Transformer-Based Intrusion Detection for Internet of Vehicles Using Multi-Strategy Feature Selection Approach
DOI:
https://doi.org/10.52436/1.jutif.2026.7.4.6001Keywords:
CAN Bus Security, Feature Selection, Intelligent Transportation Systems, Internet of Vehicles, Intrusion Detection System, TransformerAbstract
The rapid development of the Internet of Vehicles (IoV) has significantly increased the exposure of intelligent transportation systems to sophisticated cyber threats, particularly targeting in-vehicle communication networks such as the Controller Area Network (CAN). Conventional intrusion detection systems and traditional machine learning approaches often face limitations in capturing complex attack patterns under high-dimensional and dynamic vehicular network conditions. To address these challenges, this paper proposes a Transformer-based intrusion detection framework for the Internet of Vehicles using a multi-strategy feature selection approach. The proposed method integrates Information Gain, Principal Component Analysis, and Random Forest-based feature importance to systematically identify the most informative features from vehicular network traffic while reducing redundancy and computational overhead. A Transformer architecture with a self-attention mechanism is employed to model global dependencies and complex interactions within CAN bus data. The framework is evaluated on the CICIoV dataset using multiple data representations, including binary, decimal, and hexadecimal formats, to reflect realistic IoV communication scenarios. Experimental results demonstrate that the proposed model achieves consistently high detection performance, with accuracy and F1-score exceeding 99% under optimal feature selection configurations, while maintaining stable generalization across cross-validation folds. These findings indicate that the proposed framework provides a robust and effective solution for intelligent intrusion detection in Internet of Vehicles networks. Unlike existing approaches that rely on single feature selection strategies or raw feature inputs, the proposed framework uniquely integrates three complementary selection techniques within a unified Transformer-based architecture, addressing both feature redundancy and model scalability simultaneously. The findings of this study have significant implications for cybersecurity in intelligent transportation systems, offering a scalable and computationally efficient intrusion detection solution applicable to resource-constrained vehicular edge devices such as Electronic Control Units.
Downloads
References
J. Cao, X. Di, J. Li, K. Yu, and L. Zhao, “IoVST: An anomaly detection method for IoV based on spatiotemporal feature fusion,” Future Gener. Comput. Syst., vol. 166, no. November 2024, p. 107636, 2025, doi: 10.1016/j.future.2024.107636.
I. Mahmoudi, D. E. Boubiche, S. Athmani, H. Toral-Cruz, and F. I. Chan-Puc, “Toward Generative AI-Based Intrusion Detection Systems for the Internet of Vehicles (IoV),” Future Internet, vol. 17, no. 7, p. 310, Jul. 2025, doi: 10.3390/fi17070310.
R. Chen, X. Chen, and J. Zhao, “Private and utility enhanced intrusion detection based on attack behavior analysis with local differential privacy on IoV,” Comput. Netw., vol. 250, no. May, p. 110560, 2024, doi: 10.1016/j.comnet.2024.110560.
B. T. Alemu and A. J. Muhammed, “Controller-targeted DDoS attack detection and mitigation in software-defined internet of vehicles (SD-IoV),” 2023 Int. Conf. Inf. Commun. Technol. Dev. Afr. ICT4DA 2023, pp. 138–143, 2023, doi: 10.1109/ICT4DA59526.2023.10302231.
M. Dilshad et al., “IoV cyber defense: Advancing DDoS attack detection with gini index in tree models,” in 2024 international conference on emerging trends in networks and computer communications, ETNCC 2024 - proceedings, IEEE, 2024, pp. 681–688. doi: 10.1109/ETNCC63262.2024.10767505.
M. Hanifa and H. T. Zubair, “Intrusion detection system for cyber-attacks in the internet of vehicles (IoV) environment,” 1st Int. Conf. Cyber Secur. Comput. 2024 CyberComp 2024, vol. 1, pp. 68–73, 2024, doi: 10.1109/CyberComp60759.2024.10913617.
Happy, A. Iqubal, and S. K. Tiwari, “Internet of vehicle (IoV) cyber attack detection using machine learning techniques,” in 2024 4th international conference on advancement in electronics and communication engineering, AECE 2024, IEEE, 2024, pp. 1053–1057. doi: 10.1109/AECE62803.2024.10911517.
Z. Liu, H. Xu, Y. Kuang, and F. Li, “SVMDformer: a semi-supervised vehicular misbehavior detection framework based on transformer in IoV,” Proc. - Int. Conf. Distrib. Comput. Syst., vol. 2023-July, pp. 887–897, 2023, doi: 10.1109/ICDCS57875.2023.00035.
H. C. Altunay and Z. Albayrak, “A hybrid CNN + LSTMbased intrusion detection system for industrial IoT networks,” Eng. Sci. Technol. Int. J., vol. 38, p. 101322, 2023, doi: 10.1016/j.jestch.2022.101322.
S. E. V. S. Pillai, K. Polimetla, C. S. Prakash, P. K. Pareek, and P. P. Pawar, “IoT Security Detection and Evaluation for Smart Cyber Infrastructures Using LSTMs with Attention Mechanism,” in 2024 Third International Conference on Distributed Computing and Electrical Circuits and Electronics (ICDCECE), Ballari, India: IEEE, Apr. 2024, pp. 1–5. doi: 10.1109/ICDCECE60827.2024.10548639.
S. Sharipuddin et al., “Intrusion detection with deep learning on internet of things heterogeneous network,” IAES Int. J. Artif. Intell. IJ-AI, vol. 10, no. 3, p. 735, 2021, doi: 10.11591/ijai.v10.i3.pp735-742.
S. Lysenko, K. Bobrovnikova, V. Kharchenko, and O. Savenko, “IoT multi-vector cyberattack detection based on machine learning algorithms: Traffic features analysis, experiments, and efficiency,” Algorithms, vol. 15, no. 7, 2022, doi: 10.3390/a15070239.
M. Sarhan, S. Layeghy, and M. Portmann, “Feature analysis for machine learning-based IoT intrusion detection,” 2021, [Online]. Available: http://arxiv.org/abs/2108.12732
S. W. Ahmed, F. Kientz, and R. Kashef, “A Modified Transformer Neural Network (MTNN) for Robust Intrusion Detection in IoT Networks,” in 2023 International Telecommunications Conference (ITC-Egypt), Alexandria, Egypt: IEEE, Jul. 2023, pp. 663–668. doi: 10.1109/ITC-Egypt58155.2023.10206134.
R. Kumar, P. Kumar, R. Tripathi, G. P. Gupta, and N. Kumar, “P2SF-IoV: a privacy-preservation-based secured framework for internet of vehicles,” IEEE Trans. Intell. Transp. Syst., vol. 23, no. 11, pp. 22571–22582, 2022, doi: 10.1109/TITS.2021.3102581.
X. Wang, Y. Xu, Y. Xu, Z. Wang, and Y. Wu, “Intrusion Detection System for In-Vehicle CAN-FD Bus ID Based on GAN Model,” IEEE Access, vol. 12, pp. 82402–82412, 2024, doi: 10.1109/ACCESS.2024.3412933.
E. Gelenbe, B. C. Gül, and M. Nakıp, “DISFIDA: Distributed self-supervised federated intrusion detection algorithm with online learning for health internet of things and internet of vehicles,” Internet Things Neth., vol. 28, no. August, p. 101340, 2024, doi: 10.1016/j.iot.2024.101340.
Y. Shen et al., “MLIA: modulated LED illumination-based adversarial attack on traffic sign recognition system for autonomous vehicle,” in Proceedings - 2022 IEEE 21st international conference on trust, security and privacy in computing and communications, TrustCom 2022, IEEE, 2022, pp. 1020–1027. doi: 10.1109/TrustCom56396.2022.00139.
O. D. Okey, D. C. Melgarejo, M. Saadi, R. L. Rosa, J. H. Kleinschmidt, and D. Z. Rodriguez, “Transfer learning approach to IDS on cloud IoT devices using optimized CNN,” IEEE Access Pract. Innov. Open Solut., vol. 11, no. January, pp. 1023–1038, 2023, doi: 10.1109/ACCESS.2022.3233775.
H. Mun et al., “Privacy enhanced data aggregation based on federated learning in Internet of Vehicles (IoV),” Comput. Commun., vol. 223, no. February, pp. 15–25, 2024, doi: 10.1016/j.comcom.2024.05.009.
Y. Cao, X. Tang, X. Deng, and P. Wang, “Fault detection of complicated processes based on an enhanced transformer network with graph attention mechanism,” Process Saf. Environ. Prot., vol. 186, pp. 783–797, Jun. 2024, doi: 10.1016/j.psep.2024.04.012.
D. Chaudhry, H. Goel, and B. Verma, “TransFAS: Transformer-based network for Face Anti-Spoofing using Token Guided Inspection,” in 2023 IEEE 8th International Conference for Convergence in Technology (I2CT), Lonavla, India: IEEE, Apr. 2023, pp. 1–7. doi: 10.1109/I2CT57861.2023.10126455.
Y.-D. Lin et al., “ELAT: Ensemble Learning with Adversarial Training in defending against evaded intrusions,” J. Inf. Secur. Appl., vol. 71, p. 103348, Dec. 2022, doi: 10.1016/j.jisa.2022.103348.
O. Pandithurai, C. Venkataiah, S. Tiwari, and N. Ramanjaneyulu, “DDoS attack prediction using a honey badger optimization algorithm based feature selection and Bi-LSTM in cloud environment,” Expert Syst. Appl., vol. 241, no. October 2023, p. 122544, 2024, doi: 10.1016/j.eswa.2023.122544.
T. P. Nguyen, H. Nam, and D. Kim, “Transformer-based attention network for in-vehicle intrusion detection,” IEEE Access Pract. Innov. Open Solut., vol. 11, no. June, pp. 55389–55403, 2023, doi: 10.1109/ACCESS.2023.3282110.
H. Yang and M. Effatparvar, “A deep learning based intrusion detection system for CAN vehicle based on combination of triple attention mechanism and GGO algorithm,” Sci. Rep., vol. 15, no. 1, p. 19462, Jun. 2025, doi: 10.1038/s41598-025-04720-y.
C. Zhang, J. Li, N. Wang, and D. Zhang, “Research on Intrusion Detection Method Based on Transformer and CNN-BiLSTM in Internet of Things,” Sensors, vol. 25, no. 9, p. 2725, Apr. 2025, doi: 10.3390/s25092725.
B. Lampe and W. Meng, “A survey of deep learning-based intrusion detection in automotive applications,” Expert Syst. Appl., vol. 221, p. 119771, Jul. 2023, doi: 10.1016/j.eswa.2023.119771.
P. Ye et al., “GDT-IDS: Graph-based decision tree intrusion detection system for controller area network,” J. Supercomput., vol. 81, no. 4, p. 591, Mar. 2025, doi: 10.1007/s11227-025-07116-x.
E. C. P. Neto et al., “CICIoV2024: Advancing realistic IDS approaches against DoS and spoofing attack in IoV CAN bus,” Internet Things Neth., vol. 26, no. May, p. 101209, 2024, doi: 10.1016/j.iot.2024.101209.
Additional Files
Published
How to Cite
Issue
Section
License
Copyright (c) 2026 Eko Arip Winanto, M Riza Pahlevi B, Sharipuddin, Dodi Sandra, Febby Tri Ramadhanti

This work is licensed under a Creative Commons Attribution 4.0 International License.

</a



