Ilmu Komputer & AI editorial
X-SPUR: Explainable Surprisal-Based Protocol-Aware Unsupervised Reasoning for Automotive Ethernet Intrusion Detection
The core problem
Modern in-vehicle networks built on Automotive Ethernet carry heterogeneous multi-protocol traffic, yet labeled attack data are rarely available for supervised training. Unsupervised intrusion detection is therefore essential, but the strongest prior detector, AERO, still depends on handcrafted traffic features. Such feature engineering is labor-intensive, protocol-specific, and may fail to generalize across protocol families.
X-SPUR addresses this gap by representing raw packet fields as token sequences and learning benign traffic patterns through causal language modeling. Anomalies are detected from per-token cross-entropy surprisal, eliminating handcrafted feature engineering entirely. The framework is designed to be explainable, protocol-aware, and unsupervised, supporting interpretable security analysis in heterogeneous in-vehicle networks.
Innovation
On the TOW-IDS dataset, X-SPUR achieves an AUC of 0.9987. This is marginally higher than the 0.9969 reported for AERO, the strongest prior unsupervised detector. More importantly, X-SPUR eliminates handcrafted feature engineering, which AERO relies on.
To assess generalization, the authors train a separate CarDS model using the same architecture and training hyperparameters. This model retains strong performance on the second automotive Ethernet dataset, indicating that the approach is not overfitted to a single dataset or protocol mix.
The results demonstrate that token-level surprisal from causal language modeling, combined with bimodal timing fusion and per-protocol calibration, can match or exceed feature-engineered baselines while providing greater interpretability.
Why it matters
Beyond detection performance, X-SPUR provides fine-grained explainability. Per-token surprisal attributes anomaly scores to specific protocol fields, enabling security analysts to understand which fields deviate from benign behavior. This is a significant advantage over black-box or feature-engineered detectors, especially in heterogeneous in-vehicle networks where protocol semantics vary.
The bimodal fusion of payload and timing captures both content-based and temporal anomalies, which is crucial for Automotive Ethernet where attacks may manifest in either dimension. The dual top-% per-protocol -score calibration addresses the challenge of heterogeneous score distributions across protocol families, jointly capturing moderately distributed and sparse anomaly signatures.
A limitation is that the approach requires training a separate model per dataset or protocol mix, as demonstrated by the CarDS model. Future work may explore transfer learning or domain adaptation to reduce retraining overhead. Nevertheless, X-SPUR represents a step toward explainable, protocol-aware, unsupervised intrusion detection for automotive Ethernet.
Who should read this
Opening member contentโฆ