跳到正文
arXiv:cs.LG· Shashwat Khandelwal, Shanker Shreejith·· 4 小时前AI 评分32

车载网络安全双入侵检测系统:QLSTM-IDS 与 QCAE-IDS 在 ZCU104 FPGA 上实现实时攻击检测

Deep Defence on Wheels: A Dual Intrusion Detection System Architecture for Comprehensive In-Vehicle Network Security

AI 导读

研究提出双 IDS 框架,在 ZCU104 SoC(XCZU7EV FPGA)上部署量化 LSTM 与 8-bit 量化卷积自编码器,分别检测已知与未知车载网络攻击。

正文

View PDF HTML (experimental)

Abstract:Increasing connectivity to the outside world and the lack of inbuilt security mechanisms have made legacy intra-vehicular networks vulnerable to cyberattacks. Initial research focused on maximising detection accuracy for known and unknown attacks, often using large, full-precision machine learning models. However, embedding IDSs into vehicular electronic systems also requires low detection latency, energy efficiency and minimal electronic control unit (ECU) resource overhead to process about 2,000 CAN frames/s. Lightweight models must balance accuracy with these deployment constraints. We propose a dual IDS framework comprising supervised and unsupervised learning-based solutions, each optimised for real-time, resource-constrained automotive platforms. A quantised LSTM-based IDS (QLSTM-IDS) achieves over 99.9% detection accuracy for DoS/Flooding, Fuzzing and Spoofing/Malfunction attacks using a single model architecture evaluated on two widely used datasets. The model is trained using the Brevitas quantisation-aware training library, transformed into a dataflow accelerator with custom blocks compatible with AMD's FINN toolchain, and synthesised using Vitis HLS. Complementing this, an 8-bit quantised convolutional autoencoder-based IDS (QCAE-IDS), quantised using AMD's Vitis-AI toolchain, detects previously unseen anomalies that alter CAN-ID sequence patterns with over 99% accuracy. An integration architecture enables both models to operate on a single FPGA, bridging the network interface IP and processing system to minimise software overhead. QLSTM-IDS achieves 0.25 ms inference latency and 0.8 mJ energy consumption per message, while QCAE-IDS achieves 0.42 ms and 1.1 mJ per block. Both solutions are deployed and evaluated on the ZCU104 SoC (XCZU7EV FPGA), demonstrating a flexible hardware/software co-design for real-time detection of known and unknown attacks on high-speed CAN buses.
Comments: 30 pages, 9 figures, 11 tables, ACM Transactions on Embedded Computing Systems
Subjects: Cryptography and Security (cs.CR); Hardware Architecture (cs.AR); Machine Learning (cs.LG)
Cite as: arXiv:2610.07489 [cs.CR]
  (or arXiv:2610.07489v1 [cs.CR] for this version)
  https://doi.org/10.48550/arXiv.2610.07489

arXiv-issued DOI via DataCite (pending registration)

Submission history

From: Shashwat Khandelwal [view email]
[v1] Mon, 5 Oct 2026 22:52:39 UTC (3,692 KB)

来源:arXiv:cs.LG · arxiv.org