TY - JOUR
T1 - Unsupervised Cross-Domain Attack Traffic Classifier for Intelligent Connected Vehicle
AU - He, Yongping
AU - Xia, Yuanqing
AU - Yan, Tijin
AU - Zhan, Yufeng
AU - Song, Jiaru
AU - Feng, Zihang
N1 - Publisher Copyright:
© 1982-2012 IEEE.
PY - 2026
Y1 - 2026
N2 - The heterogeneous communication ecosystem in intelligent connected vehicles (ICVs) has significantly broadened attack surfaces, making accurate attack traffic classification crucial for the security of vehicular networks. Existing deep learning (DL)-based classification methods face challenges such as reliance on labeled data and susceptibility to cross-domain data distribution discrepancies. To mitigate these challenges, a cross-domain attack traffic classifier named domain adaptation noisy label (DANL) is proposed in this article. DANL integrates uncertainty-aware sample selection and graph spectral alignment into unsupervised domain adaptation (UDA) frameworks to bridge domain gaps. Furthermore, a dual correction framework integrating noisy label learning (LNL) with pseudolabel aggregation is developed to further correct misclassifications caused by erroneous alignment. Extensive experiments on public datasets demonstrate DANL’s superiority, achieving an improvement of classification accuracy up to 5.8% over baselines. Further validation in real-world tests on self-constructed ICV testbed with simulated attacks confirming its effectiveness.
AB - The heterogeneous communication ecosystem in intelligent connected vehicles (ICVs) has significantly broadened attack surfaces, making accurate attack traffic classification crucial for the security of vehicular networks. Existing deep learning (DL)-based classification methods face challenges such as reliance on labeled data and susceptibility to cross-domain data distribution discrepancies. To mitigate these challenges, a cross-domain attack traffic classifier named domain adaptation noisy label (DANL) is proposed in this article. DANL integrates uncertainty-aware sample selection and graph spectral alignment into unsupervised domain adaptation (UDA) frameworks to bridge domain gaps. Furthermore, a dual correction framework integrating noisy label learning (LNL) with pseudolabel aggregation is developed to further correct misclassifications caused by erroneous alignment. Extensive experiments on public datasets demonstrate DANL’s superiority, achieving an improvement of classification accuracy up to 5.8% over baselines. Further validation in real-world tests on self-constructed ICV testbed with simulated attacks confirming its effectiveness.
KW - Attack traffic classification
KW - cyber-physical system
KW - deep learning (DL)
KW - intelligent connected vehicle (ICV)
KW - unsupervised learning
UR - https://www.scopus.com/pages/publications/105018522286
U2 - 10.1109/TIE.2025.3600524
DO - 10.1109/TIE.2025.3600524
M3 - Article
AN - SCOPUS:105018522286
SN - 0278-0046
VL - 73
SP - 3025
EP - 3036
JO - IEEE Transactions on Industrial Electronics
JF - IEEE Transactions on Industrial Electronics
IS - 2
ER -