Uppsats
Explainable AI for Network Intrusion Detection in Modern In-Vehicle Networks - An explainability pipeline for deep learning based intrusion detection systems for in-vehicle networks
H
Chalmers tekniska högskola / Institutionen för data och informationsteknik
Publicerad: 2026
Språk: Engelska
Sammanfattning
Deep learning–based network intrusion detection systems (NIDS) have been widelyadopted for detecting attacks in Controller Area Network (CAN) traffic due to theirsuperior performance over traditional approaches. However, their black-box naturemakes the underlying decision-making process difficult to interpret, limiting theirsuitability for safety-critical automotive environments. Existing studies on CANNIDS have largely focused on detection performance and model design; limitedwork has examined shortcut learning through explanations or used explanations toimprove the models. This thesis develops an explainable artificial intelligence (XAI)pipeline for DL-based CAN NIDS. Raw CAN fields are combined with explicit temporal and statistical features. Multilayer perceptron (MLP) classifiers are evaluated on the CAN-MIRGU and can-train-and-test datasets, and the autoencoderis evaluated on the CAN-MIRGU dataset. SHAP, LIME, Integrated Gradients,Trustee, and AE-p-values are used for behavior analysis, while Right for the RightReasons (RRR) supervision and Gini-based attribution priors are applied to guidetraining. The MLP achieves high F1-scores on CAN-MIRGU, but its performancedecreases substantially under unseen attacks and cross-vehicle tests in can-trainand-test. Explanations show both meaningful use of timing-related features andreliance on dataset-specific payload patterns. For the autoencoder, p-value representations improve attack clustering over raw inputs. Moreover, p-values reveal thatin the CAN-MIRGU dataset, DoS and fuzzing attacks are distinguishable, whereasspoofing and replay attacks remain difficult to separate. RRR increases the F1-scorefor non-zero-payload DoS attacks under distribution shift from 0 to 0.61. Gini-basedregularization increases explanation sparsity while maintaining high predictive performance. These results show that explanation analysis is necessary for identifyingshortcuts, assessing generalization, and developing more reliable CAN NIDS.
Information
- Författare
- Tian, Wenjun, Wang, Yexiao
- Lärosäte / institution
- Chalmers tekniska högskola / Institutionen för data och informationsteknik
- Publiceringsdatum
- 2026
- Uppsatstyp
- H
- Språk
- Engelska