MSc Thesis Defense: Adversarial Robustness Evaluation of Learning-Based V2X Misbehavior Detection Systems by Hashim Tayyab Shah

Friday, September 11, 2026 - 11:00

Adversarial Robustness Evaluation of Learning-Based V2X Misbehavior Detection Systems

MSc Thesis Defense by: Hashim Tayyab Shah

Date: 11 September 2026

Time:  11:00 AM

Location: Essex Hall 122

 

Abstract:

Machine-learning-based misbehavior detection systems (MDSs) for vehicular communication often achieve high detection performance against predefined attacks in benchmark datasets. However, such evaluations primarily measure performance under fixed attack distributions and provide limited insight into whether the same detectors remain effective when malicious messages are adaptively modified to evade detection. This thesis investigates the adversarial robustness of representative learning-based misbehavior detectors under multiple attacker capabilities. The study evaluates four detector configurations spanning classical machine learning, ensemble learning, and deep learning: a two-consecutive-BSM (2BSM) approach, its bagging-based variants, a CNN-LSTM reconstruction-based detector, and a CNN-LSTM-SVM hybrid detector. Their performance is first established under unperturbed conditions using VeReMi and VeReMi Extension dataset. Adversarial robustness is then evaluated using complementary attack strategies. For the vehicular setting, generated adversarial samples are processed according to defined spatial, kinematic, temporal, and cross-feature consistency constraints before evaluation. The results show that strong benchmark performance does not necessarily translate into adversarial robustness. Detectors achieving near-perfect accuracy under conventional testing can experience substantial evasion after adaptive modification. Robustness also varies considerably across position-falsification attacks, classifiers, detector configurations, and adversarial methods. Bagging does not consistently improve robustness, while the CNNLSTM-SVM configuration reduces gradient-based evasion for some attacks without eliminating vulnerability across all attack types. Across the evaluated settings, no single classifier or architectural choice provides uniform adversarial resilience. These findings demonstrate that conventional detection accuracy and adversarial robustness characterize different properties of a V2X misbehavior detector. The thesis therefore motivates adversarial robustness testing as a complementary component of the evaluation of learning-based V2X MDSs intended for deployment in adaptive and potentially adversarial vehicular environments.

 

Keywords: VANETs, V2V, Misbehavior Detection, Machine Learning, Deep Learning

Thesis Committee:
Internal Reader # 1: Dr. Jessica Chen
Internal Reader # 2: Dr. Boubakeur Boufama
Advisor: Dr. Ikjot Saini
Chair: Dr. Xiaobu Yuan

Vector Institute Logo