Pith. sign in

REVIEW 3 major objections 5 minor 64 references

Most vehicular federated-learning IDS papers rest on artificial data splits, trivial attacks, and no real-time checks, so their privacy and accuracy claims are only weakly supported.

Reviewed by Pith at T0; open to challenge. T0 means a machine referee read the full paper against a public rubric. the ladder, T0–T4 →

T0 review · grok-4.5

2026-07-14 08:19 UTC pith:6ZYLCPA2

load-bearing objection Solid SoK that correctly flags the evaluation shortcuts in vehicular FL-IDS and gives a usable minimum checklist; corpus is approximate but the diagnosis holds. the 3 major comments →

arxiv 2607.10914 v1 pith:6ZYLCPA2 submitted 2026-07-12 cs.CR

SoK: Federated Learning for Intrusion Detection in Vehicular Networks

classification cs.CR
keywords Federated LearningIntrusion Detection SystemsVehicular NetworksController Area NetworkVehicle-to-EverythingAdversarial Machine LearningByzantine RobustnessSystematization of Knowledge
verification ladder T0 review T1 audit T2 compute T3 formal T4 reserved

The pith

A machine-rendered reading of the paper's core claim, the machinery that carries it, and where it could break.

This Systematization of Knowledge audits more than sixty papers that use federated learning for intrusion or misbehaviour detection inside cars and across vehicle-to-everything links. It shows that the field repeatedly evaluates models under conditions that never appear on the road: randomly shuffled data that looks identical across vehicles, attack traces that frequency counters already catch, almost no malicious participants, and no measurement of whether a detector can finish before the next CAN frame arrives. The authors unify the attack surfaces, map the federation topologies and poisoning threats, and then grade five common claims; only the bandwidth-saving claim is solidly backed. They finish with a concrete research agenda and a short list of minimum evaluation rules that any future paper would have to meet before its security guarantees can be trusted outside simulation.

Core claim

After coding the literature against a fixed schema, the authors conclude that high reported F1-scores, privacy guarantees, and Byzantine robustness are artefacts of unrealistic experimental design—IID random splits, the Car-Hacking dataset, missing adversaries, and ignored CAN timing budgets—so the community’s central claims are only conditionally or weakly supported.

What carries the argument

The fixed data-extraction schema (Table I) applied to every included study, which forces each paper to be scored on the same axes—dataset realism, IID versus non-IID partition, Byzantine fraction, aggregation rule, privacy mechanism, and inference-latency reporting—thereby turning scattered experimental choices into a single, comparable critique.

Load-bearing premise

That an iterative keyword-and-snowball search performed by the same small team, without logged hit counts or independent coding checks, still yields a representative picture of the whole field.

What would settle it

A multi-lab re-coding of the same corpus (or an expanded one) that finds a substantial fraction of papers already using vehicle-identity partitions, realistic multi-vehicle datasets, at least 10 percent Byzantine clients, and reported CAN-frame inference latencies; if that fraction is high, the “pervasive pitfalls” claim collapses.

Watch this falsifier. Get emailed when new claim-graph text bears on it.

Editorial analysis

A structured set of objections, weighed in public.

Desk editor's note, referee report, simulated authors' rebuttal, and a circularity audit.

Referee Report

3 major / 5 minor

Summary. This SoK audits federated-learning-based intrusion and misbehaviour detection for vehicular networks (in-vehicle CAN and V2X). It unifies a three-layer attack taxonomy, classifies FL topologies, model families, aggregation rules, and privacy mechanisms, and maps adversarial threats (poisoning, backdoors, inference, Sybil). From an iterative audit of more than 60 papers coded against a fixed schema (Table I), the authors argue that the literature is weakened by artificial IID client splits, over-reliance on trivial benchmarks (especially Car-Hacking), weak or absent Byzantine evaluation, and omission of real-time CAN inference constraints. Section VIII grades five common claims as only partially, conditionally, or weakly supported, and Section IX proposes a five-item minimum benchmarking checklist plus a research agenda (non-IID/personalization, edge-aggregator security, real-time co-design, cross-OEM federation, standards integration).

Significance. If the diagnosis holds, the paper is a useful field-level corrective for vehicular FL-IDS: it consolidates fragmented intra-vehicle and V2X threads, makes adversarial and evaluation gaps explicit, and offers a concrete, falsifiable minimum evaluation standard that venues and authors can adopt. Strengths include the transparent coding schema (Table I), the claim-by-claim evidence assessment in Section VIII, the dataset suitability table (Table V), and the authors’ own Threats-to-Validity discussion (II-D). The work does not claim new algorithms or machine-checked proofs; its value is systematization and evaluation hygiene rather than a novel technical result.

major comments (3)
  1. [VII-C / Table I] Section VII-C and the abstract assert field-level frequencies (“substantial majority” IID splits; “majority” single-dataset evaluation; “minority” Byzantine evaluation; “no surveyed paper” reports CAN inference latency). Table I shows these fields were coded, yet the manuscript never reports the actual counts or fractions (e.g., N/60 for each pitfall). Without a summary table of coded outcomes, the central claim that these pitfalls are recurring and undermine privacy/accuracy/robustness claims remains qualitative and hard to audit. Please add a results table (or appendix) with per-field frequencies and, where possible, paper identifiers or a supplementary coding sheet.
  2. [II-D, VII–VIII, Abstract] Section II-D correctly flags approximate corpus size, unlogged hit counts, and single-team coding. Frequency language in VII–VIII and the abstract still reads as definitive. Either (a) strengthen reproducibility (logged query dates, inclusion list of the ~60 papers, inter-coder check on a sample) or (b) systematically hedge claims to “among coded studies” and drop majority/minority phrasing that cannot be independently verified. This is load-bearing for an SoK whose main contribution is a field audit.
  3. [VIII] Section VIII grades five claims (privacy, accuracy, communication, hierarchical FL, robust aggregation) with assessments such as PARTIALLY SUPPORTED and WEAKLY SUPPORTED. The grades are plausible but only loosely tied to the coded schema: e.g., Claim 1 cites gradient inversion and SecAgg/DP usage without stating how many of the >60 papers actually deploy SecAgg or DP. Align each grade with explicit counts from the coding (privacy mechanism, Byzantine eval, partitioning, latency) so the systematization is evidence-based rather than narrative.
minor comments (5)
  1. [Table V / IX-A] Table V and Fig. 2 usefully rate FL suitability, but several “FL Partition?” cells are “No” even for multi-vehicle datasets (e.g., CAN-T&T is “Partial”). A short note on how an author could construct a vehicle-identity partition from each public dataset would improve actionability of the checklist in IX-A.
  2. [Table IV] Table IV and Fig. 1 summarize defence coverage as Partial/Minimal; a column with example citations (already present in the prose) would make the table self-contained.
  3. [Throughout] Minor consistency: “V ANET” / “VANET”, “misbehaviour” / “misbehavior”, and “FedAvg” vs “FedAvg [5]” appear in mixed forms; normalize spelling and first-use expansions.
  4. [V-D] Section V-D: “Scryptographic masking” appears to be a typo for “cryptographic masking” (or a garbled reference to secure aggregation).
  5. [II-A / header] The search window extends to February 2026 and the venue header is CYBER-AI 2026; ensure arXiv/venue metadata and the stated window remain consistent at camera-ready time.

Circularity Check

0 steps flagged

No significant circularity: the SoK audits external literature against an explicit coding schema and does not derive its pitfall conclusions from self-fitted parameters or load-bearing self-citations.

full rationale

This paper is a Systematization of Knowledge, not a first-principles derivation or parameter-fitting study. Its load-bearing claims (recurring IID splits, reliance on trivial Car-Hacking-style benchmarks, weak Byzantine evaluation, omitted CAN real-time latency checks, and only conditional support for privacy/accuracy/robustness claims) are established by coding an external corpus of 60+ papers against Table I, summarizing datasets in Table V, and assessing five literature claims in Section VIII with citations to independent work (e.g., gradient inversion [56], adaptive poisoning of robust aggregators [44], [54]). None of those assessments reduce by construction to quantities the authors themselves fitted, nor do they rest on a uniqueness theorem or ansatz imported from the authors’ prior papers. Self-citation is not used as the sole support for the central diagnosis; the Threats-to-Validity section (II-D) openly flags approximate corpus size and single-team coding bias without turning those limitations into circular premises. The minimum benchmarking checklist in Section IX is a normative proposal, not a prediction forced by earlier fits. Therefore the derivation chain is self-contained against external literature and exhibits no circular steps of the enumerated kinds.

Axiom & Free-Parameter Ledger

0 free parameters · 3 axioms · 2 invented entities

As a literature SoK the paper rests almost entirely on standard domain facts (CAN lacks authentication, FedAvg is the baseline aggregator, gradient inversion exists) and on the authors’ coding of the surveyed corpus. No free parameters are fitted; the only invented constructs are the unified taxonomy tables and the five-item minimum-benchmark checklist, both of which are definitional rather than ontological claims.

axioms (3)
  • domain assumption CAN bus provides no source authentication or encryption, so injection attacks are feasible once bus access is obtained.
    Stated as background in Section IV-A and used throughout the attack taxonomy; standard automotive-security fact.
  • ad hoc to paper The surveyed corpus of >60 papers is sufficiently representative that the observed frequency of IID splits, single-dataset evaluation, and missing Byzantine tests generalizes to the field.
    Invoked when the authors assert ‘pervasive’ pitfalls (Section VII-C); the threats-to-validity section itself notes the corpus is approximate and coding is single-team.
  • domain assumption FedAvg and its robust variants (Krum, trimmed mean, FLTrust) are the relevant aggregation baselines for vehicular FL-IDS.
    Used in Sections V-C and VI; drawn from the broader FL literature.
invented entities (2)
  • Unified three-layer attack taxonomy (intra-CAN, inter-V2X, FL-specific) no independent evidence
    purpose: Provide a common reference frame for the rest of the SoK and for future papers.
    Table II organizes previously scattered attack lists; it is a classification device, not a new physical or algorithmic object.
  • Five-item minimum benchmarking checklist for credible vehicular FL-IDS evaluation no independent evidence
    purpose: Define the bar the authors argue the community must meet before claiming real-world readiness.
    Section IX-A; the checklist is a normative proposal derived from the diagnosed pitfalls, not an empirical discovery.

pith-pipeline@v1.1.0-grok45 · 20307 in / 2646 out tokens · 26746 ms · 2026-07-14T08:19:37.584445+00:00 · methodology

0 comments
read the original abstract

Modern vehicular networks face an expanding attack surface across internal Electronic Control Units (ECUs) and external Vehicle-to-Everything (V2X) communication. Federated Learning (FL) has emerged as a decentralized paradigm to deploy Intrusion Detection Systems (IDS) without compromising data privacy. However, the vehicular FL-IDS literature suffers from fragmented methodologies and unrealistic experimental setups. This paper presents a Systematization of Knowledge (SoK) that unifies the taxonomy of vehicular attack surfaces, evaluates FL topologies, and maps adversarial threats such as poisoning and inference attacks. By auditing over 60 publications, we identify recurring pitfalls: artificial IID data splits, reliance on trivial benchmarks, weak adversarial evaluation, and omission of real-time CAN constraints. Finally, we define a forward-looking research agenda and outline minimum benchmarking requirements necessary to transition vehicular FL-IDS from optimistic simulations to secure, real-world deployment.

Figures

Figures reproduced from arXiv: 2607.10914 by Kaiwen Zhang, Reza Nourmohammadi, Sara Rouhani, Yahya Shahsavari.

Figure 1
Figure 1. Figure 1: Threat coverage in vehicular FL-IDS rules that weight updates by data volume or participant count are acutely vulnerable. Trust management systems based on reputation scores or PKI-anchored certificates [57] partially mitigate this threat but introduce reliance on a trusted author￾ity, which may itself be attacked or unavailable. G. Summary: Defence Coverage Table IV summarises defensive mechanisms against… view at source ↗
Figure 2
Figure 2. Figure 2: Dataset realism and FL suitability in vehicular IDS evaluation [PITH_FULL_IMAGE:figures/full_fig_p008_2.png] view at source ↗

discussion (0)

Sign in with ORCID, Apple, or X to comment. Anyone can read and Pith papers without signing in.

Reference graph

Works this paper leans on

64 extracted references · 7 linked inside Pith

  1. [1]

    Ai-based intrusion detection systems for in-vehicle networks: A survey,

    S. Rajapaksha, H. Kalutarage, M. O. Al-Kadri, A. Petrovski, G. Madzudzo, and M. Cheah, “Ai-based intrusion detection systems for in-vehicle networks: A survey,”ACM Computing Surveys, vol. 55, no. 11, pp. 1–40, 2023

  2. [2]

    Securing vehicle- to-everything (v2x) communication platforms,

    M. Hasan, S. Mohan, T. Shimizu, and H. Lu, “Securing vehicle- to-everything (v2x) communication platforms,”IEEE Transactions on Intelligent Vehicles, vol. 5, no. 4, pp. 693–713, 2020

  3. [3]

    Selecting optimal features for cross-fleet analysis and fault diagnosis of industrial gas turbines,

    Y . Zhang, M. Mart ´ınez-Garc´ıa, and A. Latimer, “Selecting optimal features for cross-fleet analysis and fault diagnosis of industrial gas turbines,” inTurbo Expo: Power for Land, Sea, and Air, vol. 51128. American Society of Mechanical Engineers, 2018, p. V006T05A005

  4. [4]

    Federated learning for intrusion detection systems in internet of vehicles: A general taxonomy, applications, and future directions,

    J. Alsamiri and K. Alsubhi, “Federated learning for intrusion detection systems in internet of vehicles: A general taxonomy, applications, and future directions,”Future Internet, vol. 15, no. 12, p. 403, 2023

  5. [5]

    Communication-efficient learning of deep networks from decentralized data,

    B. McMahan, E. Moore, D. Ramage, S. Hampson, and B. A. y Arcas, “Communication-efficient learning of deep networks from decentralized data,” inArtificial intelligence and statistics. Pmlr, 2017, pp. 1273– 1282

  6. [6]

    The prisma 2020 statement: an updated guideline for reporting systematic reviews,

    M. J. Page, J. E. McKenzie, P. M. Bossuyt, I. Boutron, T. C. Hoffmann, C. D. Mulrow, L. Shamseer, J. M. Tetzlaff, E. A. Akl, S. E. Brennan et al., “The prisma 2020 statement: an updated guideline for reporting systematic reviews,”bmj, vol. 372, 2021

  7. [7]

    Federated learning for intrusion detection system: Concepts, challenges and future directions,

    S. Agrawal, S. Sarkar, O. Aouedi, G. Yenduri, K. Piamrat, M. Alazab, S. Bhattacharya, P. K. R. Maddikunta, and T. R. Gadekallu, “Federated learning for intrusion detection system: Concepts, challenges and future directions,”Computer Communications, vol. 195, pp. 346–361, 2022

  8. [8]

    A review of federated learning applications in intrusion detection systems,

    A. Belenguer, J. A. Pascual, and J. Navaridas, “A review of federated learning applications in intrusion detection systems,”Computer Net- works, vol. 258, p. 111023, 2025

  9. [9]

    A survey of deep learning-based intrusion detection in automotive applications,

    B. Lampe and W. Meng, “A survey of deep learning-based intrusion detection in automotive applications,”Expert Systems with Applications, vol. 221, p. 119771, 2023

  10. [10]

    State-of-the-art survey on in-vehicle network communication (can-bus) security and vulnerabilities,

    O. Avatefipour and H. Malik, “State-of-the-art survey on in-vehicle network communication (can-bus) security and vulnerabilities,”arXiv preprint arXiv:1802.01725, 2018

  11. [11]

    Cyberattacks and coun- termeasures for in-vehicle networks,

    E. Aliwa, O. Rana, C. Perera, and P. Burnap, “Cyberattacks and coun- termeasures for in-vehicle networks,”ACM computing surveys (CSUR), vol. 54, no. 1, pp. 1–37, 2021

  12. [12]

    A survey of intrusion detection for in-vehicle networks,

    W. Wu, R. Li, G. Xie, J. An, Y . Bai, J. Zhou, and K. Li, “A survey of intrusion detection for in-vehicle networks,”IEEE Transactions on Intelligent Transportation Systems, vol. 21, no. 3, pp. 919–933, 2019

  13. [13]

    A survey of anomaly detection in in-vehicle networks,

    ¨O. ¨Ozdemir, M. T. ˙Is ¸yapar, P. Karag¨oz, K. W. Schmidt, D. Demir, and N. A. Karag ¨oz, “A survey of anomaly detection in in-vehicle networks,” arXiv preprint arXiv:2409.07505, 2024

  14. [14]

    Simulation framework for misbehavior detection in vehicular net- works,

    J. Kamel, M. R. Ansari, J. Petit, A. Kaiser, I. B. Jemaa, and P. Urien, “Simulation framework for misbehavior detection in vehicular net- works,”IEEE transactions on vehicular technology, vol. 69, no. 6, pp. 6631–6643, 2020

  15. [15]

    Vehicular edge computing and networking: A survey,

    L. Liu, C. Chen, Q. Pei, S. Maharjan, and Y . Zhang, “Vehicular edge computing and networking: A survey,”Mobile networks and applica- tions, vol. 26, no. 3, pp. 1145–1168, 2021

  16. [16]

    Experimental security analysis of a modern automobile,

    K. Koscher, A. Czeskis, F. Roesner, S. Patel, T. Kohno, S. Checkoway, D. McCoy, B. Kantor, D. Anderson, H. Shachamet al., “Experimental security analysis of a modern automobile,” in2010 IEEE symposium on security and privacy. IEEE, 2010, pp. 447–462

  17. [17]

    A survey on can bus protocol: Attacks, challenges, and potential solutions,

    M. Bozdal, M. Samie, and I. Jennions, “A survey on can bus protocol: Attacks, challenges, and potential solutions,” in2018 International Conference on Computing, Electronics & Communications Engineering (iCCECE). IEEE, 2018, pp. 201–205

  18. [18]

    Remote exploitation of an unaltered passenger vehicle,

    C. Miller and C. Valasek, “Remote exploitation of an unaltered passenger vehicle,”Black Hat USA, vol. 2015, no. S 91, pp. 1–91, 2015

  19. [19]

    A comprehensive guide to can ids data and introduction of the road dataset,

    M. E. Verma, R. A. Bridges, M. D. Iannacone, S. C. Hollifield, P. Moriano, S. C. Hespeler, B. Kay, and F. L. Combs, “A comprehensive guide to can ids data and introduction of the road dataset,”PLoS one, vol. 19, no. 1, p. e0296879, 2024

  20. [20]

    Otids: A novel intrusion detection system for in-vehicle network by using remote frame,

    H. Lee, S. H. Jeong, and H. K. Kim, “Otids: A novel intrusion detection system for in-vehicle network by using remote frame,” in2017 15th Annual Conference on Privacy, Security and Trust (PST). IEEE, 2017, pp. 57–5709

  21. [21]

    Comprehensive experimental analyses of automotive attack surfaces,

    S. Checkoway, D. McCoy, B. Kantor, D. Anderson, H. Shacham, S. Sav- age, K. Koscher, A. Czeskis, F. Roesner, and T. Kohno, “Comprehensive experimental analyses of automotive attack surfaces,” in20th USENIX security symposium (USENIX Security 11), 2011

  22. [22]

    Spoofing attack using bus-off attacks against a specific ecu of the can bus,

    K. Iehira, H. Inoue, and K. Ishida, “Spoofing attack using bus-off attacks against a specific ecu of the can bus,” in2018 15th IEEE annual consumer communications & networking conference (CCNC). IEEE, 2018, pp. 1–4

  23. [23]

    A comprehensive survey of v2x cybersecurity mechanisms and future research paths,

    R. Sedar, C. Kalalas, F. V ´azquez-Gallego, L. Alonso, and J. Alonso- Zarate, “A comprehensive survey of v2x cybersecurity mechanisms and future research paths,”IEEE Open Journal of the Communications Society, vol. 4, pp. 325–391, 2023

  24. [24]

    Dedicated short-range communications (dsrc) standards in the united states,

    J. B. Kenney, “Dedicated short-range communications (dsrc) standards in the united states,”Proceedings of the IEEE, vol. 99, no. 7, pp. 1162– 1182, 2011

  25. [25]

    C-v2x security requirements and procedures: Survey and research directions,

    V . Marojevic, “C-v2x security requirements and procedures: Survey and research directions,”arXiv preprint arXiv:1807.09338, 2018

  26. [26]

    A survey and comparative analysis of methods for countering sybil attacks in vanets,

    G. Adele, A. Borah, A. Paranjothi, and M. S. Khan, “A survey and comparative analysis of methods for countering sybil attacks in vanets,” in2024 IEEE 14th Annual Computing and Communication Workshop and Conference (CCWC). IEEE, 2024, pp. 0178–0183

  27. [27]

    Detection and localization of sybil attack CYBER-AI 2026 10 in vanet: a review,

    K. Malathi and R. Manavalan, “Detection and localization of sybil attack CYBER-AI 2026 10 in vanet: a review,”Int J Res Appl Sci Eng Technol, vol. 2, pp. 282–293, 2014

  28. [28]

    A sensor fusion-based gnss spoofing attack detection framework for autonomous vehicles,

    S. Dasgupta, M. Rahman, M. Islam, and M. Chowdhury, “A sensor fusion-based gnss spoofing attack detection framework for autonomous vehicles,”IEEE Transactions on Intelligent Transportation Systems, vol. 23, no. 12, pp. 23 559–23 572, 2022

  29. [29]

    Cyber security challenges and solutions for v2x communications: A survey,

    A. Alnasser, H. Sun, and J. Jiang, “Cyber security challenges and solutions for v2x communications: A survey,”Computer Networks, vol. 151, pp. 52–67, 2019

  30. [30]

    Threats and defenses in the federated learning life cycle: A comprehensive survey and challenges,

    Y . Li, Z. Guo, N. Yang, H. Chen, D. Yuan, and W. Ding, “Threats and defenses in the federated learning life cycle: A comprehensive survey and challenges,”IEEE Transactions on Neural Networks and Learning Systems, 2025

  31. [31]

    Data poisoning attacks against federated learning systems,

    V . Tolpegin, S. Truex, M. E. Gursoy, and L. Liu, “Data poisoning attacks against federated learning systems,” inEuropean symposium on research in computer security. Springer, 2020, pp. 480–501

  32. [32]

    How to backdoor federated learning,

    E. Bagdasaryan, A. Veit, Y . Hua, D. Estrin, and V . Shmatikov, “How to backdoor federated learning,” inInternational conference on artificial intelligence and statistics. PMLR, 2020, pp. 2938–2948

  33. [33]

    Membership inference attacks against machine learning models via prediction sensitivity,

    L. Liu, Y . Wang, G. Liu, K. Peng, and C. Wang, “Membership inference attacks against machine learning models via prediction sensitivity,”IEEE Transactions on Dependable and Secure Computing, vol. 20, no. 3, pp. 2341–2347, 2022

  34. [34]

    Federated learning based ids ap- proach for the iov,

    A. Hbaieb, S. Ayed, and L. Chaari, “Federated learning based ids ap- proach for the iov,” inProceedings of the 17th international conference on availability, reliability and security, 2022, pp. 1–6

  35. [35]

    A federated learning framework for cyberattack detection in vehicular sensor networks,

    M. Driss, I. Almomani, Z. e Huma, and J. Ahmad, “A federated learning framework for cyberattack detection in vehicular sensor networks,” Complex & Intelligent Systems, vol. 8, no. 5, pp. 4221–4235, 2022

  36. [36]

    A robust multi-stage intrusion detection system for in-vehicle network security using hierarchical federated learning,

    M. Althunayyan, A. Javed, and O. Rana, “A robust multi-stage intrusion detection system for in-vehicle network security using hierarchical federated learning,”Vehicular Communications, vol. 49, p. 100837, 2024

  37. [37]

    A federated learning–enabled secure and scalable sdn framework for energy-efficient vanets,

    S. Sathishkumar, S. Keerthi, R. Devi Priya, and S. S, “A federated learning–enabled secure and scalable sdn framework for energy-efficient vanets,”International Journal of Communication Systems, vol. 39, no. 4, p. e70409, 2026

  38. [38]

    Mobility- aware cooperative caching in iovs based on secure asynchronous feder- ated and deep reinforcement learning,

    X. Nie, C. Wang, T. Zhou, Q. Zhou, X. Zhu, and J. Zhang, “Mobility- aware cooperative caching in iovs based on secure asynchronous feder- ated and deep reinforcement learning,”IEEE Internet of Things Journal, 2025

  39. [39]

    Lstm-based intrusion detection system for in-vehicle can bus commu- nications,

    M. D. Hossain, H. Inoue, H. Ochiai, D. Fall, and Y . Kadobayashi, “Lstm-based intrusion detection system for in-vehicle can bus commu- nications,”Ieee Access, vol. 8, pp. 185 489–185 502, 2020

  40. [40]

    Misbehavior detection with spatio-temporal graph neural networks,

    M. F. Yuce, M. A. Erturk, and M. A. Aydin, “Misbehavior detection with spatio-temporal graph neural networks,”Computers and Electrical Engineering, vol. 116, p. 109198, 2024

  41. [41]

    Spatiotemporal graph neural network-driven anomaly detection for cooperative vehicle messaging in dense vanet corridors,

    A. Z. Ibrahim, “Spatiotemporal graph neural network-driven anomaly detection for cooperative vehicle messaging in dense vanet corridors,” Transactions on Emerging Telecommunications Technologies, vol. 37, no. 4, p. e70405, 2026

  42. [42]

    Federated optimization in heterogeneous networks,

    T. Li, A. K. Sahu, M. Zaheer, M. Sanjabi, A. Talwalkar, and V . Smith, “Federated optimization in heterogeneous networks,”Proceedings of Machine learning and systems, vol. 2, pp. 429–450, 2020

  43. [43]

    Ma- chine learning with adversaries: Byzantine tolerant gradient descent,

    P. Blanchard, E. M. El Mhamdi, R. Guerraoui, and J. Stainer, “Ma- chine learning with adversaries: Byzantine tolerant gradient descent,” Advances in neural information processing systems, vol. 30, 2017

  44. [44]

    Local model poisoning attacks to{Byzantine-Robust}federated learning,

    M. Fang, X. Cao, J. Jia, and N. Gong, “Local model poisoning attacks to{Byzantine-Robust}federated learning,” in29th USENIX security symposium (USENIX Security 20), 2020, pp. 1605–1622

  45. [45]

    Fltrust: Byzantine- robust federated learning via trust bootstrapping,

    X. Cao, M. Fang, J. Liu, and N. Z. Gong, “Fltrust: Byzantine- robust federated learning via trust bootstrapping,”arXiv preprint arXiv:2012.13995, 2020

  46. [46]

    Federated learning with personalization layers,

    M. G. Arivazhagan, V . Aggarwal, A. K. Singh, and S. Choud- hary, “Federated learning with personalization layers,”arXiv preprint arXiv:1912.00818, 2019

  47. [47]

    Personalized federated learning with moreau envelopes,

    C. T Dinh, N. Tran, and J. Nguyen, “Personalized federated learning with moreau envelopes,”Advances in neural information processing systems, vol. 33, pp. 21 394–21 405, 2020

  48. [48]

    Threats to federated learning: A survey,

    L. Lyu, H. Yu, and Q. Yang, “Threats to federated learning: A survey,” arXiv preprint arXiv:2003.02133, 2020

  49. [49]

    Deep learning with differential privacy,

    M. Abadi, A. Chu, I. Goodfellow, H. B. McMahan, I. Mironov, K. Talwar, and L. Zhang, “Deep learning with differential privacy,” in Proceedings of the 2016 ACM SIGSAC conference on computer and communications security, 2016, pp. 308–318

  50. [50]

    Practical secure aggregation for privacy-preserving machine learning,

    K. Bonawitz, V . Ivanov, B. Kreuter, A. Marcedone, H. B. McMahan, S. Patel, D. Ramage, A. Segal, and K. Seth, “Practical secure aggregation for privacy-preserving machine learning,” inproceedings of the 2017 ACM SIGSAC Conference on Computer and Communications Security, 2017, pp. 1175–1191

  51. [51]

    Privacy-preserving deep learning via additively homomorphic encryption,

    Y . Aono, T. Hayashi, L. Wang, S. Moriaiet al., “Privacy-preserving deep learning via additively homomorphic encryption,”IEEE transactions on information forensics and security, vol. 13, no. 5, pp. 1333–1345, 2017

  52. [52]

    Privacy-preserving byzantine-robust federated learning via deep reinforcement learning in vehicular networks,

    Y . Pan, Z. Su, Y . Wang, J. Zhou, and M. Mahmoud, “Privacy-preserving byzantine-robust federated learning via deep reinforcement learning in vehicular networks,”IEEE Transactions on Vehicular Technology, 2025

  53. [53]

    Enhancing machine learning-based ids for vehicular networks by addressing ad- versarial attacks,

    P. Mansourian, N. Zhang, A. Jaekel, and T. Allsopp, “Enhancing machine learning-based ids for vehicular networks by addressing ad- versarial attacks,”IEEE Transactions on Vehicular Technology, 2025

  54. [54]

    A comprehensive analysis of model poisoning attacks in federated learning for autonomous vehicles: A benchmark study,

    S. Almutairi and A. Barnawi, “A comprehensive analysis of model poisoning attacks in federated learning for autonomous vehicles: A benchmark study,”Results in Engineering, vol. 24, p. 103295, 2024

  55. [55]

    Targeted attacks and defenses for distributed federated learning in vehicular networks,

    U. Demir, T. Erpek, Y . E. Sagduyu, S. Kompella, and M. Xue, “Targeted attacks and defenses for distributed federated learning in vehicular networks,” inMILCOM 2025-2025 IEEE Military Communications Conference (MILCOM). IEEE, 2025, pp. 962–967

  56. [56]

    Inverting gradients-how easy is it to break privacy in federated learning?

    J. Geiping, H. Bauermeister, H. Dr ¨oge, and M. Moeller, “Inverting gradients-how easy is it to break privacy in federated learning?”Ad- vances in neural information processing systems, vol. 33, pp. 16 937– 16 947, 2020

  57. [57]

    A lightweight authentication and privacy-preserving aggregation for blockchain- enabled federated learning in vanets,

    P. Liu, Q. He, Y . Chen, S. Jiang, B. Zhao, and X. Wang, “A lightweight authentication and privacy-preserving aggregation for blockchain- enabled federated learning in vanets,”IEEE Transactions on Consumer Electronics, vol. 71, no. 1, pp. 1274–1287, 2024

  58. [58]

    In-vehicle network intrusion detection using deep convolutional neural network,

    H. M. Song, J. Woo, and H. K. Kim, “In-vehicle network intrusion detection using deep convolutional neural network,”Vehicular Commu- nications, vol. 21, p. 100198, 2020

  59. [59]

    Can-mirgu: a comprehensive can bus attack dataset from moving vehicles for intrusion detection system evaluation

    M. AL-KADRI, “Can-mirgu: a comprehensive can bus attack dataset from moving vehicles for intrusion detection system evaluation.” 2024

  60. [60]

    Road: The real ornl automotive dynamometer con- troller area network intrusion detection dataset (with a comprehensive can ids dataset survey & guide),

    M. E. Verma, M. D. Iannacone, R. A. Bridges, S. C. Hollifield, B. Kay, and F. L. Combs, “Road: The real ornl automotive dynamometer con- troller area network intrusion detection dataset (with a comprehensive can ids dataset survey & guide),”arXiv preprint arXiv:2012.14600, 2020

  61. [61]

    Canet: An unsupervised intrusion detection system for high dimensional can bus data,

    M. Hanselmann, T. Strauss, K. Dormann, and H. Ulmer, “Canet: An unsupervised intrusion detection system for high dimensional can bus data,”Ieee Access, vol. 8, pp. 58 194–58 205, 2020

  62. [62]

    Can-train-and-test: A curated can dataset for automotive intrusion detection,

    B. Lampe and W. Meng, “Can-train-and-test: A curated can dataset for automotive intrusion detection,”Computers & Security, vol. 140, p. 103777, 2024

  63. [63]

    Semi- supervised federated learning for misbehavior detection of bsms in ve- hicular networks,

    J. Huang, Y . Jiang, S. Gyawali, Z. Zhou, and F. Zhong, “Semi- supervised federated learning for misbehavior detection of bsms in ve- hicular networks,” in2024 IEEE 100th Vehicular Technology Conference (VTC2024-Fall). IEEE, 2024, pp. 1–6

  64. [64]

    Microscopic traffic simulation using sumo,

    P. A. Lopez, M. Behrisch, L. Bieker-Walz, J. Erdmann, Y .-P. Fl ¨otter¨od, R. Hilbrich, L. L ¨ucken, J. Rummel, P. Wagner, and E. Wießner, “Microscopic traffic simulation using sumo,” in2018 21st international conference on intelligent transportation systems (ITSC). Ieee, 2018, pp. 2575–2582