节点文献

基于机器学习的车联网入侵检测技术研究

Research on Intrusion Detection in Internet of Vehicles Based on Machine Learning

【作者】 杨颖

【导师】 韩兰胜;

【作者基本信息】 华中科技大学 , 网络空间安全, 2024, 硕士

【摘要】 随着人工智能、万物互联等新兴技术的飞速发展,传统的车辆自组织网络正迅速演变成为更为复杂的车联网系统。然而,伴随车联网技术的不断发展,网络攻击的威胁日益增加,攻击手段也不断更新,车联网安全正面临严峻的挑战。因此,设计并实现能够有效应对车联网复杂网络环境的入侵检测技术变得尤为重要。车外网和车内网环境存在巨大的差异,这意味着需要针对不同环境特点设计不同的入侵检测算法。针对车外网中数据特征维度高、攻击类型多样、新兴攻击频发等挑战,设计了一种基于领导类特征提取的车外网入侵检测模型。首先选取多个特征选择方法作为基学习器,基于多数投票机制设计了一种领导类选择的特征选择算法,有效减少了特征数量;然后利用三种基学习器选出每种类别数据的领导类,结合每个基学习器预测的置信度,综合判断每个检测数据的具体类别,进一步提高对已知攻击的预测准确性;对于上一阶段未检测出的未知攻击,利用K均值聚类算法对检测结果为正常的数据进行聚类,在聚类的基础上增加两个偏置分类器优化预测中误报和漏报的数据,增强未知攻击的检测性能。通过CIC-IDS 2017数据集上的实验验证模型在车外网入侵检测任务中的有效性。针对车内网中数据分布严重失衡、攻击样本稀缺、标签数据难以获取等挑战,设计了一种基于对抗自动编码器的车内网入侵检测模型。首先利用大量无标签数据输入自动编码器,学习数据样本的潜在特征表示。然后,结合生成对抗网络的思想,将自动编码器的潜在特征用作生成器,设计两种鉴别器与生成器进行对抗训练,强化提取有用的特征并生成更加逼真的攻击样本。同时结合半监督学习的思想,加入少量标签数据控制样本的类别,增强模型的性能。通过在Car-Hacking数据集上设置不同比例的攻击数据以及不同比例的标签样本数据进行实验,证明算法在数据样本不平衡以及标签样本少的场景下,检测少数类攻击具有优异的性能。

【Abstract】 With the rapid advancement of emerging technologies like artificial intelligence and the Internet of Things,traditional vehicular ad hoc networks are evolving into more complex Internet of Vehicles systems.However,as Internet of Vehicles technologies continue to advance,the threat of network attacks is increasing,with attack methods evolving continuously.As a result,Internet of Vehicles security faces significant challenges.Therefore,it becomes crucial to design and implement intrusion detection system that can effectively address the complex network environments of Internet of Vehicles.Additionally,substantial disparities exist between external and internal vehicular network environments,underscoring the necessity for bespoke intrusion detection algorithms tailored to the unique characteristics of each setting.To solve challenges such as high-dimensional feature spaces,diverse attack types,and emerging threats in external vehicular networks,a novel intrusion detection model based on leader-class feature extraction is proposed.Multiple feature selection methods are initially selected as base learners,and a leader-class feature selection algorithm is designed based on a majority voting mechanism to effectively reduce feature dimensionality.Subsequently,three base learners are utilized to identify leader classes for each data category.By combining the confidence levels predicted by each base learner,the specific category of each detection data is comprehensively determined,thereby enhancing the prediction accuracy for known attacks.For previously undetected unknown attacks,a K-means clustering algorithm is employed to cluster data identified as normal by the detection results.Two bias classifiers are then added based on the clustering to optimize the training,reducing false positives and false negatives and strengthening the detection performance of unknown attacks.Experimental validation on the CIC-IDS 2017 dataset confirms the effectiveness of the model in intrusion detection tasks for external Internet of Vehicles.To solve challenges posed by severe data imbalance,scarce attack samples,and difficulty in obtaining labeled data in vehicular networks,An intrusion detection model is proposed based on adversarial autoencoders.Initially,a large amount of unlabeled data is fed into the autoencoder to learn the latent feature representations of data samples.Subsequently,leveraging the concept of generative adversarial networks,the learned latent features from the autoencoder serve as the generator,and two discriminators are designed to engage in adversarial training,enhancing the extraction of useful features and generating more realistic attack samples.Furthermore,through the integration of semi-supervised learning,a limited amount of labeled data is utilized to regulate sample categories,thereby enhancing the model’s performance.Experimental results conducted on the Car-Hacking dataset with varying proportions of attack and labeled samples demonstrate the algorithm’s outstanding performance in detecting minority-class attacks under scenarios of data imbalance and limited labeled samples.

  • 【分类号】U495;TP181;TP393.08
节点文献中: 

本文链接的文献网络图示:

本文的引文网络