Skip to content
Conference

Autoencoder-Based Anomaly Detection on CAN Bus Networks with Surrogate Decision-Tree Interpretability

Jul 2026 · International Conference on Computer Communications and Networks · pp. 1-6 · 0 citations · 20 references

Abstract

Modern vehicles depend on dozens of Electronic Control Units (ECUs) that exchange messages over the Controller Area Network (CAN) bus. Because CAN lacks authentication and encryption, it remains susceptible to message-injection attacks. We present an empirical study of reconstruction-based CAN intrusion detection across four autoencoder families—ANN, CNN, LSTM, and Transformer—trained exclusively on attack-free traffic, together with a post-hoc surrogate-tree interface designed for analyst triage under low-prevalence operation. An AnomalyWrapper adapted from the Trustee framework [1] converts each autoencoder’s reconstruction errors into binary labels; a high-fidelity surrogate decision tree is then fitted to approximate those labels, and individual root-to-leaf decision paths are exposed as per-alert explanations. The LSTM autoencoder achieves an ROC-AUC of 0.996 and a false-positive rate of 0.9 % at a Normal-only threshold (μ+3σ). Because precision-recall measures depend on class prevalence, we evaluate under resampled anomaly rates of 1 %, 0.1 %, and 0.01 %, showing that recall remains stable while precision degrades—a well-known base-rate phenomenon that underscores the need for interpretable triage. Code and models: [GitHub repository].

View source

Similar papers

Conference Jul 2026

Resource-Constrained CAN Intrusion Detection with Distilled Decision Trees

Controller Area Network (CAN) is the dominant in-vehicle bus, yet its broadcast design and absent authentication leave it exposed to injection and spoofing attacks. Existing deep-learning intrusion detection systems achieve strong accuracy but depend on ML inference frameworks incompatible with the resource budgets of...

Amirmasoud Pourmiri, Ali Eslami, Sergio A. Salinas Monroy · 0 citations
Open access Aug 2026

Application of C4.5 Decision Tree Algorithm for Detecting Cyber Attacks Using IDS

This work constructs a web-based Intrusion Detection System prototype by training an entropy-based Decision Tree classifier, conceptually grounded in the C4.5 framework, on the NSL-KDD benchmark.

Daniel Erick Witopo, Hartana Wijaya · 0 citations
Open access Jul 2026

Explainable attention-based intrusion detection for encrypted 5G network traffic

A privacy-preserving intrusion detection framework that operates exclusively on flow-level traffic metadata without deep packet inspection, which supports the practicality of explainable Transformer models for secure and scalable APT detection in encrypted 5G environments.

Raghu Dhumpati, Varun Vemulapalli, Udayaraju Pamula et al. · 0 citations
Preprint Aug 2026

Behavioral Residualization for Unsupervised Intrusion Detection in Automotive CAN Networks

Per-ID behavioral residualization is presented, a CAN-specific representation that extracts fourteen temporal, protocol, and payload features from sliding windows and residualizes them against each arbitration ID's normal baseline, which improves mean F1 in the majority of evaluations.

Chandan Hegde, M. R. Reddy · 0 citations
Review

ma-Does the implementation of machine-learning-based anomaly detection increase the risk of system latency and false-positive trips in automated smart grid controllers compared to traditional regex-based filtering?

The findings indicate that hybrid-based approach to architecture should be suggested, where rule-based filtering is applied to address the time-sensitive deterministic checks, and the ML models give the context-driven anomaly analysis on both the SCADA and the wide-area layers.

Wenxuan Cao · 0 citations

We use cookies to run the site and, with your consent, for analytics and to show ads. See our Cookie Policy.