.2020.3043066"},{"key":"e_1_3_2_42_2","doi-asserted-by":"publisher","DOI":"10.1109\/WCICSS.2015.7420322"},{"key":"e_1_3_2_43_2","doi-asserted-by":"publisher","DOI":"10.1109\/DSAA.2016.20"},{"key":"e_1_3_2_44_2","first-page":"231","volume-title":"In 2018 48th Annual IEEE\/IFIP International Conference on Dependable Systems and Networks Workshops (DSN-W)","author":"Tomlinson Andrew","year":"2018","unstructured":"Andrew Tomlinson, Jeremy Bryans, Siraj Ahmed Shaikh, and Harsha Kumara Kalutarage. 2018. Detection of automotive CAN cyber-attacks by identifying packet timing anomalies in time windows. In 2018 48th Annual IEEE\/IFIP International Conference on Dependable Systems and Networks Workshops (DSN-W). IEEE, 231\u2013238."},{"key":"e_1_3_2_45_2","unstructured":"Miki E. Verma Michael D. Iannacone Robert A. Bridges Samuel C. Hollifield Pablo Moriano Bill Kay and Frank L. Combs. 2022. Addressing the lack of comparability & testing in CAN intrusion detection research: A comprehensive guide to CAN IDS data & introduction of the ROAD dataset. arXiv:2012.14600. Retrieved from https:\/\/arxiv.org\/abs\/2012.14600"},{"key":"e_1_3_2_46_2","unstructured":"Eric Wong Leslie Rice and J. Zico Kolter. 2020. Fast is better than free: Revisiting adversarial training. arXiv:2001.03994. Retrieved from https:\/\/arxiv.org\/abs\/2001.03994"},{"key":"e_1_3_2_47_2","unstructured":"Kaichao You Mingsheng Long Jianmin Wang and Michael I. Jordan. 2019. How does learning rate decay help modern neural networks? arXiv:1908.01878. Retrieved from https:\/\/arxiv.org\/abs\/1908.01878"},{"key":"e_1_3_2_48_2","doi-asserted-by":"crossref","first-page":"105149","DOI":"10.1016\/j.dib.2020.105149","article-title":"ReCAN\u2013dataset for reverse engineering of controller area networks","volume":"29","author":"Zago Mattia","year":"2020","unstructured":"Mattia Zago, Stefano Longari, Andrea Tricarico, Michele Carminati, Manuel Gil P\u00e9rez, Gregorio Mart\u00ecnez P\u00e9rez, and Stefano Zanero. 2020. ReCAN\u2013dataset for reverse engineering of controller area networks. Data in Brief 29 (2020), 105149.","journal-title":"Data in Brief"}],"container-title":["ACM Transactions on Cyber-Physical Systems"],"original-title":[],"language":"en","link":[{"URL":"https:\/\/dl.acm.org\/doi\/pdf\/10.1145\/3737294","content-type":"unspecified","content-version":"vor","intended-application":"similarity-checking"}],"deposited":{"date-parts":[[2025,8,4]],"date-time":"2025-08-04T15:54:07Z","timestamp":1754322847000},"score":1,"resource":{"primary":{"URL":"https:\/\/dl.acm.org\/doi\/10.1145\/3737294"}},"subtitle":[],"short-title":[],"issued":{"date-parts":[[2025,7,31]]},"references-count":47,"journal-issue":{"issue":"3","published-print":{"date-parts":[[2025,7,31]]}},"alternative-id":["10.1145\/3737294"],"URL":"https:\/\/doi.org\/10.1145\/3737294","relation":{},"ISSN":["2378-962X","2378-9638"],"issn-type":[{"value":"2378-962X","type":"print"},{"value":"2378-9638","type":"electronic"}],"subject":[],"published":{"date-parts":[[2025,7,31]]},"assertion":[{"value":"2024-09-16","order":0,"name":"received","label":"Received","group":{"name":"publication_history","label":"Publication History"}},{"value":"2025-05-18","order":2,"name":"accepted","label":"Accepted","group":{"name":"publication_history","label":"Publication History"}},{"value":"2025-08-04","order":3,"name":"published","label":"Published","group":{"name":"publication_history","label":"Publication History"}}]}}