Yayın:
A smart intrusion detection systemagainst cyber attacks in unmanned aerial vehicles

Yükleniyor...
Küçük Resim

Kurum Yazarları

Bölüm / Program

Computer Engineering

Dergi Başlığı

Dergi ISSN

Cilt Başlığı

Yayıncı

Graduate School

Araştırma Projeleri

Akademik Birimler

Dergi Sayısı

Özet

Unmanned Aerial Vehicles (UAVs) have become integral to numerous civilian and military operations due to their versatility and ability to operate in challenging environments. However, their reliance on communication networks, sensors, and software makes them susceptible to cyber-attacks, which can compromise security, safety, and mission objectives. Among the most significant threats are jamming and Global Positioning System (GPS) spoofing attacks, which can disrupt communications and manipulate navigation, potentially leading to system failure or hijacking. Protecting these systems requires robust security measures, particularly Intrusion Detection Systems (IDS). Traditional IDS approaches for UAVs face several limitations. Many produce high false alarm rates, struggle with real-time detection, and cannot adapt quickly to evolving threats. Furthermore, UAVs have inherent constraints in power, computation, and storage, limiting the complexity of onboard security algorithms. A critical challenge is the scarcity of comprehensive datasets containing diverse attack scenarios, which is essential for training effective machine learning-based IDS. Training on imbalanced or incomplete data often leads to poor detection accuracy, especially for novel or rare attacks. This thesis addresses these challenges by proposing a novel, hybrid Intrusion Detection System (IDS) framework for UAV security. This framework innovatively integrates Generative Artificial Intelligence (GenAI) for attack simulation and Deep Reinforcement Learning (DRL) for adaptive, real-time defense. The primary goal is to enhance IDS robustness against GPS spoofing and jamming attacks by tackling data scarcity and improving adaptability under dynamic threat conditions. The first core component is a synthetic attack data generation module. This module utilizes a suite of advanced generative models: Variational Autoencoders (VAE), Gaussian Copula, Conditional Tabular Generative Adversarial Network (CTGAN), and Denoising Diffusion Probabilistic Model (DDPM). These models are employed to generate realistic and diverse GPS spoofing and jamming attack data based on real flight logs. This research systematically evaluates these models to determine their effectiveness in simulating attacks specific to UAV systems, a novel contribution compared to prior work focusing on single models or scenarios. The generated synthetic data, alongside real data, is used in two ways. Firstly, it facilitates a comprehensive evaluation of traditional machine learning-based IDS, specifically using XGBoost, to understand their performance against both known and GenAI-generated attacks. A multi-train cross-testing strategy is employed to assess the generalization capabilities of IDS trained on different combinations of real and synthetic data, revealing how synthetic data impacts performance under various conditions. Secondly, and crucially, the augmented data enriches the training environment for the DRL-based adaptive detection module. This module features a Deep Q-Network (DQN) agent designed for real-time threat mitigation. By modeling UAV mission execution as a Markov Decision Process (MDP), the DQN agent learns optimal defense policies through interaction with telemetry states, which include both real and synthetic attack indicators. This integration of GenAI-based data augmentation and DRL-based adaptive defense represents a significant advancement in UAV security. The DRL agent operates within a custom simulation environment. The state representation is multi-dimensional, capturing critical indicators such as GPS integrity, jamming and spoofing probabilities (derived from XGBoost outputs), motion dynamics, and battery level. The action space includes responses like alerting the Ground Control Station (GCS), switching to Inertial Measurement Unit (IMU) navigation, throttling communications, or initiating a Return-to-Home (RTH) procedure. The reward function is meticulously designed to encourage accurate attack identification, penalize false alarms, and promote energy-efficient decisions. To evaluate the quality of the generated synthetic data, we employ a multi-dimensional framework combining statistical similarity metrics (Kullback–Leibler Divergence, Wasserstein Distance, Kolmogorov-Smirnov Statistic) with IDS classification performance. This provides a comprehensive assessment of both the fidelity and the practical impact of the synthetic data. For the DRL module, evaluation focuses on Attack Detection Rate (ADR), False Alarm Rate (FAR), resource efficiency (battery consumption, action costs), and learning stability (reward convergence, RTH activity, mission completion rate). Our experimental results demonstrate the effectiveness of GenAI models, particularly DDPM and CTGAN, in generating high-fidelity synthetic attack data. These models produced data that closely matched the statistical properties of real attacks and proved most effective in challenging the XGBoost-based IDS, significantly degrading its performance compared to training on real data alone. This highlights both the potential of GenAI for IDS testing and the vulnerability of static IDSs to sophisticated, synthesized attacks. The DRL-based IDS exhibited strong learning capabilities and effective real-time defense. The DQN agent achieved a high Attack Detection Rate (ADR) of approximately 95\% during training, demonstrating its proficiency in identifying threats using learned patterns. It also learned to invoke safety protocols like RTH when necessary. However, the results also indicated a high False Alarm Rate (FAR), suggesting a tendency towards an aggressive defense policy that requires further tuning. Despite this, the agent showed good reward convergence and improved mission completion rates, indicating successful learning and a balance between security and operational continuity. The discussion of our findings emphasizes that the fidelity of generative models is directly correlated with their ability to effectively test and potentially evade IDS. DDPM emerged as the most potent model due to its ability to capture subtle anomalies in UAV data. We also address the practical deployability of the framework, noting that while GenAI training is computationally intensive, it is an offline process, and the deployed IDS (XGBoost or the DRL agent's underlying network) can be lightweight enough for resource-constrained UAVs. However, the study acknowledges several limitations. The synthetic data may not capture all real-world complexities, the evaluation relies on a single dataset, and the generative models can be computationally demanding and lack interpretability. Furthermore, the framework currently assumes static adversaries, whereas real-world attackers adapt. Ethical considerations surrounding the dual-use nature of attack generation tools are also discussed, highlighting the need for responsible development and deployment while underscoring the benefits of using synthetic data for privacy-preserving research. In conclusion, this thesis successfully demonstrates that GenAI models can create high-fidelity synthetic UAV attack data capable of challenging existing IDS. It introduces a hybrid framework combining GenAI and DRL to create a more robust, adaptive, and intelligent IDS for UAVs. The results confirm the potential of this approach to address data scarcity and improve detection capabilities against evolving cyber-physical threats. Future work will focus on integrating the framework into adaptive IDS architectures with closed-loop feedback, allowing generative models to be refined based on detection outcomes. We also aim to explore model compression techniques for lighter deployment, enhance model interpretability, and incorporate mechanisms for continuous learning against adapting adversaries. Validating the system through field deployments on live UAVs is a key priority to assess its effectiveness under real-world operational constraints. This research paves the way for more secure and resilient UAV operations by leveraging the power of GenAI and DRL.

Tanım

Thesis (Ph.D.) -- Istanbul Technical University, Graduate School, 2025

Dergi veya Seri

ISSN

ISBN

Haklar

Anahtar Kelimeler

unmanned aerial vehicles, insansız hava araçları, cyber attacks, siber saldırılar, cyber security, siber güvenlik

Alıntı

Onay

Gözden geçir

Tamamlayıcı Bilgiler

Referans Gösteren

Related Patent

Related Goal

11
Görüntülenme
139
İndirme
Google Scholar
Scholar'da Ara ↗
Bu yayında DOI yok — Altmetric/Dimensions/PlumX/BIP! rozetleri DOI gerektirir.