SoK: Federated Learning for Intrusion Detection in Vehicular Networks
Yahya Shahsavari, Reza Nourmohammadi, Sara Rouhani, Kaiwen Zhang
cs.CR
Submitted: 2026-07-12
License: http://creativecommons.org/licenses/by-nc-sa/4.0/
The gist: Modern vehicular networks face an expanding attack surface across internal Electronic Control Units (ECUs) and external Vehicle-to-Everything (V2X) communication.
Terminology
Abstract
Modern vehicular networks face an expanding attack surface across internal Electronic Control Units (ECUs) and external Vehicle-to-Everything (V2X) communication. Federated Learning (FL) has emerged as a decentralized paradigm to deploy Intrusion Detection Systems (IDS) without compromising data privacy. However, the vehicular FL-IDS literature suffers from fragmented methodologies and unrealistic experimental setups. This paper presents a Systematization of Knowledge (SoK) that unifies the taxonomy of vehicular attack surfaces, evaluates FL topologies, and maps adversarial threats such as poisoning and inference attacks. By auditing over 60 publications, we identify recurring pitfalls: artificial IID data splits, reliance on trivial benchmarks, weak adversarial evaluation, and omission of real-time CAN constraints. Finally, we define a forward-looking research agenda and outline minimum benchmarking requirements necessary to transition vehicular FL-IDS from optimistic simulations to secure, real-world deployment.
Sources
- State-of-the-Art Survey on In-Vehicle Network Communication (CAN-Bus) Security and Vulnerabilities
- A Survey of Anomaly Detection in In-Vehicle Networks
- C-V2X Security Requirements and Procedures: Survey and Research Directions
- FLTrust: Byzantine-robust Federated Learning via Trust Bootstrapping
- Federated Learning with Personalization Layers
- Threats to Federated Learning: A Survey
- A Comprehensive Guide to CAN IDS Data & Introduction of the ROAD Dataset
Related papers
- SoK: AI-Augmented Binary Reversing
- Relaxed Sender Anonymity for CBDC Interbank Settlement: A Zero-Knowledge Approach on Permissioned EVM
- Calibration-Family Overfit: Why Trusted Sabotage Monitors Don't Transfer Across Lineages
- Efficient Fuzzy PSI under One-Sided Assumptions
- Sealing the Audit-Runtime Gap for LLM Skills
- Token Composition: A Graph Based on EVM Logs