TY - JOUR
T1 - Heterogeneous Multi-link Fusion-enabled Anomaly Detection for Centralized In-Vehicle Network Architectures
AU - Yin, Zhihua
AU - Wei, Hongqian
AU - Yu, Meng
AU - Sun, Yaping
AU - Zhang, Youtong
N1 - Publisher Copyright:
© 2014 IEEE.
PY - 2026
Y1 - 2026
N2 - With the advancement of connected vehicle technologies, the cybersecurity of in-vehicle networks (IVNs) has gained growing attention. However, the evolution of IVN architectures and the increasing stealthiness of cyber-attacks pose significant challenges to anomaly detection. To this end, a heterogeneous multi-link fusion-enabled anomaly detection system (HMLF-ADS) for centralized IVNs is proposed. In this ADS, a spatio-temporal feature parallel encoder (STFPE) is designed to capture fine-grained dynamic contextual features within each heterogeneous network link. Unlike existing approaches that focus exclusively on intra-link traffic features, a relation graph encoder (RGE) based on the inter-domain information interaction mechanism in centralized IVNs is constructed, enabling the adaptive learning of implicit inter-link correlations, and enhancing the detection of highly stealthy attacks. Real-world experiments have demonstrated its superiority, achieving a 6.10% improvement in detection accuracy over state-of-the-art methods for highly stealthy tampering attacks.
AB - With the advancement of connected vehicle technologies, the cybersecurity of in-vehicle networks (IVNs) has gained growing attention. However, the evolution of IVN architectures and the increasing stealthiness of cyber-attacks pose significant challenges to anomaly detection. To this end, a heterogeneous multi-link fusion-enabled anomaly detection system (HMLF-ADS) for centralized IVNs is proposed. In this ADS, a spatio-temporal feature parallel encoder (STFPE) is designed to capture fine-grained dynamic contextual features within each heterogeneous network link. Unlike existing approaches that focus exclusively on intra-link traffic features, a relation graph encoder (RGE) based on the inter-domain information interaction mechanism in centralized IVNs is constructed, enabling the adaptive learning of implicit inter-link correlations, and enhancing the detection of highly stealthy attacks. Real-world experiments have demonstrated its superiority, achieving a 6.10% improvement in detection accuracy over state-of-the-art methods for highly stealthy tampering attacks.
KW - Intelligent connected vehicles
KW - anomaly detection system
KW - centralized invehicle network architecture
KW - multi-link fusion
UR - https://www.scopus.com/pages/publications/105042899656
U2 - 10.1109/JIOT.2026.3706825
DO - 10.1109/JIOT.2026.3706825
M3 - Article
AN - SCOPUS:105042899656
SN - 2327-4662
JO - IEEE Internet of Things Journal
JF - IEEE Internet of Things Journal
ER -