IP Library Granted Patent US 12,488,049
Granted Patent B2
US 12,488,049 · App. 18/227,474 · Granted Dec 2, 2025

Federated graph neural network for fast anomaly detection in controller area networks

Inventors: Hengrun Zhang (Fairfax, VA); Kai Zeng (Fairfax, VA)
Assignee: George Mason University
G06F16/9024G06N3/044G06N3/088H04L12/40H04L41/16H04L63/1425H04L2012/40215
View Patent ↗
Loading inventors, assignments & file history…
Monitor This Case
Get email alerts when status or documents change.
Order Certified Copies
Most orders are placed with the USPTO same day — all within 24 business hours.
Order via The Patent Place →
Pre-filled with this patent's details
Quick Facts
Patent No.
US 12,488,049
App. No.
18/227,474
Granted
Dec 2, 2025
Kind
B2
Abstract

A method and apparatus for intrusion detection includes generating graph data from a sequence of messages in a communication network. The graph data denotes a node for each message identifier in the sequence of messages and an edge for each pair of consecutive message identifiers. Pair counts are generated for edges in the graph data as a number of times the associated pair of consecutive message identifiers occurs in the sequence. Input feature vectors are generated for nodes in the graph data. The vectors include data content of messages associated with the node and a pair count for each edge connected to the node. The input feature vectors are processed through a first graph neural network, based on the graph data, and then through one or more layers of a classifier to classify the sequence of messages as containing an anomaly or not.

Claims (66)

1 . A computer-implemented method comprising:

generating graph data from a sequence of messages in a communication network, each message including data content and a message identifier, the graph data denoting:

a node for each message identifier in the sequence of messages; and

an edge for each pair of consecutive message identifiers in the sequence of messages, the edge linking two nodes;

for edges in the graph data, generating a pair count as a number of times the associated pair of consecutive message identifiers occurs in the sequence of messages;

for nodes in the graph data, generating an input feature vector including:

data content of messages that include the message identifier associated with the node; and

a pair count for each edge connected to the node;

processing the input feature vectors through a first graph neural network, based on the graph data, to produce first output feature vectors; and

classifying the sequence of messages as containing an anomaly or not, including processing the first output feature vectors through one or more first output layers.

2 . The computer-implemented method of claim 1 , further comprising:

monitoring the sequence of messages in the communication network; and

raising an alarm when the sequence of messages is classified containing an anomaly.

3 . The computer-implemented method of claim 1 , where the edges are directed edges.

4 . The computer-implemented method of claim 1 , where the one or more first output layers include a one-class classifier.

5 . The computer-implemented method of claim 1 , where the first graph neural network includes a plurality of first network weights, the method further comprising:

training the first network weights using a dataset of messages without anomalies.

6 . The computer-implemented method of claim 1 , further comprising:

when the sequence of messages contains an anomaly:

processing the input feature vectors using a second graph neural network, based on the graph data, to produce second output feature vectors; and

classifying the anomaly, including processing the second output feature vectors through one or more second output layers.

7 . The computer-implemented method of claim 6 , where the one or more second output layers include an “openmax” layer.

8 . The computer-implemented method of claim 6 , where the second graph neural network includes a plurality of second network weights, the method further comprising:

training the second network weights using a dataset of messages with known anomalies.

9 . The computer-implemented method of claim 6 , further comprising:

when the sequence of messages contains an anomaly:

initiating a mitigation action based on the classification of the anomaly.

10 . The computer-implemented method of claim 1 , where the first graph neural network includes a node for each message identifier in a protocol of the communication network.

11 . The computer-implemented method of claim 1 , further comprising:

extracting the data content of an input feature vector from a message payload based on identified data block boundaries in the message payload.

12 . An apparatus comprising:

one or more computers configured to receive a sequence of messages from a communication network, each message including data content and a message identifier;

a non-transitory computer-readable medium coupled to the one or more computers and having instructions stored thereon, which, when executed by the one or more computers, cause the one or more computers to:

generate graph data from the sequence, the graph data denoting:

a node for each message identifier in the sequence of messages; and

an edge for each pair of consecutive message identifiers in the sequence of messages, the edge linking two nodes;

for edges in the graph data, generate a pair count as a number of times the associated pair of consecutive message identifiers occurs in the sequence of messages;

for nodes in the graph data, generate an input feature vector including:

data content of messages that include the message identifier associated with the node; and

a pair count for each edge connected to the node;

process the input feature vectors using a first graph neural network, based on the graph data, to produce first output feature vectors; and

classify the sequence of messages as containing an anomaly or not, including processing the first output feature vectors through one or more first output layers.

13 . The apparatus of claim 12 , where the one or more computers are coupled to the communication network.

14 . The apparatus of claim 12 , further comprising the communication network.

15 . The apparatus of claim 12 , where the communication network comprises a Controller Area Network (CAN) bus.

16 . The apparatus of claim 12 , where the instructions, when executed by the one or more computers, cause the one or more computers to:

when the sequence of messages contains an anomaly:

process the input feature vectors using a second graph neural network, based on the graph data, to produce second output feature vectors; and

classify the anomaly, including processing the second output feature vectors through one or more second output layers.

17 . An apparatus comprising:

a memory

a message graph generator configured to receive a sequence of messages of a communication network, each message including data content and a message identifier, and generate therefrom:

graph data denoting:

a node for each message identifier in the sequence of messages; and an edge for each pair of consecutive message identifiers in the sequence of messages, the edge linking two nodes;

a pair count for each edge in the graph data denoting a number of times an associated pair of consecutive message identifiers occurs in the sequence of messages;

an input feature vector for each node in the graph data, the input feature vector denoting:

data content of messages that include the message identifier associated with the node; and

a pair count for each edge connected to the node;

an anomaly detector configured to:

process the input feature vectors using a first graph neural network, based on the graph data, to produce first output feature vectors; and

classify the sequence of messages as containing an anomaly or not, including processing the first output feature vectors through one or more first output layers.

18 . The apparatus of claim 17 , further comprising an anomaly classifier configured to:

process the input feature vectors using a second graph neural network, based on the graph data, to produce second output feature vectors; and

classify the anomaly, including processing the second output feature vectors through one or more second output layers.

19 . The apparatus of claim 17 , further comprising a receiver configured to couple between the communication network and the message graph generator.

20 . The system of claim 17 , further comprising the communication network, where the communication network comprises a Controller Area Network (CAN) bus.

Assignments (1)
ASSIGNMENT OF ASSIGNOR'S INTEREST Recorded Aug 10, 2023
From: HENGRUN, ZHANG; ZENG, KAI
To: GEORGE MASON UNIVERSITY
Reel/Frame 064551/0948 →
Continuity (2)
Provisional Application 63393336 · Jul 29, 2022
Related Publication 20240064160A1 · Feb 22, 2024
References Cited (62)
US 20170300593A1 · Inoue · 2017 [cited by examiner]
US 20210287067A1 · Zavoronkovs · 2021 [cited by examiner]
US 20230385732A1 · Huo · 2023 [cited by examiner]
Tibshirani et al., “Diagnosis of Multiple Cancer Types by Shrunken Centroids of Gene Expression,” in Proceedings of the National Academy of Sciences of the United States of America, vol. 99, No. 10 (May 14, 2002), pp. 6… [cited by applicant]
Tomlinson et al., “Towards Viable Intrusion Detection Methods for the Automotive Controller Area Network,” CSCS 2018, Sep. 13-14, 2018, Munich, Germany. [cited by applicant]
Upstream Security, 2021 Global Automotive Cybersecurity Report, https://upstream.auto/2021report/, 2021. [cited by applicant]
Wei et al., “Federated Learning With Differential Privacy: Algorithms and Performance Analysis,” in IEEE Transactions on Information Forensics and Security, vol. 15, pp. 3454-3469, 2020. [cited by applicant]
Wu et al., “A Comprehensive Survey on Graph Neural Networks,” in IEEE Transactions on Neural Networks and Learning Systems, vol. 32, No. 1, pp. 4-24, Jan. 2021. [cited by applicant]
Wu et al., “A Survey of Intrusion Detection for In-Vehicle Networks,” in IEEE Transactions on Intelligent Transportation Systems, vol. 21, No. 3, pp. 919-933, Mar. 2020. [cited by applicant]
Yang et al., “Tree-Based Intelligent Intrusion Detection System in Internet of Vehicles,” 2019 IEEE Global Communications Conference (GLOBECOM), Waikoloa, HI, USA, 2019, pp. 1-6. [cited by applicant]
Zhang et al., “An end-to-end deep learning architecture for graph classification,” In Proceedings of the Thirty-Second AAAI Conference on Artificial Intelligence and Thirtieth Innovative Applications of Artificial Intel… [cited by applicant]
Zhang et al., “Predicting Failures of Vision Systems,” 2014 IEEE Conference on Computer Vision and Pattern Recognition, Columbus, OH, USA, 2014, pp. 3566-3573. [cited by applicant]
Amato et al., “CAN-Bus Attack Detection With Deep Learning,” in IEEE Transactions on Intelligent Transportation Systems, vol. 22, No. 8, pp. 5081-5090, Aug. 2021. [cited by applicant]
Baccouche et al., “Sequential Deep Learning for Human Action Recognition,” Human Behavior Understanding. HBU 2011. Lecture Notes in Computer Science, vol. 7065. Springer, Berlin, Heidelberg. [cited by applicant]
Bagdasaryan et al., “How to Backdoor Federated Learning,” in Proceedings of the Twenty Third International Conference on Artificial Intelligence and Statistics, Palermo, Italy, vol. 108, 2020. [cited by applicant]
Bendale et al., “Towards Open Set Deep Networks,” arXiv:1511.06233v1, Nov. 19, 2015. [cited by applicant]
Bendale et al., “Towards Open World Recognition,” 2015 IEEE Conference on Computer Vision and Pattern Recognition (CVPR), Boston, MA, USA, 2015, pp. 1893-1902. [cited by applicant]
Blanchard et al., Machine learning with adversaries: byzantine tolerant gradient descent. In Proceedings of the 31st International Conference on Neural Information Processing Systems (NIPS'17). Curran Associates Inc., R… [cited by applicant]
Bonawitz et al, “Practical Secure Aggregation for Privacy-Preserving Machine Learning,” In Proceedings of the 2017 ACM SIGSAC Conference on Computer and Communications Security (CCS '17). Association for Computing Machi… [cited by applicant]
Choi et al., “Identifying ECUs Using Inimitable Characteristics of Signals in Controller Area Networks,” in IEEE Transactions on Vehicular Technology, vol. 67, No. 6, pp. 4757-4770, Jun. 2018. [cited by applicant]
Damaskinos et al., “Aggregathor: Byzantine Machine Learning via Robust Gradient Aggregation,” in Part of Proceedings of Machine Learning and Systems 1 (MLSys 2019). [cited by applicant]
Ding et al., “A deep hybrid learning model to detect unsafe behavior: Integrating convolution neural networks and long short-term memory,” Automation in Construction, vol. 86, 2018, pp. 118-124. [cited by applicant]
Gierlichs et al., Cryptographic Hardware and Embedded Systems—CHES 2016, in Proceedings 18th International Conference Santa Barbara, CA, USA, Aug. 17-19, 2016. Uploaded as Part 1 and Part 2. [cited by applicant]
Groza et al, “Efficient Intrusion Detection With Bloom Filtering in Controller Area Networks,” in IEEE Transactions on Information Forensics and Security, vol. 14, No. 4, pp. 1037-1051, Apr. 2019. [cited by applicant]
Guo et al., “Multi-stage Deep Classifier Cascades for Open World Recognition,” In Proceedings of the 28th ACM International Conference on Information and Knowledge Management (CIKM '19). Association for Computing Machin… [cited by applicant]
Hanselmann et al., “CANet: An Unsupervised Intrusion Detection System for High Dimensional CAN Bus Data,” in IEEE Access, vol. 8, pp. 58194-58205, 2020. [cited by applicant]
Iehira et al., “Spoofing attack using bus-off attacks against a specific ECU of the CAN bus,” 2018 15th IEEE Annual Consumer Communications & Networking Conference (CCNC), Las Vegas, NV, USA, 2018, pp. 1-4. [cited by applicant]
Islam et al., “Graph-Based Intrusion Detection System for Controller Area Networks,” in IEEE Transactions on Intelligent Transportation Systems, vol. 23, No. 3, pp. 1727-1736, Mar. 2022. [cited by applicant]
Jedh et al., “Detection of Message Injection Attacks Onto the CAN Bus Using Similarities of Successive Messages-Sequence Graphs,” in IEEE Transactions on Information Forensics and Security, vol. 16, pp. 4133-4146, 2021. [cited by applicant]
K. Koscher et al., “Experimental Security Analysis of a Modern Automobile,” 2010 IEEE Symposium on Security and Privacy, Oakland, CA, USA, 2010, pp. 447-462. [cited by applicant]
Kang et al., “Intrusion Detection System Using Deep Neural Network for In-Vehicle Network Security,” PLoS One 11 (6): e0155781, Jun. 7, 2016. [cited by applicant]
Kingma et al., “Adam: A Method for Stochastic Optimization,” ICLR 2015. [cited by applicant]
Kosmanos et al., “A novel Intrusion Detection System against spoofing attacks in connected Electric Vehicles,” Array, vol. 5, 2020, 100013. [cited by applicant]
Lee et al., “OTIDS: A Novel Intrusion Detection System for In-vehicle Network by Using Remote Frame,” 2017 15th Annual Conference on Privacy, Security and Trust (PST), Calgary, AB, Canada, 2017, pp. 57-5709. [cited by applicant]
Li et al., “Federated Optimization in Heterogeneous Networks,” arXiv:1812.06127v5, in Proceedings of the 3rd MLSys Conference, Austin, TX, USA, 2020. [cited by applicant]
Lin et al., “Cyber-Security for the Controller Area Network (CAN) Communication Protocol,” 2012 International Conference on Cyber Security, Alexandria, VA, USA, 2012, pp. 1-7. [cited by applicant]
Longari et al., “CANnolo: An Anomaly Detection System Based on LSTM Autoencoders for Controller Area Network,” in IEEE Transactions on Network and Service Management, vol. 18, No. 2, pp. 1913-1924, Jun. 2021. [cited by applicant]
Marchetti et al., “Anomaly detection of CAN bus messages through analysis of ID sequences,” 2017 IEEE Intelligent Vehicles Symposium (IV), Los Angeles, CA, USA, 2017, pp. 1577-1583. [cited by applicant]
Marchetti et al., “Evaluation of anomaly detection for in-vehicle networks through information-theoretic algorithms,” 2016 IEEE 2nd International Forum on Research and Technologies for Society and Industry Leveraging a … [cited by applicant]
Marchetti et al., “READ: Reverse Engineering of Automotive Data Frames,” in IEEE Transactions on Information Forensics and Security, vol. 14, No. 4, pp. 1083-1097, Apr. 2019. [cited by applicant]
Martinelli et al., “Who's Driving My Car? A Machine Learning based Approach to Driver Identification,” In Proceedings of the 4th International Conference on Information Systems Security and Privacy (ICISSP 2018), 367-37… [cited by applicant]
McMahan et al., “Communication-Efficient Learning of Deep Networks from Decentralized Data,” arXiv:1602.05629v4, in Proceedings of the 20th International Conference on Artificial Intelligenceand Statistics (AISTATS) 201… [cited by applicant]
Muter et al., “Entropy-based anomaly detection for in-vehicle networks,” 2011 IEEE Intelligent Vehicles Symposium (IV), Baden-Baden, Germany, 2011, pp. 1110-1115. [cited by applicant]
Nilsson et al., “Vehicle ECU classification based on safety-security characteristics,” IET Road Transport Information and Control—RTIC 2008 and ITS United Kingdom Members' Conference, Manchester, 2008, pp. 1-7. [cited by applicant]
Othmane et al., “On the Performance of Detecting Injection of Fabricated Messages into the CAN Bus,” in IEEE Transactions on Dependable and Secure Computing, vol. 19, No. 1, pp. 468-481, Jan. 1-Feb. 2022. [cited by applicant]
Pesé et al., “S2-CAN: Sufficiently Secure Controller Area Network,” In Proceedings of the 37th Annual Computer Security Applications Conference (ACSAC '21). Association for Computing Machinery, New York, NY, USA, 425-43… [cited by applicant]
Rahmani et al., “Learning a Deep Model for Human Action Recognition from Novel Viewpoints,” IEEE Transactions on Pattern Analysis and Machine Intelligence, Apr. 5, 2017. [cited by applicant]
Rouf et al., “Security and privacy vulnerabilities of in-car wireless networks: A tire pressure monitoring system case study,” in Proceedings of the 19th USENIX Security Symposium, 19th USENIX Security Symposium; Washin… [cited by applicant]
Ruff et al., “Deep One-Class Classification,” in Proceedings of the 35th International Conference on Machine Learning, PMLR 80:4393-4402, 2018. [cited by applicant]
Russakovsky et al., “ImageNet Large Scale Visual Recognition Challenge,” Int J Comput Vis, vol. 115, Apr. 11, 2015, pp. 211-252. [cited by applicant]
Salah et al., “Human Behavior Understanding,” in Proceedings of the 6th International Workshop on Human Behavior Understanding, HBU 2015, held in Osaka, Japan, in Sep. 2015. [cited by applicant]
Scheirer et al., “Meta-Recognition: The Theory and Practice of Recognition Score Analysis,” in IEEE Transactions on Pattern Analysis and Machine Intelligence, vol. 33, No. 8, pp. 1689-1695, Aug. 2011. [cited by applicant]
Schölkopf et al., “Estimating the Support of a High-Dimensional Distribution,” Neural Comput. 13, 7 (Jul. 2001), 1443-1471. [cited by applicant]
Seo et al., “GIDS: GAN based Intrusion Detection System for In-Vehicle Network,” 2018 16th Annual Conference on Privacy, Security and Trust (PST), Belfast, Ireland, 2018, pp. 1-6. [cited by applicant]
So et al., “Byzantine-Resilient Secure Federated Learning,” in IEEE Journal on Selected Areas in Communications, vol. 39, No. 7, pp. 2168-2181, Jul. 2021. [cited by applicant]
Song et al., “Discovering CAN Specification Using On-Board Diagnostics,” in IEEE Design & Test, vol. 38, No. 3, pp. 93-103, Jun. 2021. [cited by applicant]
Song et al., “Intrusion detection system based on the analysis of time intervals of CAN messages for in-vehicle network,” 2016 International Conference on Information Networking (ICOIN), Kota Kinabalu, Malaysia, 2016, p… [cited by applicant]
Sun et al., “Anomaly Detection for In-Vehicle Network Using CNN-LSTM With Attention Mechanism,” in IEEE Transactions on Vehicular Technology, vol. 70, No. 10, pp. 10880-10893, Oct. 2021. [cited by applicant]
Tariq et al., “CANTransfer: transfer learning based intrusion detection on a controller area network using convolutional LSTM network,” In Proceedings of the 35th Annual ACM Symposium on Applied Computing (SAC '20). Ass… [cited by applicant]
Tax et al., “Support Vector Data Description,” Machine Learning, vol. 54, Jan. 2004, pp. 45-66. [cited by applicant]
Taylor et al, “Anomaly Detection in Automobile Control Network Data with Long Short-Term Memory Networks,” 2016 IEEE International Conference on Data Science and Advanced Analytics (DSAA), Montreal, QC, Canada, 2016, pp… [cited by applicant]
Taylor et al., “Frequency-based anomaly detection for the automotive CAN bus,” 2015 World Congress on Industrial Control Systems Security (WCICSS), London, UK, 2015, pp. 45-49. [cited by applicant]