X-SPUR: Explainable Surprisal-Based Protocol-Aware Unsupervised Reasoning for Automotive Ethernet Intrusion Detection

📅 2026-09-17
📈 Citations: 0
Influential: 0
📄 PDF
🤖 AI Summary
本文提出X-SPUR框架,通过基于惊讶度的无监督学习方法解决汽车以太网入侵检测问题,无需手工特征工程,实现高精度检测。
📝 Abstract
Automotive Ethernet carries heterogeneous multi-protocol traffic in modern in-vehicle networks, where labeled attack data are rarely available and the strongest prior unsupervised detector still relies on handcrafted traffic features. This article presents X-SPUR, an explainable, surprisal-based, protocol-aware unsupervised reasoning framework that instead represents raw packet fields as token sequences, learns benign traffic patterns through causal language modeling, and detects anomalies from per-token cross-entropy surprisal. To incorporate temporal context, we introduce a bimodal fusion architecture that combines payload-token embeddings with inter-packet timing through additive fusion and a Hadamard interaction. To handle the heterogeneous score distributions of different protocol families, we further propose a dual top-$k$% per-protocol $Z$-score calibration that jointly captures moderately distributed and sparse anomaly signatures. On the TOW-IDS dataset, X-SPUR achieves an AUC of 0.9987. This is marginally higher than the 0.9969 reported for AERO. X-SPUR also eliminates handcrafted feature engineering. We train a separate CarDS model using the same architecture and training hyperparameters. This model retains strong performance on the second automotive Ethernet dataset. Beyond detection, per-token surprisal provides fine-grained explainability by attributing anomaly scores to specific protocol fields, supporting interpretable security analysis in heterogeneous in-vehicle networks.
Problem

Research questions and friction points this paper is trying to address.

Automotive Ethernet
Unsupervised Reasoning
Intrusion Detection
Heterogeneous Traffic
Anomaly Detection
Innovation

Methods, ideas, or system contributions that make the work stand out.

unsupervised reasoning
surprisal-based detection
bimodal fusion architecture
dual top-$k$% per-protocol $Z$-score calibration
fine-grained explainability
🔎 Similar Papers
No similar papers found.
💼 Related Jobs
No related jobs found.
J
Jisoo Kim
Department of Data Science, Sookmyung Women's University, Seoul 04310, Republic of Korea
S
Seonghoon Jeong
Division of Artificial Intelligence Engineering, Sookmyung Women's University, Seoul 04310, Republic of Korea