{"status":"ok","message-type":"work","message-version":"1.0.0","message":{"indexed":{"date-parts":[[2026,7,23]],"date-time":"2026-07-23T16:10:58Z","timestamp":1784823058628,"version":"3.55.0"},"reference-count":51,"publisher":"MDPI AG","issue":"7","license":[{"start":{"date-parts":[[2023,3,30]],"date-time":"2023-03-30T00:00:00Z","timestamp":1680134400000},"content-version":"vor","delay-in-days":0,"URL":"https:\/\/creativecommons.org\/licenses\/by\/4.0\/"}],"content-domain":{"domain":[],"crossmark-restriction":false},"short-container-title":["Sensors"],"abstract":"<jats:p>Electronic Control Units (ECUs) have been increasingly used in modern vehicles to control the operations of the vehicle, improve driving comfort, and safety. For the operation of the vehicle, these ECUs communicate using a Controller Area Network (CAN) protocol that has many security vulnerabilities. According to the report of Upstream 2022, more than 900 automotive cybersecurity incidents were reported in 2021 only. In addition to developing a more secure CAN protocol, intrusion detection can provide a path to mitigate cyberattacks on the vehicle. This paper proposes a machine learning-based intrusion detection system (IDS) using a Support Vector Machine (SVM), Decision Tree (DT), and K-Nearest Neighbor (KNN) and investigates the effectiveness of the IDS using multiple real-world datasets. The novelty of our developed IDS is that it has been trained and tested on multiple vehicular datasets (Kia Soul and a Chevrolet Spark) to detect and classify intrusion. Our IDS has achieved accuracy up to 99.9% with a high true positive and a low false negative rate. Finally, the comparison of our performance evaluation outcomes demonstrates that the proposed IDS outperforms the existing works in terms of its liability and efficiency to detect cyber-attacks with a minimal error rate.<\/jats:p>","DOI":"10.3390\/s23073610","type":"journal-article","created":{"date-parts":[[2023,3,31]],"date-time":"2023-03-31T02:08:01Z","timestamp":1680228481000},"page":"3610","update-policy":"https:\/\/doi.org\/10.3390\/mdpi_crossmark_policy","source":"Crossref","is-referenced-by-count":66,"title":["Intrusion Detection in Vehicle Controller Area Network (CAN) Bus Using Machine Learning: A Comparative Performance Study"],"prefix":"10.3390","volume":"23","author":[{"given":"Bifta Sama","family":"Bari","sequence":"first","affiliation":[{"name":"Department of Electrical and Computer Engineering, Tennessee Tech University, Cookeville, TN 38501, USA"}],"role":[{"vocabulary":"crossref","role":"author"}]},{"ORCID":"https:\/\/orcid.org\/0000-0002-0072-3909","authenticated-orcid":false,"given":"Kumar","family":"Yelamarthi","sequence":"additional","affiliation":[{"name":"Department of Electrical and Computer Engineering, Tennessee Tech University, Cookeville, TN 38501, USA"}],"role":[{"vocabulary":"crossref","role":"author"}]},{"ORCID":"https:\/\/orcid.org\/0000-0001-7175-1619","authenticated-orcid":false,"given":"Sheikh","family":"Ghafoor","sequence":"additional","affiliation":[{"name":"Department of Computer Science, Tennessee Tech University, Cookeville, TN 38501, USA"}],"role":[{"vocabulary":"crossref","role":"author"}]}],"member":"1968","published-online":{"date-parts":[[2023,3,30]]},"reference":[{"key":"ref_1","doi-asserted-by":"crossref","first-page":"162401","DOI":"10.1109\/ACCESS.2021.3130495","article-title":"Vehicle Security: A Survey of Security Issues and Vulnerabilities, Malware Attacks and Defenses","volume":"9","author":"Elkhail","year":"2021","journal-title":"IEEE Access"},{"key":"ref_2","doi-asserted-by":"crossref","first-page":"899","DOI":"10.1016\/j.mechatronics.2005.05.002","article-title":"Development of the Electronic Control Unit for the Rack-Actuating Steer-by-Wire Using the Hardware-in-the-Loop Simulation System","volume":"15","author":"Park","year":"2005","journal-title":"Mechatronics"},{"key":"ref_3","unstructured":"Ring, M., Frkat, D., and Schmiedecker, M. (2018, January 13\u201314). Cyber Security Evaluation of Automotive E\/E Architectures. Proceedings of the ACM Computer Science in Cars Symposium (CSCS 2018), Munich, Germany."},{"key":"ref_4","doi-asserted-by":"crossref","unstructured":"Koundal, D., Ramadan, R.A., Corchado, J.M., Aldhyani, T.H.H., and Alkahtani, H. (2022). Attacks to Automatous Vehicles: A Deep Learning Algorithm for Cybersecurity. Sensors, 22.","DOI":"10.3390\/s22010360"},{"key":"ref_5","doi-asserted-by":"crossref","first-page":"399","DOI":"10.1016\/j.dcan.2020.04.007","article-title":"Attacks and Defences on Intelligent Connected Vehicles: A Survey","volume":"6","author":"Dibaei","year":"2020","journal-title":"Digit. Commun. Netw."},{"key":"ref_6","doi-asserted-by":"crossref","first-page":"4660","DOI":"10.1109\/TITS.2021.3053942","article-title":"AI-Enabled Fingerprinting and Crowdsource-Based Vehicle Localization for Resilient and Safe Transportation Systems","volume":"22","author":"Shit","year":"2021","journal-title":"IEEE Trans. Intell. Transp. Syst."},{"key":"ref_7","doi-asserted-by":"crossref","unstructured":"Kang, M.J., and Kang, J.W. (2016). Intrusion Detection System Using Deep Neural Network for In-Vehicle Network Security. PLoS ONE, 11.","DOI":"10.1371\/journal.pone.0155781"},{"key":"ref_8","doi-asserted-by":"crossref","first-page":"5015","DOI":"10.1109\/JIOT.2018.2867917","article-title":"Analyzing and Enhancing the Security of Ultrasonic Sensors for Autonomous Vehicles","volume":"5","author":"Xu","year":"2018","journal-title":"IEEE Internet Things J."},{"key":"ref_9","doi-asserted-by":"crossref","unstructured":"Kamal, M., and Talbert, D.A. (2020, January 10\u201313). Toward Never-Ending Learner for Malware Analysis (NELMA). Proceedings of the 2020 IEEE International Conference on Big Data, Atlanta, GA, USA.","DOI":"10.1109\/BigData50022.2020.9378357"},{"key":"ref_10","first-page":"39","article-title":"0-Days & Mitigations: Roadways to Exploit and Secure Connected BMW Cars","volume":"2019","author":"Cai","year":"2019","journal-title":"Black Hat USA"},{"key":"ref_11","doi-asserted-by":"crossref","unstructured":"Lee, H., Jeong, S.H., and Kim, H.K. (2017, January 28\u201330). OTIDS: A Novel Intrusion Detection System for in-Vehicle Network by Using Remote Frame. Proceedings of the 2017 15th Annual Conference on Privacy, Security and Trust, PST 2017, Calgary, AB, Canada.","DOI":"10.1109\/PST.2017.00017"},{"key":"ref_12","doi-asserted-by":"crossref","first-page":"169","DOI":"10.1049\/iet-net.2018.5171","article-title":"Trusted FPGA-Based Transport Traffic Inject, Impersonate (I2) Attacks Beaconing in the Internet of Vehicles","volume":"8","author":"Appathurai","year":"2019","journal-title":"IET Netw."},{"key":"ref_13","doi-asserted-by":"crossref","first-page":"45233","DOI":"10.1109\/ACCESS.2018.2865169","article-title":"Sliding Window Optimized Information Entropy Analysis Method for Intrusion Detection on In-Vehicle Networks","volume":"6","author":"Wu","year":"2018","journal-title":"IEEE Access"},{"key":"ref_14","doi-asserted-by":"crossref","first-page":"2941","DOI":"10.1109\/TIFS.2021.3069171","article-title":"Event-Triggered Interval-Based Anomaly Detection and Attack Identification Methods for an In-Vehicle Network","volume":"16","author":"Han","year":"2021","journal-title":"IEEE Trans. Inf. Forensics Secur."},{"key":"ref_15","doi-asserted-by":"crossref","first-page":"1037","DOI":"10.1109\/TIFS.2018.2869351","article-title":"Efficient Intrusion Detection with Bloom Filtering in Controller Area Networks","volume":"14","author":"Groza","year":"2019","journal-title":"IEEE Trans. Inf. Forensics Secur."},{"key":"ref_16","first-page":"100416","article-title":"LoRCA: Lightweight Round Block and Stream Cipher Algorithms for IoV Systems","volume":"34","author":"Noura","year":"2022","journal-title":"Veh. Commun."},{"key":"ref_17","doi-asserted-by":"crossref","first-page":"264","DOI":"10.1016\/j.patrec.2020.04.038","article-title":"Securing the Internet of Vehicles through Lightweight Block Ciphers","volume":"135","author":"Castiglione","year":"2020","journal-title":"Pattern Recognit. Lett."},{"key":"ref_18","doi-asserted-by":"crossref","first-page":"1","DOI":"10.1145\/2960407","article-title":"Security in Automotive Networks: Lightweight Authentication and Authorization","volume":"22","author":"Mundhenk","year":"2017","journal-title":"ACM Trans. Des. Autom. Electron. Syst."},{"key":"ref_19","doi-asserted-by":"crossref","unstructured":"Sun, X., Yan, B., Zhang, X., and Rong, C. (2015). An Integrated Intrusion Detection Model of Cluster-Based Wireless Sensor Network. PLoS ONE, 10.","DOI":"10.1371\/journal.pone.0139513"},{"key":"ref_20","first-page":"993","article-title":"A Practical Wireless Attack on the Connected Car and Security Protocol for In-Vehicle CAN","volume":"16","author":"Woo","year":"2015","journal-title":"IEEE Trans. Intell. Transp. Syst."},{"key":"ref_21","doi-asserted-by":"crossref","first-page":"99595","DOI":"10.1109\/ACCESS.2021.3095962","article-title":"Comparative Performance Evaluation of Intrusion Detection Based on Machine Learning in In-Vehicle Controller Area Network Bus","volume":"9","author":"Moulahi","year":"2021","journal-title":"IEEE Access"},{"key":"ref_22","doi-asserted-by":"crossref","first-page":"103","DOI":"10.1504\/IJMIC.2019.096792","article-title":"Self-Adaptative Multi-Kernel Algorithm for Switched Linear Systems Identification","volume":"31","author":"Sellami","year":"2019","journal-title":"Int. J. Model. Identif. Control"},{"key":"ref_23","doi-asserted-by":"crossref","unstructured":"Emperuman, M., and Chandrasekaran, S. (2020). Hybrid Continuous Density Hmm-Based Ensemble Neural Networks for Sensor Fault Detection and Classification in Wireless Sensor Network. Sensors, 20.","DOI":"10.3390\/s20030745"},{"key":"ref_24","doi-asserted-by":"crossref","first-page":"1","DOI":"10.1016\/j.inffus.2018.09.013","article-title":"Machine Learning Algorithms for Wireless Sensor Networks: A Survey","volume":"49","author":"Amgoth","year":"2019","journal-title":"Inf. Fusion"},{"key":"ref_25","doi-asserted-by":"crossref","unstructured":"Perakovi, D., Delia Jurcut, A., Markovi, G., Jhansi Kattamuri, S., Kiran Varma Penmatsa, R., Chakravarty, S., and Sai Pavan Madabathula, V. (2023). Swarm Optimization and Machine Learning Applied to PE Malware Detection towards Cyber Threat Intelligence. Electronics, 12.","DOI":"10.3390\/electronics12020342"},{"key":"ref_26","doi-asserted-by":"crossref","first-page":"107754","DOI":"10.1016\/j.compeleceng.2022.107754","article-title":"Decision Tree Based User-Centric Security Solution for Critical IoT Infrastructure","volume":"99","author":"Puthal","year":"2022","journal-title":"Comput. Electr. Eng."},{"key":"ref_27","doi-asserted-by":"crossref","unstructured":"He, Q., Meng, X., Qu, R., and Xi, R. (2020). Machine Learning-Based Detection for Cyber Security Attacks on Connected and Autonomous Vehicles. Mathematics, 8.","DOI":"10.3390\/math8081311"},{"key":"ref_28","first-page":"1","article-title":"State of the Art Survey on Comparison of CAN, FlexRay, LIN Protocol and Simulation of LIN Protocol","volume":"2020","author":"Hafeez","year":"2020","journal-title":"SAE Tech. Pap."},{"key":"ref_29","doi-asserted-by":"crossref","first-page":"45","DOI":"10.1109\/MVT.2017.2669348","article-title":"Driving with Sharks: Rethinking Connected Vehicles with Vehicle Cybersecurity","volume":"12","author":"Eiza","year":"2017","journal-title":"IEEE Veh. Technol. Mag."},{"key":"ref_30","doi-asserted-by":"crossref","unstructured":"Haque, K.F., Abdelgawad, A., Yanambaka, V.P., and Yelamarthi, K. (2020). LoRa Architecture for V2X Communication: An Experimental Evaluation with Vehicles on the Move. Sensors, 20.","DOI":"10.3390\/s20236876"},{"key":"ref_31","doi-asserted-by":"crossref","unstructured":"Haque, K.F., Abdelgawad, A., Yanambaka, V.P., and Yelamarthi, K. (2020, January 14\u201316). A LoRa Based Reliable and Low Power Vehicle to Everything (V2X) Communication Architecture. Proceedings of the 2020 IEEE International Symposium on Smart Electronic Systems (iSES), Chennai, India.","DOI":"10.1109\/iSES50453.2020.00047"},{"key":"ref_32","doi-asserted-by":"crossref","first-page":"730","DOI":"10.1007\/978-3-030-82199-9_49","article-title":"Detecting CAN Bus Intrusion by Applying Machine Learning Method to Graph Based Features","volume":"Volume 296","author":"Refat","year":"2022","journal-title":"Intelligent Systems and Applications"},{"key":"ref_33","doi-asserted-by":"crossref","unstructured":"Alalwany, E., and Mahgoub, I. (2022). Classification of Normal and Malicious Traffic Based on an Ensemble of Machine Learning for a Vehicle CAN-Network. Sensors, 22.","DOI":"10.3390\/s22239195"},{"key":"ref_34","doi-asserted-by":"crossref","first-page":"919","DOI":"10.1109\/TITS.2019.2908074","article-title":"A Survey of Intrusion Detection for In-Vehicle Networks","volume":"21","author":"Wu","year":"2020","journal-title":"IEEE Trans. Intell. Transp. Syst."},{"key":"ref_35","unstructured":"(2023, January 16). HCRL-CAN-Intrusion-Dataset (OTIDS). Available online: https:\/\/ocslab.hksecurity.net\/Dataset\/CAN-intrusion-dataset."},{"key":"ref_36","first-page":"100198","article-title":"In-Vehicle Network Intrusion Detection Using Deep Convolutional Neural Network","volume":"21","author":"Song","year":"2020","journal-title":"Veh. Commun."},{"key":"ref_37","doi-asserted-by":"crossref","first-page":"79","DOI":"10.4236\/wet.2018.94007","article-title":"Classification Approach for Intrusion Detection in Vehicle Systems","volume":"9","author":"Alshammari","year":"2018","journal-title":"Wirel. Eng. Technol."},{"key":"ref_38","doi-asserted-by":"crossref","unstructured":"Almaraz-Rivera, J.G., Perez-Diaz, J.A., and Cantoral-Ceballos, J.A. (2022). Transport and Application Layer DDoS Attacks Detection to IoT Devices by Using Machine Learning and Deep Learning Models. Sensors, 22.","DOI":"10.3390\/s22093367"},{"key":"ref_39","doi-asserted-by":"crossref","unstructured":"Palanca, A., Evenchick, E., Maggi, F., and Zanero, S. (2017, January 6\u20137). A Stealth, Selective, Link-Layer Denial-of-Service Attack against Automotive Networks. Proceedings of the 14th International Conference on Detection of Intrusions and Malware, and Vulnerability Assessment, DIMVA 2017, Bonn, Germany.","DOI":"10.1007\/978-3-319-60876-1_9"},{"key":"ref_40","doi-asserted-by":"crossref","first-page":"4325","DOI":"10.1109\/TVT.2018.2795384","article-title":"Security Shortcomings and Countermeasures for the SAE J1939 Commercial Vehicle Bus Protocol","volume":"67","author":"Murvay","year":"2018","journal-title":"IEEE Trans. Veh. Technol."},{"key":"ref_41","doi-asserted-by":"crossref","first-page":"988","DOI":"10.1109\/TDSC.2018.2864993","article-title":"Learning from the Ones That Got Away: Detecting New Forms of Phishing Attacks","volume":"15","author":"Gutierrez","year":"2018","journal-title":"IEEE Trans. Dependable Secur. Comput."},{"key":"ref_42","doi-asserted-by":"crossref","first-page":"7687","DOI":"10.1109\/ACCESS.2017.2778071","article-title":"Energy-Efficient Wireless Transmissions for Battery-Less Vehicle Tire Pressure Monitoring System","volume":"6","author":"Kang","year":"2017","journal-title":"IEEE Access"},{"key":"ref_43","first-page":"754","article-title":"Razzer: Finding Kernel Race Bugs through Fuzzing","volume":"2019","author":"Jeong","year":"2019","journal-title":"Proc.-IEEE Symp. Secur. Priv."},{"key":"ref_44","first-page":"635","article-title":"Personal Data Privacy Challenges of the Fourth Industrial Revolution","volume":"2019","author":"Onik","year":"2019","journal-title":"Int. Conf. Adv. Commun. Technol. ICACT"},{"key":"ref_45","doi-asserted-by":"crossref","first-page":"39","DOI":"10.1007\/978-3-030-12085-6_4","article-title":"Detecting In-Vehicle CAN Message Attacks Using Heuristics and RNNs","volume":"Volume 11398","author":"Tariq","year":"2019","journal-title":"Information and Operational Technology Security Systems"},{"key":"ref_46","first-page":"1","article-title":"Remote Exploitation of an Unaltered Passenger Vehicle","volume":"2015","author":"Miller","year":"2015","journal-title":"Black Hat USA"},{"key":"ref_47","unstructured":"Jichici, C., Groza, B., and Murvay, P.S. (2018, January 8\u20139). Examining the Use of Neural Networks for Intrusion Detection in Controller Area Networks. Proceedings of the 11th International Conference on Innovative Security Solutions for Information Technology and Communications 2018, Bucharest, Romania."},{"key":"ref_48","unstructured":"(2023, January 16). HCRL-In-Vehicle Network Intrusion Detection Challenge. Available online: https:\/\/ocslab.hksecurity.net\/Datasets\/datachallenge2019\/car."},{"key":"ref_49","unstructured":"Rayhan Ahmed Mithu, M., Kholodilo, V., Manicavasagm, R., Ulybyshev, D., and Rogers, M. (2020, January 17\u201320). Secure Industrial Control System with Intrusion Detection. Proceedings of the Thirty-Third International Florida Artificial Intelligence Research Society Conference, Miami, FL, USA."},{"key":"ref_50","doi-asserted-by":"crossref","first-page":"61070","DOI":"10.1109\/ACCESS.2020.2983219","article-title":"Identification Failure Data for Cluster Heads Aggregation in WSN Based on Improving Classification of SVM","volume":"8","author":"Dao","year":"2020","journal-title":"IEEE Access"},{"key":"ref_51","doi-asserted-by":"crossref","first-page":"340","DOI":"10.1109\/JSEN.2017.2771226","article-title":"Fault Detection in Wireless Sensor Networks through SVM Classifier","volume":"18","author":"Zidi","year":"2018","journal-title":"IEEE Sens. J."}],"container-title":["Sensors"],"original-title":[],"language":"en","link":[{"URL":"https:\/\/www.mdpi.com\/1424-8220\/23\/7\/3610\/pdf","content-type":"unspecified","content-version":"vor","intended-application":"similarity-checking"}],"deposited":{"date-parts":[[2025,10,10]],"date-time":"2025-10-10T19:07:25Z","timestamp":1760123245000},"score":1,"resource":{"primary":{"URL":"https:\/\/www.mdpi.com\/1424-8220\/23\/7\/3610"}},"subtitle":[],"short-title":[],"issued":{"date-parts":[[2023,3,30]]},"references-count":51,"journal-issue":{"issue":"7","published-online":{"date-parts":[[2023,4]]}},"alternative-id":["s23073610"],"URL":"https:\/\/doi.org\/10.3390\/s23073610","relation":{},"ISSN":["1424-8220"],"issn-type":[{"value":"1424-8220","type":"electronic"}],"subject":[],"published":{"date-parts":[[2023,3,30]]}}}