Explainable Machine Learning for Cyberattack Identification from Traffic Flows
By: Yujing Zhou , Marc L. Jacquet , Robel Dawit and more
Potential Business Impact:
Protects traffic lights from computer hackers.
The increasing automation of traffic management systems has made them prime targets for cyberattacks, disrupting urban mobility and public safety. Traditional network-layer defenses are often inaccessible to transportation agencies, necessitating a machine learning-based approach that relies solely on traffic flow data. In this study, we simulate cyberattacks in a semi-realistic environment, using a virtualized traffic network to analyze disruption patterns. We develop a deep learning-based anomaly detection system, demonstrating that Longest Stop Duration and Total Jam Distance are key indicators of compromised signals. To enhance interpretability, we apply Explainable AI (XAI) techniques, identifying critical decision factors and diagnosing misclassification errors. Our analysis reveals two primary challenges: transitional data inconsistencies, where mislabeled recovery-phase traffic misleads the model, and model limitations, where stealth attacks in low-traffic conditions evade detection. This work enhances AI-driven traffic security, improving both detection accuracy and trustworthiness in smart transportation systems.
Similar Papers
Machine Learning for Cyber-Attack Identification from Traffic Flows
Machine Learning (CS)
Finds computer attacks on traffic lights.
Building Transparency in Deep Learning-Powered Network Traffic Classification: A Traffic-Explainer Framework
Networking and Internet Architecture
Shows why internet traffic is going where.
Explainable and Resilient ML-Based Physical-Layer Attack Detectors
Cryptography and Security
Helps computers spot sneaky network attacks faster.