Controller Area Network Bus Spoofing Attack Detection in Internet of Vehicles Using Machine Learning Approaches
DOI:
https://doi.org/10.24996/ijs.2026.67.9.27Keywords:
Internet of Vehicles (IoV), DoS Attack , Spoofing Attack, , Eensemble LearningAbstract
Considering the complexity of network traffic in IoV operations, methods that can identify complex patterns become useful. Machine learning fosters several techniques to enhance the detection, prevention, and mitigation of cyberattacks. This paper presents a hybrid approach combining machine learning (ML) and deep learning (DL) techniques for detecting multiple variants of spoofing in the Internet of Vehicles (IoV). The increasing connectivity of vehicles has expanded the attack surface for malicious actors, making effective detection of spoofing attacks a critical security concern. Our approach integrates traditional ML algorithms (Random Forest, Gradient Boosting, SVM) with deep learning architectures (CNN-LSTM, CNN), leveraging the complementary strengths of both approaches. To address the significant class imbalance observed in the CICIoV2024 dataset (86.96% benign traffic versus 13.04% attack traffic), we implemented a balanced sampling approach using under sampling of the dominant class while maintaining realistic data distributions. Experimental evaluation showed that our hybrid approach achieved high detection accuracy (99.3–99.4%) across various attack types, such as Denial of Service (DOS), GAS, RPM, SPEED, and STEERING_WHEEL spoofing. Performance analysis revealed that the highest overall accuracy was achieved with CNN-LSTM (99.4%), while Random Forest provided similar results (99.3%) with significantly better computational efficiency (40x faster training time). These results make it mainly appropriate for real-time applications.




