HybridDeep-Sybil: AI-Driven Sybil Attack Detection for Connected Vehicles
HybridDeep-Sybil combines CNN-based feature extraction and LSTM temporal modeling to detect Sybil attacks in V2X vehicular environments while considering both predictive performance and deployment efficiency.
BY MD WAHIDUR RAHMAN
Connected and autonomous vehicles increasingly rely on wireless communication to exchange information about position, speed, traffic conditions, and surrounding road events.
These Vehicle-to-Everything (V2X) communications can improve road safety and traffic efficiency, but they also introduce new cybersecurity risks.
Why Sybil Attacks Matter
A Sybil attack occurs when a malicious vehicle creates or impersonates multiple identities inside a vehicular network.
By pretending to be several different vehicles at the same time, an attacker may manipulate traffic information, create false congestion reports, or disrupt trust in cooperative driving systems.
The HybridDeep-Sybil Idea
Our recent work, HybridDeep-Sybil: A Hybrid CNN–LSTM Framework for Sybil Attack Detection in Automotive Consumer-Electronics Environments, explores how deep learning can identify deceptive vehicular behavior.
The framework combines:
- CNN layers for local feature extraction
- LSTM layers for temporal behavior modeling
- Dense classification layers for final Sybil detection
Vehicular Data Representation
Each input sample is represented as a 10 × 16 sequential feature window.
This allows the model to analyze multiple consecutive observations instead of treating each message independently.
Model Architecture
The final architecture includes:
- Two Conv1D layers with 64 filters
- Batch normalization
- LSTM with 64 units
- Dense layer with 32 neurons
- Dropout of 0.30
- Sigmoid output layer
The complete model contains approximately 51,137 trainable parameters.
Why Temporal Modeling Matters
A single message may appear normal.
However, when several messages are analyzed together, suspicious patterns such as coordinated identities, abnormal mobility, or implausible timing relationships may become visible.
This is why the CNN–LSTM combination is useful for vehicular cybersecurity.
Toward Safer Connected Vehicles
HybridDeep-Sybil is designed to support the development of secure and trustworthy V2X environments.
Future work can explore:
- Federated learning
- Continual learning
- Explainable AI
- Edge deployment
- Adaptive Sybil attacks
- Cross-scenario evaluation
The broader goal is to make connected and autonomous transportation systems more resilient to intelligent cyberattacks.