{"status":"ok","message-type":"work","message-version":"1.0.0","message":{"indexed":{"date-parts":[[2026,6,9]],"date-time":"2026-06-09T16:10:57Z","timestamp":1781021457156,"version":"3.54.1"},"reference-count":52,"publisher":"MDPI AG","issue":"21","license":[{"start":{"date-parts":[[2023,10,28]],"date-time":"2023-10-28T00:00:00Z","timestamp":1698451200000},"content-version":"vor","delay-in-days":0,"URL":"https:\/\/creativecommons.org\/licenses\/by\/4.0\/"}],"funder":[{"name":"Guangdong Basic and Applied Research Foundation","award":["2022B1515120072"],"award-info":[{"award-number":["2022B1515120072"]}]}],"content-domain":{"domain":[],"crossmark-restriction":false},"short-container-title":["Sensors"],"abstract":"<jats:p>The Internet of Vehicles(IoV) employs vehicle-to-everything (V2X) technology to establish intricate interconnections among the Internet, the IoT network, and the Vehicle Networks (IVNs), forming a complex vehicle communication network. However, the vehicle communication network is very vulnerable to attacks. The implementation of an intrusion detection system (IDS) emerges as an essential requisite to ensure the security of in-vehicle\/inter-vehicle communication in IoV. Within this context, the imbalanced nature of network traffic data and the diversity of network attacks stand as pivotal factors in IDS performance. On the one hand, network traffic data often heavily suffer from data imbalance, which impairs the detection performance. To address this issue, this paper employs a hybrid approach combining the Synthetic Minority Over-sampling Technique (SMOTE) and RandomUnderSampler to achieve a balanced class distribution. On the other hand, the diversity of network attacks constitutes another significant factor contributing to poor intrusion detection model performance. Most current machine learning-based IDSs mainly perform binary classification, while poorly dealing with multiclass classification. This paper proposes an adaptive tree-based ensemble network as the intrusion detection engine for the IDS in IoV. This engine employs a deep-layer structure, wherein diverse ML models are stacked as layers and are interconnected in a cascading manner, which enables accurate and efficient multiclass classification, facilitating the precise identification of diverse network attacks. Moreover, a machine learning-based approach is used for feature selection to reduce feature dimensionality, substantially alleviating the computational overhead. Finally, we evaluate the proposed IDS performance on various cyber-attacks from the in-vehicle and external networks in IoV by using the network intrusion detection dataset CICIDS2017 and the vehicle security dataset Car-Hacking. The experimental results demonstrate remarkable performance, with an F1-score of 0.965 on the CICIDS2017 dataset and an F1-score of 0.9999 on the Car-Hacking dataset. These scores demonstrate that our IDS can achieve efficient and precise multiclass classification. This research provides a valuable reference for ensuring the cybersecurity of IoV.<\/jats:p>","DOI":"10.3390\/s23218788","type":"journal-article","created":{"date-parts":[[2023,10,30]],"date-time":"2023-10-30T13:26:55Z","timestamp":1698672415000},"page":"8788","update-policy":"https:\/\/doi.org\/10.3390\/mdpi_crossmark_policy","source":"Crossref","is-referenced-by-count":35,"title":["Multi-Classification and Tree-Based Ensemble Network for the Intrusion Detection System in the Internet of Vehicles"],"prefix":"10.3390","volume":"23","author":[{"given":"Wanting","family":"Gou","sequence":"first","affiliation":[{"name":"China Telecom Research Institute, Guangzhou 510630, China"}],"role":[{"vocabulary":"crossref","role":"author"}]},{"given":"Haodi","family":"Zhang","sequence":"additional","affiliation":[{"name":"China Telecom Research Institute, Guangzhou 510630, China"}],"role":[{"vocabulary":"crossref","role":"author"}]},{"given":"Ronghui","family":"Zhang","sequence":"additional","affiliation":[{"name":"Guangdong Provincial Key Laboratory of Intelligent Transport System, School of Intelligent Systems Engineering, Sun Yat-sen University, Guangzhou 510275, China"}],"role":[{"vocabulary":"crossref","role":"author"}]}],"member":"1968","published-online":{"date-parts":[[2023,10,28]]},"reference":[{"key":"ref_1","unstructured":"Cho, K.-T., and Shin, K.G. (2016, January 10\u201312). Fingerprinting Electronic Control Units for Vehicle Intrusion Detection. Proceedings of the 25th USENIX Security Symposium (USENIX Security 16), Austin, TX, USA."},{"key":"ref_2","first-page":"993","article-title":"A Practical Wireless Attack on the Connected Car and Security Protocol for In-Vehicle CAN","volume":"16","author":"Woo","year":"2015","journal-title":"IEEE Trans. Intell. Transp. Syst."},{"key":"ref_3","first-page":"94","article-title":"A Survey of Remote Automotive Attack Surfaces","volume":"2014","author":"Miller","year":"2014","journal-title":"Black Hat USA"},{"key":"ref_4","doi-asserted-by":"crossref","unstructured":"Koscher, K., Czeskis, A., Roesner, F., Patel, S., Kohno, T., Checkoway, S., McCoy, D., Kantor, B., Anderson, D., and Shacham, H. (2010, January 16\u201319). Experimental Security Analysis of a Modern Automobile. Proceedings of the 2010 IEEE Symposium on Security and Privacy, Washington, DC, USA.","DOI":"10.1109\/SP.2010.34"},{"key":"ref_5","first-page":"1","article-title":"Remote exploitation of an unaltered passenger vehicle","volume":"2015","author":"Miller","year":"2015","journal-title":"Black Hat USA"},{"key":"ref_6","unstructured":"Lv, S., Nie, S., Liu, L., and Lu, W. (2016). Car hacking research: Remote attack Tesla motors. Keen Secur. Lab Tencent Sl, Available online: https:\/\/keenlab.tencent.com\/en\/2016\/09\/19\/Keen-Security-Lab-of-Tencent-Car-Hacking-Research-Remote-Attack-to-Tesla-Cars\/."},{"key":"ref_7","doi-asserted-by":"crossref","unstructured":"Kumar, M., Hanumanthappa, M., and Kumar, T.V.S. (2012, January 9\u201311). Intrusion Detection System using decision tree algorithm. Proceedings of the 2012 IEEE 14th International Conference on Communication Technology, Chengdu, China.","DOI":"10.1109\/ICCT.2012.6511281"},{"key":"ref_8","doi-asserted-by":"crossref","unstructured":"Zhang, H., Dai, S., Li, Y., and Zhang, W. (2018, January 17\u201319). Real-time Distributed-Random-Forest-Based Network Intrusion Detection System Using Apache Spark. Proceedings of the 2018 IEEE 37th International Performance Computing and Communications Conference (IPCCC), Orlando, FL, USA.","DOI":"10.1109\/PCCC.2018.8711068"},{"key":"ref_9","doi-asserted-by":"crossref","unstructured":"Iman, A.N., and Ahmad, T. (2020, January 20). Improving Intrusion Detection System by Estimating Parameters of Random Forest in Boruta. Proceedings of the 2020 International Conference on Smart Technology and Applications (ICoSTA), Surabaya, Indonesia.","DOI":"10.1109\/ICoSTA48221.2020.1570609975"},{"key":"ref_10","doi-asserted-by":"crossref","unstructured":"Waskle, S., Parashar, L., and Singh, U. (2020, January 2\u20134). Intrusion Detection System Using PCA with Random Forest Approach. Proceedings of the 2020 International Conference on Electronics and Sustainable Communication Systems (ICESC), Coimbatore, India.","DOI":"10.1109\/ICESC48915.2020.9155656"},{"key":"ref_11","doi-asserted-by":"crossref","unstructured":"Sharafaldin, I., Habibi Lashkari, A., and Ghorbani, A.A. (2018, January 22\u201324). Toward Generating a New Intrusion Detection Dataset and Intrusion Traffic Characterization. Proceedings of the 4th International Conference on Information Systems Security and Privacy, Funchal, Madeira, Portugal.","DOI":"10.5220\/0006639801080116"},{"key":"ref_12","first-page":"100198","article-title":"In-vehicle network intrusion detection using deep convolutional neural network","volume":"21","author":"Song","year":"2020","journal-title":"Veh. Commun."},{"key":"ref_13","doi-asserted-by":"crossref","first-page":"231","DOI":"10.1016\/j.cose.2014.06.006","article-title":"Selection of Candidate Support Vectors in incremental SVM for network intrusion detection","volume":"45","author":"Chitrakar","year":"2014","journal-title":"Comput. Secur."},{"key":"ref_14","doi-asserted-by":"crossref","unstructured":"Canbay, Y., and Sagiroglu, S. (2015, January 9\u201311). A Hybrid Method for Intrusion Detection. Proceedings of the 2015 IEEE 14th International Conference on Machine Learning and Applications (ICMLA), Miami, FL, USA.","DOI":"10.1109\/ICMLA.2015.197"},{"key":"ref_15","first-page":"157","article-title":"Intrusion Detection based on a Novel Hybrid Learning Approach","volume":"6","author":"Khalvati","year":"2018","journal-title":"J. AI Data Min."},{"key":"ref_16","doi-asserted-by":"crossref","first-page":"e4680867","DOI":"10.1155\/2018\/4680867","article-title":"Intrusion Detection System Based on Decision Tree over Big Data in Fog Environment","volume":"2018","author":"Peng","year":"2018","journal-title":"Wirel. Commun. Mob. Comput."},{"key":"ref_17","doi-asserted-by":"crossref","first-page":"124","DOI":"10.1109\/MCOM.2018.1701270","article-title":"Leveraging LSTM Networks for Attack Detection in Fog-to-Things Communications","volume":"56","author":"Diro","year":"2018","journal-title":"IEEE Commun. Mag."},{"key":"ref_18","doi-asserted-by":"crossref","first-page":"74571","DOI":"10.1109\/ACCESS.2020.2988854","article-title":"Fog-Based Attack Detection Framework for Internet of Things Using Deep Learning","volume":"8","author":"Samy","year":"2020","journal-title":"IEEE Access"},{"key":"ref_19","doi-asserted-by":"crossref","first-page":"231","DOI":"10.1007\/s11277-022-09548-7","article-title":"Fog Computing-Based Intrusion Detection Architecture to Protect IoT Networks","volume":"125","author":"Labiod","year":"2022","journal-title":"Wirel. Pers. Commun."},{"key":"ref_20","doi-asserted-by":"crossref","unstructured":"Li, S., Lu, Y., and Li, J. (2022, January 4\u20136). CAD-IDS: A Cooperative Adaptive Distributed Intrusion Detection System with Fog Computing. Proceedings of the 2022 IEEE 25th International Conference on Computer Supported Cooperative Work in Design (CSCWD), Hangzhou, China.","DOI":"10.1109\/CSCWD54268.2022.9776147"},{"key":"ref_21","doi-asserted-by":"crossref","first-page":"12569","DOI":"10.1109\/JIOT.2020.3029248","article-title":"Daas: Dew computing as a service for intelligent intrusion detection in edge-of-things ecosystem","volume":"8","author":"Singh","year":"2020","journal-title":"IEEE Internet Things J."},{"key":"ref_22","doi-asserted-by":"crossref","first-page":"310","DOI":"10.1109\/MNET.011.2000286","article-title":"Internet of things intrusion detection: Centralized, on-device, or federated learning?","volume":"34","author":"Rahman","year":"2020","journal-title":"IEEE Netw."},{"key":"ref_23","doi-asserted-by":"crossref","first-page":"101157","DOI":"10.1016\/j.phycom.2020.101157","article-title":"Intelligent intrusion detection based on federated learning aided long short-term memory","volume":"42","author":"Zhao","year":"2020","journal-title":"Phys. Commun."},{"key":"ref_24","first-page":"102419","article-title":"Deep learning for cyber security intrusion detection: Approaches, datasets, and comparative study","volume":"50","author":"Ferrag","year":"2020","journal-title":"J. Inf. Secur. Appl."},{"key":"ref_25","doi-asserted-by":"crossref","first-page":"6435","DOI":"10.1109\/TII.2021.3130248","article-title":"Intrusion Detection Framework for the Internet of Things Using a Dense Random Neural Network","volume":"18","author":"Latif","year":"2022","journal-title":"IEEE Trans. Ind. Inform."},{"key":"ref_26","doi-asserted-by":"crossref","first-page":"2707","DOI":"10.1007\/s11277-021-08359-6","article-title":"Malicious Traffic classification Using Long Short-Term Memory (LSTM) Model","volume":"119","author":"Thapa","year":"2021","journal-title":"Wirel. Pers. Commun."},{"key":"ref_27","doi-asserted-by":"crossref","first-page":"100542","DOI":"10.1016\/j.ijcip.2022.100542","article-title":"Cyber-attacks detection in industrial systems using artificial intelligence-driven methods","volume":"38","author":"Wang","year":"2022","journal-title":"Int. J. Crit. Infrastruct. Prot."},{"key":"ref_28","doi-asserted-by":"crossref","first-page":"103210","DOI":"10.1016\/j.cose.2023.103210","article-title":"CPS-GUARD: Intrusion detection for cyber-physical systems and IoT devices using outlier-aware deep autoencoders","volume":"129","author":"Catillo","year":"2023","journal-title":"Comput. Secur."},{"key":"ref_29","doi-asserted-by":"crossref","first-page":"1662","DOI":"10.1109\/ACCESS.2017.2779939","article-title":"LSTM Fully Convolutional Networks for Time Series Classification","volume":"6","author":"Karim","year":"2018","journal-title":"IEEE Access"},{"key":"ref_30","doi-asserted-by":"crossref","first-page":"7094","DOI":"10.1007\/s10489-021-02205-9","article-title":"Unsupervised deep learning approach for network intrusion detection combining convolutional autoencoder and one-class SVM","volume":"51","author":"Binbusayyis","year":"2021","journal-title":"Appl. Intell."},{"key":"ref_31","unstructured":"Ma, T., Yu, Y., Wang, F., Zhang, Q., and Chen, X. (2018). Frontier Computing: Theory, Technologies and Applications FC 2016 5, Springer."},{"key":"ref_32","doi-asserted-by":"crossref","first-page":"4507","DOI":"10.1109\/TITS.2020.3017882","article-title":"Novel Deep Learning-Enabled LSTM Autoencoder Architecture for Discovering Anomalous Events from Intelligent Transportation Systems","volume":"22","author":"Ashraf","year":"2021","journal-title":"IEEE Trans. Intell. Transp. Syst."},{"key":"ref_33","doi-asserted-by":"crossref","first-page":"6703","DOI":"10.1109\/TVT.2015.2480244","article-title":"Host-Based Intrusion Detection for VANETs: A Statistical Approach to Rogue Node Detection","volume":"65","author":"Zaidi","year":"2016","journal-title":"IEEE Trans. Veh. Technol."},{"key":"ref_34","doi-asserted-by":"crossref","first-page":"48","DOI":"10.1080\/21642583.2018.1440260","article-title":"Intelligent intrusion detection in external communication systems for autonomous vehicles","volume":"6","year":"2018","journal-title":"Syst. Sci. Control Eng."},{"key":"ref_35","doi-asserted-by":"crossref","first-page":"9960","DOI":"10.1109\/JIOT.2021.3119055","article-title":"A Novel Intrusion Detection Method Based on Lightweight Neural Network for Internet of Things","volume":"9","author":"Zhao","year":"2022","journal-title":"IEEE Internet Things J."},{"key":"ref_36","doi-asserted-by":"crossref","unstructured":"Yang, L., Moubayed, A., Hamieh, I., and Shami, A. (2019, January 9\u201313). Tree-based Intelligent Intrusion Detection System in Internet of Vehicles. Proceedings of the 2019 IEEE Global Communications Conference (GLOBECOM), Big Island, HI, USA.","DOI":"10.1109\/GLOBECOM38437.2019.9013892"},{"key":"ref_37","doi-asserted-by":"crossref","unstructured":"Chen, Z., Simsek, M., Kantarci, B., and Djukic, P. (2021, January 7\u201311). All Predict Wisest Decides: A Novel Ensemble Method to Detect Intrusive Traffic in IoT Networks. Proceedings of the 2021 IEEE Global Communications Conference (GLOBECOM), Madrid, Spain.","DOI":"10.1109\/GLOBECOM46510.2021.9685318"},{"key":"ref_38","doi-asserted-by":"crossref","unstructured":"Tavallaee, M., Bagheri, E., Lu, W., and Ghorbani, A.A. (2009, January 8\u201310). A detailed analysis of the KDD CUP 99 data set. Proceedings of the 2009 IEEE Symposium on Computational Intelligence for Security and Defense Applications, Ottawa, ON, Canada.","DOI":"10.1109\/CISDA.2009.5356528"},{"key":"ref_39","doi-asserted-by":"crossref","unstructured":"Moustafa, N., and Slay, J. (2015, January 10\u201312). UNSW-NB15: A comprehensive data set for network intrusion detection systems (UNSW-NB15 network data set). Proceedings of the 2015 Military Communications and Information Systems Conference (MilCIS), Canberra, Australia.","DOI":"10.1109\/MilCIS.2015.7348942"},{"key":"ref_40","doi-asserted-by":"crossref","first-page":"77","DOI":"10.1109\/MCI.2012.2228600","article-title":"Ensemble Methods: Foundations and Algorithms [Book Review]","volume":"8","author":"Schwenker","year":"2013","journal-title":"IEEE Comput. Intell. Mag."},{"key":"ref_41","doi-asserted-by":"crossref","unstructured":"Chen, T., and Guestrin, C. (2016, January 13\u201317). XGBoost: A Scalable Tree Boosting System. Proceedings of the 22nd ACM SIGKDD International Conference on Knowledge Discovery and Data Mining, San Francisco, CA, USA.","DOI":"10.1145\/2939672.2939785"},{"key":"ref_42","unstructured":"Ke, G., Meng, Q., Finley, T., Wang, T., Chen, W., Ma, W., Ye, Q., and Liu, T.-Y. (2017, January 4\u20139). LightGBM: A Highly Efficient Gradient Boosting Decision Tree. Proceedings of the Advances in Neural Information Processing Systems, Long Beach, CA, USA."},{"key":"ref_43","doi-asserted-by":"crossref","first-page":"5","DOI":"10.1023\/A:1010933404324","article-title":"Random Forests","volume":"45","author":"Breiman","year":"2001","journal-title":"Mach. Learn."},{"key":"ref_44","doi-asserted-by":"crossref","first-page":"3","DOI":"10.1007\/s10994-006-6226-1","article-title":"Extremely randomized trees","volume":"63","author":"Geurts","year":"2006","journal-title":"Mach. Learn."},{"key":"ref_45","doi-asserted-by":"crossref","unstructured":"Maimon, O., and Rokach, L. (2005). Data Mining and Knowledge Discovery Handbook, Springer.","DOI":"10.1007\/b107408"},{"key":"ref_46","doi-asserted-by":"crossref","unstructured":"Roopak, M., Yun Tian, G., and Chambers, J. (2019, January 7\u20139). Deep Learning Models for Cyber Security in IoT Networks. Proceedings of the 2019 IEEE 9th Annual Computing and Communication Workshop and Conference (CCWC), Las Vegas, NV, USA.","DOI":"10.1109\/CCWC.2019.8666588"},{"key":"ref_47","doi-asserted-by":"crossref","unstructured":"Belarbi, O., Khan, A., Carnelli, P., and Spyridopoulos, T. (2022, January 10\u201312). An Intrusion Detection System based on Deep Belief Networks. Proceedings of the International Conference on Science of Cyber Security, Shimane, Japan.","DOI":"10.1007\/978-3-031-17551-0_25"},{"key":"ref_48","doi-asserted-by":"crossref","unstructured":"Yao, Y., Su, L., and Lu, Z. (2018, January 29\u201331). DeepGFL: Deep Feature Learning via Graph for Attack Detection on Flow-Based Network Traffic. Proceedings of the MILCOM 2018\u20142018 IEEE Military Communications Conference (MILCOM), Los Angeles, CA, USA.","DOI":"10.1109\/MILCOM.2018.8599821"},{"key":"ref_49","doi-asserted-by":"crossref","first-page":"79","DOI":"10.4236\/wet.2018.94007","article-title":"Classification Approach for Intrusion Detection in Vehicle Systems","volume":"9","author":"Alshammari","year":"2018","journal-title":"Wirel. Eng. Technol."},{"key":"ref_50","doi-asserted-by":"crossref","unstructured":"Ullah, S., Khan, M.A., Ahmad, J., Jamal, S.S., e Huma, Z., Hassan, M.T., Pitropakis, N., and Buchanan, W.J. (2022). HDL-IDS: A Hybrid Deep Learning Architecture for Intrusion Detection in the Internet of Vehicles. Sensors, 22.","DOI":"10.3390\/s22041340"},{"key":"ref_51","doi-asserted-by":"crossref","first-page":"1803","DOI":"10.1109\/TNSM.2020.3014929","article-title":"Multi-Stage Optimized Machine Learning Framework for Network Intrusion Detection","volume":"18","author":"Injadat","year":"2021","journal-title":"IEEE Trans. Netw. Serv. Manag."},{"key":"ref_52","doi-asserted-by":"crossref","first-page":"2219","DOI":"10.1109\/TNSE.2020.2990984","article-title":"Data-Driven Intrusion Detection for Intelligent Internet of Vehicles: A Deep Convolutional Neural Network-Based Method","volume":"7","author":"Nie","year":"2020","journal-title":"IEEE Trans. Netw. Sci. Eng."}],"container-title":["Sensors"],"original-title":[],"language":"en","link":[{"URL":"https:\/\/www.mdpi.com\/1424-8220\/23\/21\/8788\/pdf","content-type":"unspecified","content-version":"vor","intended-application":"similarity-checking"}],"deposited":{"date-parts":[[2025,10,10]],"date-time":"2025-10-10T21:13:21Z","timestamp":1760130801000},"score":1,"resource":{"primary":{"URL":"https:\/\/www.mdpi.com\/1424-8220\/23\/21\/8788"}},"subtitle":[],"short-title":[],"issued":{"date-parts":[[2023,10,28]]},"references-count":52,"journal-issue":{"issue":"21","published-online":{"date-parts":[[2023,11]]}},"alternative-id":["s23218788"],"URL":"https:\/\/doi.org\/10.3390\/s23218788","relation":{},"ISSN":["1424-8220"],"issn-type":[{"value":"1424-8220","type":"electronic"}],"subject":[],"published":{"date-parts":[[2023,10,28]]}}}