CANalyze-AI: Semantic Zero-Day Detection and Rule Synthesis via LoRA-Fine-Tuned LLM for CAN Security

  • Awais Bilal
  • , Liehuang Zhu
  • , Kashif Sharif*
  • , Fan Li
  • , Sadaf Bukhari
  • *Corresponding author for this work

Research output: Chapter in Book/Report/Conference proceedingConference contributionpeer-review

Abstract

Modern Controller Area Network (CAN) buses lack native security, leaving vehicles exposed to spoofing, replay, and injection attacks, especially zero-day or unseen variants that evade traditional IDSs. We present CANalyze-AI, an edge-optimized hybrid IDS combining Random Forest and XGBoost with a 4-bit, LoRA-adapted GPT-2 to add semantic reasoning under strict resource budgets. Upon flagging anomalous 50-frame windows, the LLM produces concise, human-readable rationales and drafts Sigma rules that pass schema checks before use. On a composite CAN dataset, CANalyze-AI completes detection-plus-explanation in under 100 ms per window, fits within a ≤4 GB RAM envelope, and improves F1 by +0.9% over XGBoost and +2.2% over Random Forest. Under evasion, true-positive rate degrades by 7.1%, as compared to ≥12% for the baselines. Ablations show adaptive routing and LoRA adapters are key to performance and interpretability. We discuss practical guardrails against prompt-level attacks and limits arising from synthetic “zero-day” generation, and outline paths to real-fleet validation.

Original languageEnglish
Title of host publicationInformation Security and Cryptology - 21st International Conference, Inscrypt 2025, Revised Selected Papers
EditorsRongmao Chen, Robert H. Deng, Moti Yung
PublisherSpringer Science and Business Media Deutschland GmbH
Pages349-368
Number of pages20
ISBN (Print)9789819562084
DOIs
Publication statusPublished - 2026
Externally publishedYes
Event21st International Conference on Information Security and Cryptology, Inscrypt 2025 - Xi'an, China
Duration: 19 Oct 202522 Oct 2025

Publication series

NameLecture Notes in Computer Science
Volume16410 LNCS
ISSN (Print)0302-9743
ISSN (Electronic)1611-3349

Conference

Conference21st International Conference on Information Security and Cryptology, Inscrypt 2025
Country/TerritoryChina
CityXi'an
Period19/10/2522/10/25

Keywords

  • Controller area network
  • Edge-optimized
  • Hybrid IDS

Fingerprint

Dive into the research topics of 'CANalyze-AI: Semantic Zero-Day Detection and Rule Synthesis via LoRA-Fine-Tuned LLM for CAN Security'. Together they form a unique fingerprint.

Cite this