Table 1.
Comparison of architectural features of existing CAN intrusion detection methods and the proposed framework.
Fig 1.
Proposed 1D CNN-BiLSTM intrusion detection framework for CAN bus networks.
Table 2.
Hyperparameter settings of the proposed 1D CNN–Deep BiLSTM intrusion detection model.
Fig 2.
Data preprocessing workflow used for CAN intrusion detection, including feature extraction, normalization, window construction, and attack label assignment.
Table 3.
Comparative performance analysis of deep learning architectures for CAN intrusion detection.
Table 4.
Wilcoxon signed-rank test results using fold-wise F1-scores obtained from 10-fold cross-validation.
Fig 3.
Performance comparison of intrusion detection models.
Table 5.
Evaluation results of last-frame and any-attack window labeling methods.
Fig 4.
Performance improvement achieved using any-attack window labeling strategy.
Table 6.
Performance variation of the proposed model under different decision thresholds.
Table 7.
Performance comparison of different focal loss values.
Fig 5.
Effect of focal loss alpha parameter on IDS performance.
Fig 6.
Performance comparison between the baseline BiLSTM model from the base paper and the proposed CNN–BiLSTM with focal loss model.
Table 8.
Performance comparison between the baseline BiLSTM model from the base paper and the proposed CNN–BiLSTM with focal loss model.