Pith. sign in

REVIEW 1 cited by

CAN-BERT do it? Controller Area Network Intrusion Detection System based on BERT Language Model

Not yet reviewed by Pith; the record is open.

This paper has not been read by Pith yet. Machine review is queued; the pith claim, tier, and objections will appear here once it completes.

SPECIMEN: schema-true, not a live event

T0 review · schema-true

One-sentence machine reading of the paper's core claim.

pith:XXXXXXXX · record.json · timestamp

arxiv 2210.09439 v1 pith:7GOVSS5K submitted 2022-10-17 cs.LG cs.CRcs.NI

classification cs.LGcs.CRcs.NI
keywords in-vehiclenetworkbertcan-bertdetectionlanguagemodelarea
verification ladder T0 review T1 audit T2 compute T3 formal
0 comments
read the original abstract

Due to the rising number of sophisticated customer functionalities, electronic control units (ECUs) are increasingly integrated into modern automotive systems. However, the high connectivity between the in-vehicle and the external networks paves the way for hackers who could exploit in-vehicle network protocols' vulnerabilities. Among these protocols, the Controller Area Network (CAN), known as the most widely used in-vehicle networking technology, lacks encryption and authentication mechanisms, making the communications delivered by distributed ECUs insecure. Inspired by the outstanding performance of bidirectional encoder representations from transformers (BERT) for improving many natural language processing tasks, we propose in this paper ``CAN-BERT", a deep learning based network intrusion detection system, to detect cyber attacks on CAN bus protocol. We show that the BERT model can learn the sequence of arbitration identifiers (IDs) in the CAN bus for anomaly detection using the ``masked language model" unsupervised training objective. The experimental results on the ``Car Hacking: Attack \& Defense Challenge 2020" dataset show that ``CAN-BERT" outperforms state-of-the-art approaches. In addition to being able to identify in-vehicle intrusions in real-time within 0.8 ms to 3 ms w.r.t CAN ID sequence length, it can also detect a wide variety of cyberattacks with an F1-score of between 0.81 and 0.99.

Discussion (0). Continue with ORCID to comment.

Forward citations

Cited by 1 Pith paper

Reviewed papers in the Pith corpus that reference this work. Sorted by Pith novelty score. Full citation record

  1. Good Enough to Learn: LLM-based Anomaly Detection in ECU Logs without Reliable Labels

    cs.LG 2025-07 conditional novelty 4.0 of 10

    A decoder-only LLM pre-trained on ECU log text and fine-tuned with an entropy regularizer detects cycle-time anomalies with 0.81 region recall despite noisy labels.

Pith tools