Adversarial CAN Message Generation for Vehicle IDS Evasion

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

Current intrusion detection systems (IDS) in vehicles are vulnerable to adversarial example attacks, which can be evaded by generating and inserting noise into CAN messages, causing the attack to disappear and lose its intended meaning when inserted into a real vehicle.

Innovation Solution

An adversarial attack apparatus and method that collects CAN messages, extracts relevant data, adds type information, and inserts noise based on class and subclass information using a preprocessing module, generating an adversarial CAN message capable of avoiding IDS through an artificial neural network, and restoring the message to its original form for insertion into a vehicle.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Reliability

If noise is inserted into CAN messages to generate adversarial examples, then the IDS detection accuracy deteriorates, but the attack meaning disappears and the message cannot be effectively inserted into real vehicles

Engineering Contradiction:
ImproveIDS detection accuracyVSAvoidattack meaning preservation
Core Design Contradiction:
ReliabilityVSObject-generated harmful factors

Solution Approach 1:

The patent applies local quality by selectively inserting noise only into specific non-critical data fields of CAN messages while preserving critical fields such as arbitration ID and control fields. This targeted approach allows the adversarial example to evade IDS detection in specific areas without compromising the overall attack meaning or message functionality when inserted into real vehicles.

Inventive Principle:
Principle #3Local quality

Solution Approach 2:

The patent segments the CAN message into critical and non-critical fields, applying different noise insertion strategies to each segment. Critical fields remain unchanged to preserve attack meaning, while non-critical fields receive noise to achieve IDS evasion, thus resolving the contradiction between detection accuracy and attack effectiveness.

Inventive Principle:
Principle #1Segmentation

2Measurement precision

If machine learning-based IDS is used to detect hacking attacks, then the detection accuracy improves, but the system becomes vulnerable to adversarial example attacks

Engineering Contradiction:
Improvedetection accuracyVSAvoidvulnerability to adversarial attacks
Core Design Contradiction:
Measurement precisionVSReliability

Solution Approach 1:

The patent implements preliminary anti-action by pre-processing CAN messages with targeted noise insertion before they reach the IDS. This anticipatory modification creates adversarial examples that are designed to fool the machine learning-based IDS, thereby demonstrating the system's vulnerability to such attacks before deployment.

Inventive Principle:
Principle #9Preliminary anti-action

Solution Approach 2:

The patent changes the parameters of CAN messages by inserting noise into specific data fields, transforming normal messages into adversarial examples. This parameter modification allows the messages to bypass the machine learning-based IDS while maintaining their ability to execute attacks in real vehicle systems.

Inventive Principle:
Principle #35Parameter changes

3Adaptability or versatility

If noise is modulated when inserting adversarial examples into real vehicles, then the message format adapts to the vehicle system, but the attack meaning disappears and other values change

Engineering Contradiction:
Improvemessage format adaptabilityVSAvoidattack functionality
Core Design Contradiction:
Adaptability or versatilityVSObject-generated harmful factors

Solution Approach 1:

The patent applies local quality by identifying and protecting critical message fields from noise modulation while allowing adaptation in non-critical fields. This ensures that the arbitration ID, control fields, and other essential components remain unchanged to preserve attack functionality, while peripheral data fields can be modulated to adapt to the vehicle system's message format requirements.

Inventive Principle:
Principle #3Local quality

Solution Approach 2:

The patent performs preliminary analysis of the vehicle's CAN message format requirements before inserting adversarial examples. By pre-identifying which fields must remain unchanged and which can be adapted, the system ensures that noise modulation does not compromise attack functionality while still achieving necessary format compatibility.

Inventive Principle:
Principle #10Preliminary action

Data Source

PatentUS20240340297A1Apparatus and method for adversarial can packetization for physical attack of vehicle
Publication Date: 2024.10.10 FOUND OF SOONGSIL UNIV IND COOP
  • US20240340297A1 patent drawing
  • US20240340297A1 patent drawing
  • US20240340297A1 patent drawing

AI summary

An apparatus and a method for an adversarial attack on vehicle's controller area network (CAN). The apparatus comprises: a data generation module for collecting a plurality of CAN messages, extracting preconfigured some data from the plurality of collected CAN messages, adding type information for the CAN messages to the extracted some data so as to generate CAN message packets, and gathering the generated CAN message packets so as to configure a CAN message packet data set; a pre-processing module for inserting noise into some CAN message packets of the CAN message packet data set, wherein the noise is inserted on the basis of the type information of each CAN message packet; and an adversarial attack generation module for receiving the CAN message packet having noise inserted thereinto so as to generate an adversarial CAN message that can evade an intrusion detection system (IDS) of the vehicle.