DOI: https://doi.org/10.1038/s41598-025-94445-9
PMID: https://pubmed.ncbi.nlm.nih.gov/40210906
تاريخ النشر: 2025-04-10
المؤلف: Hasim Ali Khan وآخرون
الموضوع الرئيسي: أمن الشبكات وكشف التسلل
نظرة عامة
لقد أثار التوسع السريع في شبكات إنترنت المركبات (IoV) تحديات أمنية كبيرة، لا سيما في كشف التسلل بسبب طبيعتها المعقدة والديناميكية. يقدم هذا البحث عدة تدابير أمنية مبتكرة، بما في ذلك تشفير AES-256 للأمان القوي في الوقت الحقيقي، والحساب الآمن متعدد الأطراف (SMPC)، والتشفير المتجانس (HE) لمعالجة البيانات مع الحفاظ على الخصوصية. لتعزيز أداء نظام كشف التسلل القائم على التعلم العميق (IDS)، يستخدم البحث تطبيع Z-score واستبدال الوسيط لإعداد البيانات، إلى جانب تقنيات استخراج الميزات المتقدمة باستخدام Vision Transformer (ViT)، وتحويلات الموجة، وشبكات الانتباه الرسومية (GAT). تم اقتراح طريقة تحسين هجينة جديدة، وهي تحسين Crayfish-Mother الآمن (CMSO)، لتحسين اختيار الميزات مع تقليل التكاليف الحاسوبية. إن دمج DenseNet وGoogleNet وAlexNet وSqueezeNet ضمن بنية DAGSNet الجديدة يحسن بشكل كبير من دقة كشف الميزات وتصنيفها، محققًا معدلات دقة تبلغ 0.991 و0.984 على مجموعتين من البيانات، مع أوقات تشفير وفك تشفير ضئيلة تبلغ 0.02 ثانية و0.82 ثانية، على التوالي.
يعمل نموذج EDL-CMSO بشكل فعال على دمج خوارزميات التشفير المعقدة، وتقنيات استخراج الميزات الفعالة، وهياكل التعلم العميق المحسّنة لمعالجة القضايا الحرجة في كشف التسلل في IoV. بينما يعزز تنفيذ طرق التشفير المتقدمة الخصوصية والأمان، إلا أنه قد يؤدي أيضًا إلى زيادة استهلاك الطاقة والتكاليف الحاسوبية، مما يطرح تحديات للتوسع والمعالجة في الوقت الحقيقي في بيئات IoV ذات الموارد المحدودة. يظهر النموذج المقترح وعدًا للتطبيقات الواقعية، لا سيما في إدارة الأساطيل المتصلة، والمركبات المستقلة، وأنظمة النقل الذكية، حيث يمكنه حماية الاتصالات بين المركبات والبنية التحتية (V2I) وبين المركبات (V2V). ستركز الأعمال المستقبلية على تعزيز طرق التشفير، وتحسين الكفاءة الحاسوبية، وتقييم متانة النموذج ضد التهديدات السيبرانية المعقدة في شبكات IoV الكبيرة، بهدف تعزيز الأمان في تطبيقات المدن الذكية المتطورة وتركيبات IoV الضخمة.
طرق
تقدم المنهجية المقترحة في هذا البحث نموذج Crayfish-Mother Swarm Optimizer القائم على التعلم العميق للتشفير (EDL-CMSO) الذي يهدف إلى تعزيز كشف التسلل في أنظمة إنترنت المركبات (IoV). يدمج الإطار التعلم العميق (DL)، وتكنولوجيا البلوكشين، وطرق التشفير المتقدمة، مستخدمًا الحساب الآمن متعدد الأطراف (SMPC) والتشفير المتجانس (HE) لتسهيل الحسابات على البيانات المشفرة دون الكشف الكامل. يتم استخدام معيار التشفير المتقدم (AES-256) لتأمين المفاتيح المتماثلة وتطبيقات الأجهزة في الحلقة، مما يعزز التحكم في الوصول وحماية البيانات في الوقت الحقيقي. يتم تطبيق تقنيات المعالجة المسبقة، بما في ذلك استبدال الوسيط لتنظيف البيانات وتطبيع Z-score للتوحيد القياسي، ضمن نظام كشف التسلل القائم على التعلم العميق (IDS).
تستفيد البنية من إطار DAGSNet الجديد، الذي يجمع الميزات من DenseNet وGoogleNet وAlexNet وSqueezeNet لتعزيز قدرات كشف الميزات. يتم استخدام Crayfish-Mother Swarm Optimizer (CMSO) لاختيار الميزات بكفاءة، بينما تستخدم تقنيات استخراج الميزات المتقدمة مثل Vision Transformer (ViT)، وتحويلات الموجة، وشبكات الانتباه الرسومية (GAT). يضمن هذا التكامل الشامل كشف التسلل بشكل فعال وآمن ويحافظ على الخصوصية في أنظمة IoV. تبدأ المقاربة متعددة المراحل المنهجية بجمع البيانات من بيئات شبكة التحكم في المنطقة (CAN)، تليها التشفير والمعالجة المسبقة لتنقيح البيانات. يصنف النموذج في النهاية حركة مرور الشبكة على أنها ضارة أو طبيعية، مما يوفر حلاً قويًا للأمن السيبراني في التطبيقات السيارات.
نقاش
تستعرض قسم النقاش في الورقة التقدمات الأخيرة في أنظمة كشف التسلل (IDS) لإنترنت المركبات (IoV)، مع تسليط الضوء على مجموعة متنوعة من الأساليب المبتكرة وآثارها على الأمان والخصوصية. قدم Liu et al. (2021) نظام كشف تسلل تعاوني يستفيد من التعلم الفيدرالي على الأجهزة الطرفية، مما يعزز الخصوصية ويقلل من استخدام الموارد من خلال تكنولوجيا البلوكشين. طور El-Gayar et al. (2024) شبكة الغابة الديناميكية المنظمة (DFSENet)، التي تصنف بشكل فعال بيانات حركة مرور الشبكة لحماية المركبات المتصلة الذكية من التهديدات السيبرانية. تشمل المساهمات الملحوظة الأخرى استراتيجيات التعلم الانتقالي لـ Li et al. (2021) لتحديثات النموذج في الوقت المناسب، وخوارزميات التعلم الآلي لـ Sousa et al. (2023) لسيناريوهات المركبات المدعومة بشبكة 5G، واستخدام Poongodi وHamdi (2023) للشبكات التنافسية التوليدية لنظام كشف التسلل الموزع.
على الرغم من هذه التقدمات، تحدد الورقة التحديات المستمرة في مشهد IoV، مثل الطلبات العالية على المعالجة، والحاجة إلى بيانات مصنفة في الوقت الحقيقي، وقيود النماذج المركزية، التي تؤثر على الكفاءة وقابلية التوسع. يؤكد المؤلفون على ضرورة وجود حل شامل وقابل للتكيف يعالج هذه القضايا، مما يضمن كشف التسلل بشكل موثوق وفعال عبر بيئات IoV المتنوعة. يبرز النقاش أهمية دمج تقنيات متقدمة مثل التعلم العميق، والتعلم الفيدرالي، والتحليل الزمني المكاني لتعزيز مرونة IDS ضد التهديدات السيبرانية المتطورة.
القيود
يعترف قسم القيود بعدة تحديات مرتبطة بنظام كشف التسلل (IDS) القائم على EDL-CMSO المقترح لإنترنت المركبات (IoV). أولاً، يعزز دمج التشفير المتجانس (HE) والحساب الآمن متعدد الأطراف (SMPC) الخصوصية ولكنه يقدم عبئًا حاسوبيًا، مما قد يعيق الأداء في الوقت الحقيقي في البيئات ذات الموارد المحدودة. ثانيًا، بينما يقوم Crayfish-Mother Swarm Optimizer (CMSO) بتحسين اختيار الميزات، لا يزال التصنيف القائم على التعلم العميق يتطلب قوة معالجة كبيرة، مما يعقد النشر على الأجهزة الطرفية ذات الطاقة المحدودة. بالإضافة إلى ذلك، على الرغم من أن طرق توازن البيانات تخفف من عدم توازن الفئات، إلا أنها قد تقدم عن غير قصد تحيزًا اصطناعيًا، مما يؤثر على قابلية تطبيق النظام في السيناريوهات الواقعية.
تؤكد الورقة على الجمع المبتكر بين SMPC وHE وAES-256 مع التعلم العميق لنظام كشف التسلل، مما يعد بحسابات تحافظ على الخصوصية وكشف فعال عن التهديدات. ومع ذلك، تقترح أن مساهمات EDL-CMSO في معالجة قيود IDS الحالية – مثل العبء الحاسوبي العالي وانخفاض القدرة على التكيف مع أنماط الهجوم الجديدة – يجب أن يتم توضيحها بشكل أكثر صراحة. تدعي البحث ثلاث مساهمات رئيسية: تقديم CMSO لاختيار الميزات بكفاءة، وتطوير DAGSNet لدقة تصنيف عالية، ودمج طرق التشفير المتقدمة لتحديد التهديدات بشكل آمن. من خلال مقارنة EDL-CMSO بشكل صارم مع تقنيات IDS الحديثة، تظهر الدراسة دقتها الفائقة في الكشف (94-97%)، وانخفاض معدلات الإنذارات الكاذبة، وقابلية التوسع، مما يضع معيارًا شاملاً للبحث المستقبلي في هذا المجال.
DOI: https://doi.org/10.1038/s41598-025-94445-9
PMID: https://pubmed.ncbi.nlm.nih.gov/40210906
Publication Date: 2025-04-10
Author(s): Hasim Ali Khan et al.
Primary Topic: Network Security and Intrusion Detection
Overview
The rapid expansion of Internet of Vehicle (IoV) networks has raised significant security challenges, particularly in intrusion detection due to their complex and dynamic nature. This research introduces several innovative security measures, including AES-256 encryption for robust real-time security, Secure Multi-Party Computation (SMPC), and Homomorphic Encryption (HE) for privacy-preserving data processing. To enhance the performance of a deep learning-based intrusion detection system (IDS), the study employs Z-score normalization and median imputation for data preparation, alongside advanced feature extraction techniques using Vision Transformer (ViT), wavelet transforms, and Graph Attention Networks (GAT). A novel hybrid optimization method, Crayfish-Mother secure Optimization (CMSO), is proposed to optimize feature selection while minimizing computational costs. The integration of DenseNet, GoogleNet, AlexNet, and SqueezeNet within the new DAGSNet architecture significantly improves feature detection and classification accuracy, achieving precision rates of 0.991 and 0.984 on two datasets, with minimal encryption and decryption times of 0.02 seconds and 0.82 seconds, respectively.
The EDL-CMSO model effectively combines complex encryption algorithms, efficient feature extraction techniques, and optimized deep learning structures to address critical issues in IoV intrusion detection. While the implementation of advanced cryptographic methods enhances privacy and security, it may also lead to increased energy consumption and computational costs, posing challenges for scalability and real-time processing in resource-constrained IoV environments. The proposed model shows promise for real-world applications, particularly in connected fleet management, autonomous vehicles, and intelligent transportation systems, where it can safeguard vehicle-to-infrastructure (V2I) and vehicle-to-vehicle (V2V) communications. Future work will focus on enhancing encryption methods, improving computational efficiency, and assessing the model’s robustness against sophisticated cyber threats in large-scale IoV networks, ultimately aiming to bolster security in evolving smart city applications and mass IoV installations.
Methods
The proposed methodology in this research introduces an encryption deep learning-based Crayfish-Mother Swarm Optimizer (EDL-CMSO) model aimed at enhancing intrusion detection in Internet of Vehicles (IoV) systems. The framework integrates deep learning (DL), blockchain technology, and advanced cryptographic methods, utilizing Secure Multi-Party Computation (SMPC) and Homomorphic Encryption (HE) to facilitate computations on encrypted data without full disclosure. The Advanced Encryption Standard (AES-256) is employed to secure symmetric keys and hardware-in-the-loop applications, bolstering access control and real-time data protection. Preprocessing techniques, including median imputation for data cleaning and Z-score normalization for standardization, are applied within the deep learning-based Intrusion Detection System (IDS).
The architecture leverages the novel DAGSNet framework, which amalgamates features from DenseNet, GoogleNet, AlexNet, and SqueezeNet to enhance feature detection capabilities. The Crayfish-Mother Swarm Optimizer (CMSO) is utilized for efficient feature selection, while feature extraction employs advanced techniques such as Vision Transformer (ViT), Wavelet Transforms, and Graph Attention Networks (GAT). This comprehensive integration ensures effective, secure, and privacy-preserving intrusion detection in IoV systems. The systematic multi-phase approach begins with data collection from Controller Area Network (CAN) environments, followed by encryption and preprocessing to refine the data. The model ultimately classifies network traffic as either malicious or normal, providing a robust solution for cybersecurity in automotive applications.
Discussion
The discussion section of the paper reviews recent advancements in intrusion detection systems (IDS) for the Internet of Vehicles (IoV), highlighting various innovative approaches and their implications for security and privacy. Liu et al. (2021) introduced a cooperative IDS leveraging federated learning on edge devices, enhancing privacy and reducing resource utilization through blockchain technology. El-Gayar et al. (2024) developed the Dynamic Forest-Structured Ensemble Network (DFSENet), which effectively classifies network traffic data to protect intelligent connected vehicles from cyber threats. Other notable contributions include Li et al.’s (2021) transfer learning strategies for timely model updates, Sousa et al.’s (2023) machine learning algorithms for 5G-enabled vehicle scenarios, and Poongodi and Hamdi’s (2023) use of generative adversarial networks for distributed IDS.
Despite these advancements, the paper identifies persistent challenges in the IoV landscape, such as high processing demands, the need for real-time labeled data, and the limitations of centralized models, which compromise efficiency and scalability. The authors emphasize the necessity for a comprehensive and adaptable solution that addresses these issues, ensuring reliable and effective intrusion detection across diverse IoV environments. The discussion underscores the importance of integrating advanced techniques like deep learning, federated learning, and spatiotemporal analysis to enhance the resilience of IDS against evolving cyber threats.
Limitations
The section on limitations acknowledges several challenges associated with the proposed EDL-CMSO-based Intrusion Detection System (IDS) for Internet of Vehicles (IoV). Firstly, the integration of Homomorphic Encryption (HE) and Secure Multi-Party Computation (SMPC) enhances privacy but introduces computational overhead, potentially hindering real-time performance in resource-constrained environments. Secondly, while the Crayfish-Mother Swarm Optimizer (CMSO) optimizes feature selection, the deep learning-based classification still demands significant processing power, complicating deployment on power-limited edge devices. Additionally, although data balancing methods mitigate class imbalance, they may inadvertently introduce synthetic bias, affecting the system’s applicability in real-world scenarios.
The paper emphasizes the innovative combination of SMPC, HE, and AES-256 with deep learning for IDS, which promises privacy-preserving computations and efficient threat detection. However, it suggests that the contributions of EDL-CMSO in addressing existing IDS limitations—such as high computational overhead and low adaptability to novel attack patterns—should be more explicitly articulated. The research claims three key contributions: the introduction of CMSO for efficient feature selection, the development of DAGSNet for high classification accuracy, and the incorporation of advanced encryption methods for secure threat identification. By rigorously comparing EDL-CMSO with state-of-the-art IDS techniques, the study demonstrates its superior detection accuracy (94-97%), reduced false alarm rates, and scalability, thereby establishing a comprehensive benchmark for future research in this domain.
