{"status":"ok","message-type":"work","message-version":"1.0.0","message":{"indexed":{"date-parts":[[2026,2,5]],"date-time":"2026-02-05T07:00:34Z","timestamp":1770274834529,"version":"3.49.0"},"reference-count":33,"publisher":"MDPI AG","issue":"14","license":[{"start":{"date-parts":[[2020,7,15]],"date-time":"2020-07-15T00:00:00Z","timestamp":1594771200000},"content-version":"vor","delay-in-days":0,"URL":"https:\/\/creativecommons.org\/licenses\/by\/4.0\/"}],"funder":[{"DOI":"10.13039\/501100010418","name":"Institute for Information and Communications Technology Promotion","doi-asserted-by":"publisher","award":["2018-0-00532"],"award-info":[{"award-number":["2018-0-00532"]}],"id":[{"id":"10.13039\/501100010418","id-type":"DOI","asserted-by":"publisher"}]}],"content-domain":{"domain":[],"crossmark-restriction":false},"short-container-title":["Sensors"],"abstract":"<jats:p>The communication and connectivity functions of vehicles increase their vulnerability to hackers. The unintended failure and malfunction of in-vehicle systems caused by external factors threaten the security and safety of passengers. As the controller area network alone cannot protect vehicles from external attacks, techniques to analyze and detect external attacks are required. Therefore, we propose a multi-labeled hierarchical classification (MLHC) intrusion detection model that analyzes and detects external attacks caused by message injection. This model quickly determines the occurrence of attacks and classifies the attack using only existing classified attack data. We evaluated the performance of the model by analyzing its learning space. We further verified the model by comparing its accuracy, F1 score and data learning and evaluation times with the two layers multi-class detection (TLMD) and single-layer multi-class classification (SLMC) models. The simulation results show that the MLHC model has the highest F1 score of 0.9995 and is 87.30% and 99.92% faster than the SLMC and TLMD models in terms of detection time, respectively. Consequently, the proposed model can classify both the type and existence or absence of attacks with high accuracy and can be used in interior communication environments of high-speed vehicles with a high throughput.<\/jats:p>","DOI":"10.3390\/s20143934","type":"journal-article","created":{"date-parts":[[2020,7,16]],"date-time":"2020-07-16T10:54:46Z","timestamp":1594896886000},"page":"3934","update-policy":"https:\/\/doi.org\/10.3390\/mdpi_crossmark_policy","source":"Crossref","is-referenced-by-count":20,"title":["Hierarchical Anomaly Detection Model for In-Vehicle Networks Using Machine Learning Algorithms"],"prefix":"10.3390","volume":"20","author":[{"ORCID":"https:\/\/orcid.org\/0000-0001-5260-1252","authenticated-orcid":false,"given":"Seunghyun","family":"Park","sequence":"first","affiliation":[{"name":"School of Cybersecurity, Korea University, Seoul 02841, Korea"}],"role":[{"role":"author","vocabulary":"crossref"}]},{"ORCID":"https:\/\/orcid.org\/0000-0002-8100-7583","authenticated-orcid":false,"given":"Jin-Young","family":"Choi","sequence":"additional","affiliation":[{"name":"School of Cybersecurity, Korea University, Seoul 02841, Korea"}],"role":[{"role":"author","vocabulary":"crossref"}]}],"member":"1968","published-online":{"date-parts":[[2020,7,15]]},"reference":[{"key":"ref_1","unstructured":"Miller, C., and Valasek, C. (2015, January 1\u20136). Remote Exploitation of an Unaltered Passenger Vehicle. Proceedings of the Black Hat USA 2015, Las Vegas, NV, USA."},{"key":"ref_2","doi-asserted-by":"crossref","first-page":"7","DOI":"10.1109\/MDAT.2018.2863106","article-title":"Lessons learned from hacking a car","volume":"36","author":"Miller","year":"2019","journal-title":"IEEE Des. Test"},{"key":"ref_3","first-page":"100198","article-title":"In-vehicle network intrusion detection using deep convolutional neural network","volume":"21","author":"Song","year":"2020","journal-title":"Veh. Commun."},{"key":"ref_4","doi-asserted-by":"crossref","first-page":"21","DOI":"10.1109\/TIT.1967.1053964","article-title":"Nearest Neighbor Pattern Classification","volume":"13","author":"Cover","year":"1967","journal-title":"IEEE Trans. Inf. Theory"},{"key":"ref_5","doi-asserted-by":"crossref","first-page":"81","DOI":"10.1007\/BF00116251","article-title":"Induction of Decision Trees","volume":"1","author":"Quinlan","year":"1986","journal-title":"Mach. Learn."},{"key":"ref_6","doi-asserted-by":"crossref","first-page":"37004","DOI":"10.1109\/ACCESS.2019.2905041","article-title":"Network Intrusion Detection: Based on Deep Hierarchical Network and Original Flow Data","volume":"7","author":"Zhang","year":"2019","journal-title":"IEEE Access"},{"key":"ref_7","first-page":"1","article-title":"Intrusion detection system using deep neural network for in-vehicle network security","volume":"11","author":"Kang","year":"2016","journal-title":"PLoS ONE"},{"key":"ref_8","doi-asserted-by":"crossref","first-page":"11","DOI":"10.1016\/j.ress.2010.06.026","article-title":"Security threats to automotive CAN networks Practical examples and selected short-term countermeasures","volume":"96","author":"Hoppe","year":"2011","journal-title":"Reliab. Eng. Syst. Saf."},{"key":"ref_9","doi-asserted-by":"crossref","unstructured":"Taylor, A., Leblanc, S., and Japkowicz, N. (2016, January 17\u201319). Anomaly detection in automobile control network data with long short-term memory networks. Proceedings of the IEEE International Conference on Data Science and Advanced Analytics (DSAA 2016), Montreal, QC, Canada.","DOI":"10.1109\/DSAA.2016.20"},{"key":"ref_10","doi-asserted-by":"crossref","first-page":"9091","DOI":"10.1109\/ACCESS.2018.2799210","article-title":"A Distributed Anomaly Detection System for In-Vehicle Network Using HTM","volume":"6","author":"Wang","year":"2018","journal-title":"IEEE Access"},{"key":"ref_11","first-page":"823","article-title":"Automotive Serial Controller Area Network","volume":"95","author":"Kiencke","year":"1986","journal-title":"SAE Trans."},{"key":"ref_12","unstructured":"International Organization for Standardization (ISO) (2020, July 15). ISO 11898-1: 2015 Controller Area Network (CAN). Available online: https:\/\/www.iso.org\/standard\/63648.html."},{"key":"ref_13","doi-asserted-by":"crossref","unstructured":"Cho, K.T., and Shin, K.G. (2016, January 24\u201328). Error Handling of In-vehicle Networks Makes Them Vulnerable. Proceedings of the 2016 ACM SIGSAC Conference on Computer and Communications Security, Vienna, Austria.","DOI":"10.1145\/2976749.2978302"},{"key":"ref_14","unstructured":"Checkoway, S., McCoy, D., Kantor, B., Anderson, D., Shacham, H., Savage, S., Koscher, K., Czeskis, A., Roesner, F., and Kohno, T. (2011, January 10\u201312). Comprehensive experimental analyses of automotive attack surfaces. Proceedings of the 20th USENIX Security Symposium, San Francisco, CA, USA."},{"key":"ref_15","first-page":"993","article-title":"A Practical Wireless Attack on the Connected Car and Security Protocol for In-Vehicle CAN","volume":"16","author":"Woo","year":"2015","journal-title":"IEEE Trans. Intell. Transp. Syst."},{"key":"ref_16","first-page":"153","article-title":"Threats and Countermeasures of Cyber Security in Direct and Remote Vehicle Communication Systems","volume":"15","author":"Bharati","year":"2020","journal-title":"J. Inf. Assur. Secur."},{"key":"ref_17","doi-asserted-by":"crossref","unstructured":"Koscher, K., Czeskis, A., Roesner, F., Patel, S., Kohno, T., Checkoway, S., McCoy, D., Kantor, B., Anderson, D., and Shacham, H. (2010, January 16\u201319). Experimental security analysis of a modern automobile. Proceedings of the 2010 IEEE Symposium on Security and Privacy, Berkeley\/Oakland, CA, USA.","DOI":"10.1109\/SP.2010.34"},{"key":"ref_18","doi-asserted-by":"crossref","unstructured":"Vasenev, A., Stahl, F., Hamazaryan, H., Ma, Z., Shan, L., Kemmerich, J., and Loiseaux, C. (2019, January 3\u20135). Practical Security and Privacy Threat Analysis in the Automotive Domain: Long Term Support Scenario for Over-the-Air Updates. Proceedings of the 5th International Conference on Vehicle Technology and Intelligent Transport Systems (VEHITS 2019), Heraklion, Crete, Greece.","DOI":"10.5220\/0007764200002179"},{"key":"ref_19","doi-asserted-by":"crossref","unstructured":"Steger, M., Dorri, A., Kanhere, S.S., R\u00f6mer, K., Jurdak, R., and Karner, M. (2017, January 25\u201326). Secure Wireless Automotive Software Updates Using Blockchains: A Proof of Concept. Proceedings of the Advanced Microsystems for Automotive Applications (AMAA 2017), Berlin, Germany.","DOI":"10.1007\/978-3-319-66972-4_12"},{"key":"ref_20","unstructured":"Van Bulck, J., M\u00f6hlberg, J.T., and Piessens, F. (2017, January 4\u20138). VulCAN: Efficient component authentication and software isolation for automotive control networks. Proceedings of the 33rd Annual Computer Security Applications Conference (ACSAC 2017), Orlando, FL, USA."},{"key":"ref_21","doi-asserted-by":"crossref","first-page":"2114","DOI":"10.1109\/TIFS.2018.2812149","article-title":"VoltageIDS: Low-level communication characteristics for automotive intrusion detection system","volume":"13","author":"Choi","year":"2018","journal-title":"IEEE Trans. Inf. Forensics Secur."},{"key":"ref_22","doi-asserted-by":"crossref","unstructured":"Wang, E., Xu, W., Sastry, S., Liu, S., and Zeng, K. (2017, January 18\u201321). Hardware Module-based Message Authentication in Intra-Vehicle Networks. Proceedings of the 2017 ACM\/IEEE 8th International Conference on Cyber-Physical Systems (ICCPS), Pittsburgh, PA, USA.","DOI":"10.1145\/3055004.3055016"},{"key":"ref_23","doi-asserted-by":"crossref","unstructured":"Narayanan, S.N., Mittal, S., and Joshi, A. (2016, January 18\u201320). OBD-SecureAlert: An Anomaly Detection System for Vehicles. Proceedings of the IEEE International Conference on Smart Computing (SMARTCOMP 2016), St. Louis, MO, USA.","DOI":"10.1109\/SMARTCOMP.2016.7501710"},{"key":"ref_24","doi-asserted-by":"crossref","unstructured":"Martinelli, F., Mercaldo, F., Nardone, V., and Santone, A. (2017, January 9\u201312). Car Hacking Identification through Fuzzy Logic Algorithms. Proceedings of the IEEE International Conference on Fuzzy Systems (FUZZ-IEEE), Naples, Italy.","DOI":"10.1109\/FUZZ-IEEE.2017.8015464"},{"key":"ref_25","unstructured":"Tencent Keen Security Lab (2020, July 10). Experimental Security Assessment on Lexus Cars. Available online: https:\/\/keenlab.tencent.com\/en\/2020\/03\/30\/Tencent-Keen-Security-Lab-Experimental-Security-Assessment-on-Lexus-Cars\/."},{"key":"ref_26","doi-asserted-by":"crossref","first-page":"15521","DOI":"10.1109\/ACCESS.2019.2892961","article-title":"CAN ID Shuffling Technique (CIST): Moving Target Defense Strategy for Protecting In-Vehicle CAN","volume":"7","author":"Woo","year":"2019","journal-title":"IEEE Access"},{"key":"ref_27","first-page":"52","article-title":"Anomaly intrusion detection method for vehicular networks based on survival analysis","volume":"14","author":"Han","year":"2018","journal-title":"Veh. Commun."},{"key":"ref_28","doi-asserted-by":"crossref","first-page":"3035741","DOI":"10.1155\/2020\/3035741","article-title":"Malware Detection in Self-Driving Vehicles Using Machine Learning Algorithms","volume":"2020","author":"Park","year":"2020","journal-title":"J. Adv. Transp."},{"key":"ref_29","unstructured":"Yuan, Y., Huo, L., and Hogrefe, D. (2017, January 3\u20136). Two Layers Multi-class Detection Method for Network Intrusion Detection System. Proceedings of the 2017 IEEE Symposium on Computers and Communications (ISCC), Heraklion, Crete, Greece."},{"key":"ref_30","doi-asserted-by":"crossref","first-page":"225","DOI":"10.1016\/j.ins.2017.06.007","article-title":"A novel weighted support vector machines multiclass classifier based on differential evolution for intrusion detection systems","volume":"414","author":"Aburomman","year":"2017","journal-title":"Inf. Sci."},{"key":"ref_31","doi-asserted-by":"crossref","first-page":"400","DOI":"10.1214\/aoms\/1177729586","article-title":"A Stochastic Approximation Method","volume":"22","author":"Robbins","year":"1951","journal-title":"Ann. Math. Stat."},{"key":"ref_32","doi-asserted-by":"crossref","first-page":"5","DOI":"10.1023\/A:1010933404324","article-title":"Random forests","volume":"45","author":"Breiman","year":"2001","journal-title":"Mach. Learn."},{"key":"ref_33","doi-asserted-by":"crossref","first-page":"2023","DOI":"10.1109\/TMC.2017.2684167","article-title":"Smartphone-based real time vehicle tracking in indoor parking structures","volume":"16","author":"Gao","year":"2017","journal-title":"IEEE Trans. Mob. Comput."}],"container-title":["Sensors"],"original-title":[],"language":"en","link":[{"URL":"https:\/\/www.mdpi.com\/1424-8220\/20\/14\/3934\/pdf","content-type":"unspecified","content-version":"vor","intended-application":"similarity-checking"}],"deposited":{"date-parts":[[2025,10,11]],"date-time":"2025-10-11T09:48:40Z","timestamp":1760176120000},"score":1,"resource":{"primary":{"URL":"https:\/\/www.mdpi.com\/1424-8220\/20\/14\/3934"}},"subtitle":[],"short-title":[],"issued":{"date-parts":[[2020,7,15]]},"references-count":33,"journal-issue":{"issue":"14","published-online":{"date-parts":[[2020,7]]}},"alternative-id":["s20143934"],"URL":"https:\/\/doi.org\/10.3390\/s20143934","relation":{},"ISSN":["1424-8220"],"issn-type":[{"value":"1424-8220","type":"electronic"}],"subject":[],"published":{"date-parts":[[2020,7,15]]}}}