AI-Enabled Hardware-in-the-Loop Validation for Automotive Cybersecurity: A Review of Cyber Threats, Testbeds, and Intelligent Detection
Abstract
1. Introduction
Review Methodology and Scope
2. Contemporary Automotive Architectures and Cyber Threats
2.1. Evolution of Automotive E/E Architectures
2.2. Types of Cyber Threats Targeting Automotive Systems
2.2.1. In-Network Attacks
- Controller Area Network: Classical CAN, CAN FD, and CAN XL
- Masquerading attack: The attackers can gain access to CAN frames due to the lack of encryption and message authentication, making it easier for them to infiltrate the network. The adversary first suppresses a legitimate message and then injects counterfeit frames that mimic its behavior, using the same transmission intervals, message format, and payload value ranges [29].
- Eavesdropping attack: The attackers can eavesdrop on broadcasted vehicular CAN messages, potentially allowing them to infiltrate in-vehicle networks.
- Injection attack: The attackers may attempt to inject false signals into the vehicle’s bus system. Using on-board diagnostics (OBD) ports, they can establish connections with the in-vehicle system, potentially compromising the ECUs.
- Replay attack: The attackers can disrupt the vehicle’s real-time operation by continuously retransmitting legitimate frames. Mitigating replay attacks is a challenging task because network entities often cannot determine whether they are under attack [30].
- Bus-off attack: The attacker may continuously send data bits not only in the identification field but also in other fields.
- DoS attack: The attacker may disrupt the normal processing of in-vehicle communication by continuously sending high-priority CAN packets, which can block valid packets with low-priority and potentially gain control of the vehicle [31].
- Local Interconnect Network (LIN) bus
- FlexRay
- Media-Oriented Systems Transport (MOST)
- Automotive Ethernet (AE)
- AUTOSAR, Service-Oriented Communication, and Security Gateways
2.2.2. External Network Attacks
2.2.3. Physical-Layer Attacks
2.2.4. Remote Attacks
2.2.5. Cloud, Backend, API, and Connected-Service Attacks
2.2.6. Firmware, OTA, and Software-Supply-Chain Attacks
2.2.7. Sensor Spoofing and Perception Attacks
2.3. Automotive Cybersecurity Standards and Regulatory Context
3. Cybersecurity-Oriented HIL/VIL and Digital-Twin Validation
3.1. HIL and VIL for Automotive Cybersecurity Testing
3.2. Cyberattack Injection and Cyber–Physical Data Acquisition
3.3. HIL/VIL-Generated Data for AI-Based Detection
3.4. Digital Twins as a Bridge Between HIL and AI
4. AI-Powered Cyber Threat Detection and Mitigation
4.1. Foundational Machine Learning Approaches
4.2. Deep Learning for Complex Pattern Recognition
4.3. Emerging AI Architectures and Deployment Considerations
4.4. Automotive Cybersecurity Datasets and Benchmarking
4.5. Cyber–Physical Behavior Modeling and HIL-Based Detection
4.6. Adversarial Robustness of AI-Based Automotive Intrusion Detection
5. Integrated AI–HIL Framework for Automotive Cybersecurity Evaluation
6. Conclusions and Future Perspectives
Author Contributions
Funding
Institutional Review Board Statement
Informed Consent Statement
Data Availability Statement
Conflicts of Interest
Abbreviations
| ABS | Anti-lock Braking System |
| ADAS | Advanced Driver-Assistance Systems |
| AE | Automotive Ethernet |
| AI | Artificial Intelligence |
| CAN | Controller Area Network |
| CNN | Convolutional Neural Network |
| DL | Deep Learning |
| DoS | Denial of Service |
| DSRC | Dedicated Short-Range Communications |
| ECU | Electronic Control Unit |
| GNSS | Global Navigation Satellite System |
| GPS | Global Positioning System |
| GRU | Gated Recurrent Unit |
| HIL | Hardware-in-the-Loop |
| IDS | Intrusion Detection System |
| IVN | In-Vehicle Network |
| LIN | Local Interconnect Network |
| LSTM | Long Short-Term Memory |
| ML | Machine Learning |
| MOST | Media-Oriented Systems Transport |
| OBD-II | On-Board Diagnostics II |
| OTA | Over-the-Air |
| TCN | Temporal Convolutional Network |
| V2X | Vehicle-to-Everything |
| VIL | Vehicle-in-the-Loop |
| AUTOSAR | AUTomotive Open System ARchitecture |
| BSW | Basic Software |
| RTE | Runtime Environment |
| SOME/IP | Scalable service-Oriented MiddlewarE over IP |
| CSMS | Cyber Security Management System |
| SUMS | Software Update Management System |
| EMC | Electromagnetic Compatibility |
References
- Potteiger, B.; Emfinger, W.; Neema, H.; Koutsoukos, X.; Tang, C.; Stouffer, K. Evaluating the Effects of Cyber-Attacks on Cyber Physical Systems Using a Hardware-in-the-Loop Simulation Testbed. In Proceedings of the 2017 Resilience Week (RWS); IEEE: New York, NY, USA, 2017; pp. 177–183. [Google Scholar] [CrossRef] [Scilit]
- Ravi, A.; Shah, C.V. Innovations in Electronic Control Units: Enhancing Performance and Reliability with AI (Revision-1). Int. J. Eng. Comput. Sci. 2024, 13, 26033–26050. [Google Scholar] [CrossRef] [Scilit]
- Hafeez, A.; Mohan, J.; Girdhar, M.; Awad, S. Machine Learning Based ECU Detection for Automotive Security. In Proceedings of the 17th International Computer Engineering Conference (ICENCO), Cairo, Egypt, 29–30 December 2021; IEEE: New York, NY, USA, 2021; pp. 73–81. [Google Scholar] [CrossRef] [Scilit]
- Gupta, M.; Benson, J.; Patwa, F.; Sandhu, R. Secure V2V and V2I Communication in Intelligent Transportation Using Cloudlets. IEEE Trans. Serv. Comput. 2022, 15, 1912–1925. [Google Scholar] [CrossRef] [Scilit]
- Tesla. Support. Available online: https://www.tesla.com/support/connectivity (accessed on 23 June 2022).
- Hussain, R.; Zeadally, S. Autonomous cars: Research results, issues, and future challenges. IEEE Commun. Surv. Tutor. 2019, 21, 1275–1313. [Google Scholar] [CrossRef] [Scilit]
- Miller, C.; Valasek, C. Adventures in Automotive Networks and Control Units. In Proceedings of the DEF CON 21, Las Vegas, NV, USA, 1–4 August 2013; pp. 15–31. [Google Scholar]
- Miller, C.; Valasek, C. Remote Exploitation of an Unaltered Passenger Vehicle. In Proceedings of the Black Hat USA; Black Hat: Las Vegas, NV, USA, 2015. [Google Scholar]
- Hariharan, S.; Papadopoulos, A.V.; Nolte, T. On in-vehicle network security testing methodologies in construction machinery. In Proceedings of the IEEE 27th International Conference on Emerging Technologies and Factory Automation (ETFA); IEEE: New York, NY, USA, 2022; pp. 1–4. [Google Scholar]
- Luo, F.; Zhang, X.; Yang, Z.; Jiang, Y.; Wang, J.; Wu, M.; Feng, W. Cybersecurity Testing for Automotive Domain: A Survey. Sensors 2022, 22, 9211. [Google Scholar] [CrossRef] [Scilit] [PubMed]
- Santa Barletta, V.; Caivano, D.; Catalano, C.; De Vincentiis, M.; Scalera, M. Automotive Intelligence for Supporting Vehicle-SOC Analysts. Comput. Stand. Interfaces 2026, 96, 104088. [Google Scholar] [CrossRef] [Scilit]
- Abboush, M.; Knieke, C.; Rausch, A. A virtual testing framework for real-time validation of automotive software systems based on hardware in the loop and fault injection. Sensors 2024, 24, 3733. [Google Scholar] [CrossRef] [Scilit] [PubMed]
- Vu, L.; Nguyen, T.-L.; Abdelrahman, M.S.; Vu, T.; Mohammed, O.A. A Cyber-HIL for Investigating Control Systems in Ship Cyber-Physical Systems under Communication Issues and Cyber Attacks. IEEE Trans. Ind. Appl. 2024, 60, 2142–2152. [Google Scholar] [CrossRef] [Scilit]
- VicOne. Shifting Gears: VicOne 2025 Automotive Cybersecurity Report. 2025. Available online: https://vicone.com/reports/2025-automotive-cybersecurity-report/ (accessed on 10 September 2026).
- Grady, H.; Nauman, N.; Miah, M.S. Data-Driven Hardware-in-the-Loop Plant Modeling for Self-Driving Vehicles. In Proceedings of the 2022 IEEE International Symposium on Robotic and Sensors Environments (ROSE), Abu Dhabi, United Arab Emirates, 14–15 November 2022; pp. 1–8. [Google Scholar] [CrossRef] [Scilit]
- Ogunmolu, O.; Gu, X.; Jiang, S.; Gans, N. Nonlinear Systems Identification Using Deep Dynamic Neural Networks. arXiv 2016, arXiv:1610.01439. [Google Scholar] [CrossRef] [Scilit]
- Abreu, R.; Simão, E.; Serôdio, C.; Branco, F.; Valente, A. Enhancing IoT Security in Vehicles: A Comprehensive Review of AI-Driven Solutions for Cyber-Threat Detection. AI 2024, 5, 2279–2299. [Google Scholar] [CrossRef] [Scilit]
- Wang, W.; Guo, K.; Cao, W.; Zhu, H.; Nan, J.; Yu, L. Review of Electrical and Electronic Architectures for Autonomous Vehicles: Topologies, Networking and Simulators. Automot. Innov. 2024, 7, 82–101. [Google Scholar] [CrossRef] [Scilit]
- Plappert, C.; Zelle, D.; Gadacz, H.; Rieke, R.; Scheuermann, D.; Krauß, C. Attack Surface Assessment for Cybersecurity Engineering in the Automotive Domain. In Proceedings of the 2021 29th Euromicro International Conference on Parallel, Distributed and Network-Based Processing (PDP), Valladolid, Spain, 10–12 March 2021; pp. 266–275. [Google Scholar] [CrossRef] [Scilit]
- Pekaric, I.; Sauerwein, C.; Haselwanter, S.; Felderer, M. A Taxonomy of Attack Mechanisms in the Automotive Domain. Comput. Stand. Interfaces 2021, 78, 103539. [Google Scholar] [CrossRef] [Scilit]
- Keen Security Lab of Tencent. Car Hacking Research: Remote Attack Tesla Motors. 19 September 2016. Available online: https://keenlab.tencent.com/en/2016/09/19/Keen-Security-Lab-of-Tencent-Car-Hacking-Research-Remote-Attack-to-Tesla-Cars/ (accessed on 10 September 2026).
- Tencent Keen Security Lab. Experimental Security Assessment of BMW Cars. Tencent Keen Security Lab, 2018. Available online: https://keenlab.tencent.com/en/2018/05/22/New-CarHacking-Research-by-KeenLab-Experimental-Security-Assessment-of-BMW-Cars/ (accessed on 10 September 2026).
- Childs, D. Pwn2Own Automotive 2024—Day Two Results. Zero Day Initiative, 24 January 2024. Available online: https://www.zerodayinitiative.com/blog/2024/1/24/pwn2own-automotive-2024-day-two-results (accessed on 10 September 2026).
- Koscher, K.; Czeskis, A.; Roesner, F.; Patel, S.; Kohno, T.; Checkoway, S.; McCoy, D.; Kantor, B.; Anderson, D.; Shacham, H.; et al. Experimental Security Analysis of a Modern Automobile. In Proceedings of the IEEE Symposium on Security and Privacy (SP); IEEE: New York, NY, USA, 2010; pp. 447–462. [Google Scholar] [CrossRef] [Scilit]
- Huang, J.; Zhao, M.; Zhou, Y.; Xing, C.-C. In-Vehicle Networking: Protocols, Challenges, and Solutions. IEEE Netw. 2019, 33, 92–98. [Google Scholar] [CrossRef] [Scilit]
- ISO 11898-1:2024; Road Vehicles—Controller Area Network (CAN)—Part 1: Data Link Layer and Physical Coding Sublayer. ISO: Geneva, Switzerland, 2024. Available online: https://www.iso.org/standard/86384.html (accessed on 10 September 2026).
- Sun, X.; Yu, F.R.; Zhang, P. A survey on cyber-security of connected and autonomous vehicles (CAVs). IEEE Trans. Intell. Transp. Syst. 2022, 23, 6240–6259. [Google Scholar] [CrossRef] [Scilit]
- Liu, J.; Zhang, S.; Sun, W.; Shi, Y. In-vehicle network attacks and countermeasures: Challenges and future directions. IEEE Netw. 2017, 31, 50–58. [Google Scholar] [CrossRef] [Scilit]
- Iehira, K.; Inoue, H.; Ishida, K. Spoofing attack using bus-off attacks against a specific ECU of the CAN bus. In Proceedings of the 15th IEEE Annual Consumer Communications and Networking Conference (CCNC); IEEE: New York, NY, USA, 2018; pp. 1–4. [Google Scholar]
- Ahmad, J.; Zia, M.U.; Naqvi, I.H.; Chattha, J.N.; Butt, F.A.; Huang, T.; Xiang, W. Machine learning and blockchain technologies for cybersecurity in connected vehicles. Wiley Interdiscip. Rev. Data Min. Knowl. Discov. 2024, 14, e1515. [Google Scholar] [CrossRef] [Scilit]
- Derhab, A.; Belaoued, M.; Mohiuddin, I.; Kurniawan, F.; Khan, M.K. Histogram-based intrusion detection and filtering framework for secure and safe in-vehicle networks. IEEE Trans. Intell. Transp. Syst. 2022, 23, 2366–2379. [Google Scholar] [CrossRef] [Scilit]
- Ruff, M. Evolution of local interconnect network (LIN) solutions. In Proceedings of the 2003 Fall IEEE Vehicular Technology Conference (VTC 2003-Fall) (IEEE Cat. No. 03CH37484), Orlando, FL, USA, 6–9 October 2003; pp. 3382–3389. [Google Scholar]
- Refat, R.U.D.; Elkhail, A.A.; Malik, H. Machine Learning for Automotive Cybersecurity: Challenges, Opportunities and Future Directions. In AI-Enabled Technologies for Autonomous and Connected Vehicles; Springer: Cham, Switzerland, 2022; pp. 547–567. [Google Scholar] [CrossRef] [Scilit]
- Shaw, R.; Jackman, B. An introduction to FlexRay as an industrial network. In Proceedings of the 2008 IEEE International Symposium on Industrial Electronics, Cambridge, UK; IEEE: New York, NY, USA, 2008; pp. 1849–1854. [Google Scholar]
- Han, G.; Zeng, H.; Li, Y.; Dou, W. SAFE: Security-aware FlexRay scheduling engine. In Proceedings of the Design, Automation & Test in Europe Conference & Exhibition (DATE); IEEE: New York, NY, USA, 2014; pp. 1–4. [Google Scholar]
- Wolf, M.; Weimerskirch, A.; Paar, C. Security in Automotive Bus Systems. In Proceedings of the Embedded Security in Cars Workshop (ESCAR 2004), Bochum, Germany, 10–11 November 2004; pp. 1–13. [Google Scholar]
- De Vincenzi, M.; Costantino, G.; Matteucci, I.; Fenzl, F.; Plappert, C.; Rieke, R.; Zelle, D. A Systematic Review on Security Attacks and Countermeasures in Automotive Ethernet. ACM Comput. Surv. 2024, 56, 135. [Google Scholar] [CrossRef] [Scilit]
- AUTOSAR. AUTOSAR Classic Platform. Available online: https://www.autosar.org/standards/classic-platform (accessed on 10 September 2026).
- AUTOSAR. AUTOSAR Adaptive Platform. Available online: https://www.autosar.org/standards/adaptive-platform (accessed on 10 September 2026).
- AUTOSAR. SOME/IP Protocol Specification. AUTOSAR Foundation, Release R24-11, Document ID 696, 2024. Available online: https://www.autosar.org/fileadmin/standards/R24-11/FO/AUTOSAR_FO_PRS_SOMEIPProtocol.pdf (accessed on 10 September 2026).
- AUTOSAR. Requirements on Firewall. AUTOSAR Foundation, Release R22-11, Document ID 1062, 2022. Available online: https://www.autosar.org/fileadmin/standards/R22-11/FO/AUTOSAR_RS_Firewall.pdf (accessed on 10 September 2026).
- AUTOSAR. Specification of Intrusion Detection System Manager. AUTOSAR Classic Platform, Release R24-11, Document ID 977, 2024. Available online: https://www.autosar.org/fileadmin/standards/R24-11/CP/AUTOSAR_CP_SWS_IntrusionDetectionSystemManager.pdf (accessed on 10 September 2026).
- Guan, T.; Han, Y.; Kang, N.; Tang, N.; Chen, X.; Wang, S. An Overview of Vehicular Cybersecurity for Intelligent Connected Vehicles. Sustainability 2022, 14, 5211. [Google Scholar] [CrossRef] [Scilit]
- Kukkala, V.K.; Thiruloga, S.V.; Pasricha, S. Roadmap for cybersecurity in autonomous vehicles. IEEE Consum. Electron. Mag. 2022, 11, 13–23. [Google Scholar] [CrossRef] [Scilit]
- Appathurai, A.; Manogaran, G.; Chilamkurti, N. Trusted FPGA-Based Transport Traffic Inject, Impersonate (I2) Attacks Beaconing in the Internet of Vehicles. IET Netw. 2019, 8, 169–178. [Google Scholar] [CrossRef] [Scilit]
- Khan, J. Vehicle network security testing. In Proceedings of the 2017 Third International Conference on Sensing, Signal Processing and Security (ICSSS); IEEE: New York, NY, USA, 2017; pp. 119–123. [Google Scholar]
- Kumar, S.; Mann, K.S. Prevention of DoS attacks by detection of multiple malicious nodes in VANETs. In Proceedings of the International Conference on Automation, Computing Technology and Management (ICACTM); IEEE: New York, NY, USA, 2019; pp. 89–94. [Google Scholar]
- Mondal, A.; Jana, M. Detection of Fabrication, Replay and Suppression Attack in VANET—A Database Approach. In Proceedings of the Conference on Advancement in Computation, Communication and Electronics Paradigm (ACCEP-2019), Howrah, India, 18 January 2019; pp. 38–42. [Google Scholar]
- Federal Communications Commission. Use of the 5.850–5.925 GHz Band: Second Report and Order. FCC 24-123, ET Docket No. 19-138; Adopted 20 November 2024; Released 21 November 2024. Available online: https://docs.fcc.gov/public/attachments/FCC-24-123A1.pdf (accessed on 10 September 2026).
- Federal Communications Commission. Wireless Telecommunications Bureau and Public Safety and Homeland Security Bureau Provide Guidance for Intelligent Transportation System Licensees to Transition from DSRC to C-V2X Operations in the 5.895–5.925 GHz Band. DA 25-125, ET Docket No. 19-138; Released 11 February 2025. Available online: https://docs.fcc.gov/public/attachments/DA-25-125A1.pdf (accessed on 10 September 2026).
- 3rd Generation Partnership Project (3GPP). Overall Description of Radio Access Network (RAN) Aspects for Vehicle-to-Everything (V2X) Based on LTE and NR. 3GPP Technical Report TR 37.985. Available online: https://portal.3gpp.org/desktopmodules/Specifications/SpecificationDetails.aspx?specificationId=3601 (accessed on 10 September 2026).
- Checkoway, S.; McCoy, D.; Kantor, B.; Anderson, D.; Shacham, H.; Savage, S.; Koscher, K.; Czeskis, A.; Roesner, F.; Kohno, T.; et al. Comprehensive experimental analyses of automotive attack surfaces. In Proceedings of the USENIX Security Symposium; The USENIX Association: Berkeley, CA, USA, 2011; pp. 77–92. [Google Scholar]
- Rouf, I.; Miller, R.; Mustafa, H.; Taylor, T.; Oh, S.; Xu, W.; Gruteser, M.; Trappe, W.; Seskar, I. Security and Privacy Vulnerabilities of In-Car Wireless Networks: A Tire Pressure Monitoring System Case Study. In Proceedings of the 19th USENIX Security Symposium, Washington, DC, USA; The USENIX Association: Berkeley, CA, USA, 2010. [Google Scholar]
- Yang, T.; Kong, L.; Xin, W.; Hu, J.; Chen, Z. Resisting Relay Attacks on Vehicular Passive Keyless Entry and Start Systems. In Proceedings of the 2012 9th International Conference on Fuzzy Systems and Knowledge Discovery, Chongqing, China; IEEE: New York, NY, USA, 2012. [Google Scholar]
- Alipour, H.; Al-Nashif, Y.B.; Satam, P.; Hariri, S. Wireless anomaly detection based on IEEE 802.11 behavior analysis. IEEE Trans. Inf. Forensics Secur. 2015, 10, 2158–2170. [Google Scholar] [CrossRef] [Scilit]
- Satam, P.; Hariri, S. WIDS: An anomaly based intrusion detection system for Wi-Fi (IEEE 802.11) protocol. IEEE Trans. Netw. Serv. Manag. 2021, 18, 1077–1091. [Google Scholar] [CrossRef] [Scilit]
- Satam, P. Anomaly based Wi-Fi intrusion detection system. In Proceedings of the 2017 IEEE 2nd International Workshops on Foundations and Applications of Self* Systems (FAS*W); IEEE: New York, NY, USA, 2017; pp. 377–378. [Google Scholar]
- Satam, P.; Satam, S.; Hariri, S. Bluetooth intrusion detection system (BIDS). In Proceedings of the IEEE/ACS 15th International Conference on Computer Systems and Applications (AICCSA); IEEE: New York, NY, USA, 2018; pp. 1–7. [Google Scholar]
- Satam, S.; Satam, P.; Hariri, S. Multi-level Bluetooth intrusion detection system. In Proceedings of the IEEE/ACS 17th International Conference on Computer Systems and Applications; IEEE: New York, NY, USA, 2020; pp. 1–8. [Google Scholar]
- Curry, S.; Rivera, N.; Rhinehart, J.; Carroll, I.; Lugo, K. Hacking Kia: Remotely Controlling Cars with Just a License Plate. 20 September 2024. Available online: https://samcurry.net/hacking-kia (accessed on 10 September 2026).
- Halder, S.; Ghosal, A.; Conti, M. Secure over-the-air software updates in connected vehicles: A survey. Comput. Netw. 2020, 178, 107343. [Google Scholar] [CrossRef] [Scilit]
- National Highway Traffic Safety Administration. Cybersecurity Best Practices for the Safety of Modern Vehicles; Release 2022; U.S. Department of Transportation: Washington, DC, USA, 2022. Available online: https://www.nhtsa.gov/sites/nhtsa.gov/files/2022-09/cybersecurity-best-practices-safety-modern-vehicles-2022-tag.pdf (accessed on 10 September 2026).
- Yan, C.; Xu, W.; Liu, J. Can You Trust Autonomous Vehicles: Contactless Attacks against Sensors of Self-Driving Vehicle. Def Con 2016, 24, 109. [Google Scholar] [CrossRef] [PubMed]
- Islam, T.; Sheakh, M.A.; Jui, A.N.; Sharif, O.; Hasan, M.Z. A review of cyber attacks on sensors and perception systems in autonomous vehicle. J. Econ. Technol. 2023, 1, 242–258. [Google Scholar] [CrossRef] [Scilit]
- Humphreys, T. Statement on the Vulnerability of Civil Unmanned Aerial Vehicles and Other Systems to Civil GPS Spoofing; University of Texas at Austin: Austin, TX, USA, 2012; pp. 1–16. [Google Scholar]
- Abrar, M.M.; Youssef, A.; Islam, R.; Satam, S.; Latibari, B.S.; Hariri, S.; Shao, S.; Salehi, S.; Satam, P. GPS-IDS: An anomaly-based GPS spoofing attack detection framework for autonomous vehicles. arXiv 2024, arXiv:2405.08359. [Google Scholar]
- Shoukry, Y.; Martin, P.; Tabuada, P.; Srivastava, M. Non-invasive spoofing attacks for anti-lock braking systems. In Proceedings of the Cryptographic Hardware and Embedded Systems: 15th International Workshop, Santa Barbara, CA, USA; Springer: Berlin/Heidelberg, Germany, 2013; pp. 55–72. [Google Scholar]
- Eykholt, K.; Evtimov, I.; Fernandes, E.; Li, B.; Rahmati, A.; Xiao, C.; Prakash, A.; Kohno, T.; Song, D. Robust Physical-World Attacks on Deep Learning Visual Classification. In Proceedings of the 2018 IEEE/CVF Conference on Computer Vision and Pattern Recognition (CVPR), Salt Lake City, UT, USA, 18–23 June 2018; pp. 1625–1634. [Google Scholar] [CrossRef] [Scilit]
- Cui, Y.; Liu, J.; Zhang, X.; Lin, J.; Guo, J. A Survey on Cybersecurity in Vehicular Networks: Attacks, Solutions and Future Directions. Electronics 2019, 8, 727. [Google Scholar] [CrossRef] [Scilit]
- Kim, K.; Kim, S.; Kim, T. Cybersecurity for Autonomous Vehicles: Review of Attacks, Defense Technologies, and Challenges. Comput. Secur. 2021, 103, 102150. [Google Scholar] [CrossRef] [Scilit]
- Luo, F.; Wang, J.; Zhang, X.; Jiang, Y.; Li, Z.; Luo, C. In-vehicle network intrusion detection systems: A systematic survey of deep learning-based approaches. PeerJ Comput. Sci. 2023, 9, e1648. [Google Scholar] [CrossRef] [Scilit] [PubMed]
- ISO/SAE 21434:2021; Road Vehicles—Cybersecurity Engineering. ISO: Geneva, Switzerland, 2021. Available online: https://www.iso.org/standard/70918.html (accessed on 10 September 2026).
- United Nations Economic Commission for Europe. UN Regulation No. 155—Cyber Security and Cyber Security Management System; UNECE: Geneva, Switzerland, 2021; Available online: https://unece.org/transport/documents/2021/03/standards/un-regulation-no-155-cyber-security-and-cyber-security (accessed on 10 September 2026).
- United Nations Economic Commission for Europe. UN Regulation No. 156—Software Update and Software Update Management System; UNECE: Geneva, Switzerland, 2021; Available online: https://unece.org/transport/documents/2021/03/standards/un-regulation-no-156-software-update-and-software-update (accessed on 10 September 2026).
- Weaver, A.; von Jouanne, A.; Sicker, D.; Yokochi, A. Cybersecurity Dynamometer Testbed: A Review to Advance Vehicle-in-the-Loop Testing of Traditional, Connected and Autonomous Vehicles. IEEE Open J. Veh. Technol. 2025, 6, 2925–2943. [Google Scholar] [CrossRef] [Scilit]
- Oruganti, P.S.; Appel, M.; Ahmed, Q. Hardware-in-loop based automotive embedded systems cybersecurity evaluation testbed. In Proceedings of the ACM Workshop on Automotive Cybersecurity (AutoSec); ACM: New York, NY, USA, 2019; pp. 41–44. [Google Scholar] [CrossRef] [Scilit]
- Kang, B.; Jeon, S. A Vehicle-in-the-Loop Simulation-Based Framework for Automotive Cybersecurity Evaluation. IEEE Access 2025, 13, 179622–179638. [Google Scholar] [CrossRef] [Scilit]
- Mihalič, F.; Truntič, M.; Hren, A. Hardware-in-the-loop simulations: A historical overview of engineering challenges. Electronics 2022, 11, 2462. [Google Scholar] [CrossRef] [Scilit]
- Abboush, M.; Knieke, C.; Rausch, A. Hardware-in-the-loop-based real-time fault injection framework for an ECU prototype with a dynamic vehicle model. Sensors 2022, 22, 1360. [Google Scholar] [CrossRef] [Scilit] [PubMed]
- King, P.J.; Copp, D.G. Hardware in the Loop for Automotive Vehicle Control Systems Development and Testing. Meas. Control 2006, 39, 19–23. [Google Scholar] [CrossRef] [Scilit]
- ISO 16750-3:2023; Road Vehicles—Environmental Conditions and Testing for Electrical and Electronic Equipment—Part 3: Mechanical Loads. ISO: Geneva, Switzerland, 2023. Available online: https://www.iso.org/standard/77579.html (accessed on 10 September 2026).
- ISO 16750-4:2023; Road Vehicles—Environmental Conditions and Testing for Electrical and Electronic Equipment—Part 4: Climatic Loads. ISO: Geneva, Switzerland, 2023. Available online: https://www.iso.org/standard/77580.html (accessed on 10 September 2026).
- ISO 11452-1:2025; Road Vehicles—Component Test Methods for Electrical Disturbances from Narrowband Radiated Electromagnetic Energy—Part 1: General Principles and Terminology. ISO: Geneva, Switzerland, 2025. Available online: https://www.iso.org/standard/83225.html (accessed on 10 September 2026).
- Stabili, D.; Valgimigli, F.; Torrini, E.; Marchetti, M. HackCar: A Test Platform for Attacks and Defenses on a Cost-Contained Automotive Architecture. In Proceedings of the 2024 IEEE Intelligent Vehicles Symposium; IEEE: New York, NY, USA, 2024; pp. 1099–1105. [Google Scholar] [CrossRef] [Scilit]
- Fowler, D.S.; Cheah, M.; Shaikh, S.A.; Bryans, J. Towards a Testbed for Automotive Cybersecurity. In Proceedings of the 2017 IEEE International Conference on Software Testing, Verification and Validation (ICST); IEEE: New York, NY, USA, 2017; pp. 540–541. [Google Scholar]
- Toyama, T.; Yoshida, T.; Oguma, H.; Matsumoto, T. PASTA: Portable Automotive Security Testbed with Adaptability. In Proceedings of Black Hat Europe, London, UK; Black Hat: London, UK, 2018. [Google Scholar]
- Folan, S.; Wang, Y. Cybersecurity Simulator for Connected and Autonomous Vehicles. In Proceedings of the 24th ACM International Symposium on Theory, Algorithmic Foundations, and Protocol Design for Mobile Networks and Mobile Computing (MobiHoc 2023); ACM: New York, NY, USA, 2023; pp. 430–435. [Google Scholar]
- Abboush, M.; Bamal, D.; Knieke, C.; Rausch, A. Intelligent fault detection and classification based on hybrid deep learning methods for hardware-in-the-loop test of automotive software systems. Sensors 2022, 22, 4066. [Google Scholar] [CrossRef] [Scilit] [PubMed]
- Malhotra, P.; Vig, L.; Shroff, G.; Agarwal, P. Long short term memory networks for anomaly detection in time series. In Proceedings of the 23rd European Symposium on Artificial Neural Networks, Computational Intelligence and Machine Learning (ESANN), Bruges, Belgium; i6doc: Louvain-la-Neuve, Belgium, 2015; pp. 89–94. [Google Scholar]
- Desta, A.K.; Ohira, S.; Arai, I.; Fujikawa, K. ID sequence analysis for intrusion detection in the CAN bus using long short term memory networks. In Proceedings of the IEEE International Conference on Pervasive Computing and Communications Workshops (PerCom Workshops); IEEE: New York, NY, USA, 2020; pp. 1–6. [Google Scholar]
- VanDerHorn, E.; Mahadevan, S. Digital Twin: Generalization, Characterization and Implementation. Decis. Support Syst. 2021, 145, 113524. [Google Scholar] [CrossRef] [Scilit]
- Kabir, M.R.; Ray, S. ViSE: Digital Twin Exploration for Automotive Functional Safety and Cybersecurity. J. Hardw. Syst. Secur. 2024, 8, 133–144. [Google Scholar] [CrossRef] [Scilit]
- Sharmin, S.; Mansor, H.; Abdul Kadir, A.F.; Ismail, A.R. Digital Twin-Based Evaluation of Vehicular Controller Area Network Intrusion Detection Systems. Int. J. Perceptive Cogn. Comput. 2025, 11, 67–80. [Google Scholar] [CrossRef] [Scilit]
- Yigit, Y.; Panitsas, I.; Maglaras, L.; Tassiulas, L.; Canberk, B. Cyber-Twin: Digital Twin-Boosted Autonomous Attack Detection for Vehicular Ad-Hoc Networks. In Proceedings of the 2024 IEEE International Conference on Communications (ICC), Denver, CO, USA, 9–13 June 2024; pp. 2167–2172. [Google Scholar] [CrossRef] [Scilit]
- Wang, Y.; Qin, G.; Sun, M.; Liang, Y.; Yang, X.; Li, M.; Hu, C. An Intrusion Detection System for Internet of Vehicles Based on Digital Twin. J. Supercomput. 2025, 81, 1562. [Google Scholar] [CrossRef] [Scilit]
- Shah, U.M.; Minhas, D.M.; Kifayat, K.; Shah, K.A.; Frey, G. Threat Modeling and Attacks on Digital Twins of Vehicles: A Systematic Literature Review. Smart Cities 2025, 8, 142. [Google Scholar] [CrossRef] [Scilit]
- Bulusu, R. Systemization of Knowledge: Resilience and Fault Tolerance in Cyber-Physical Systems. arXiv 2025, arXiv:2512.20873. [Google Scholar] [CrossRef] [Scilit]
- Olufowobi, H.; Young, C.; Zambreno, J.; Bloom, G. SAIDuCANT: Specification-based automotive intrusion detection using controller area network (CAN) timing. IEEE Trans. Veh. Technol. 2020, 69, 1484–1494. [Google Scholar] [CrossRef]
- Girdhar, M.; Hong, J.; Yoo, Y.; Song, T.-J. Machine learning-enabled cyber attack prediction and mitigation for EV charging stations. In Proceedings of the IEEE Power and Energy Society General Meeting (PESGM); IEEE: New York, NY, USA, 2022; pp. 1–5. [Google Scholar]
- Thiruloga, S.V.; Kukkala, V.K.; Pasricha, S. TENET: Temporal CNN with attention for anomaly detection in automotive cyber-physical systems. In Proceedings of the 2022 27th Asia and South Pacific Design Automation Conference (ASP-DAC); IEEE: New York, NY, USA, 2022; pp. 326–331. [Google Scholar]
- Saravanan, R.; Balaji, S.; Ganesan, M.; Braveen, M.; Srinivasa Perumal, R. Optimal Attention Deep Learning-Based In-Vehicle Intrusion Detection and Classification Model on CAN Messages. Sci. Rep. 2025, 15, 33952. [Google Scholar] [CrossRef] [Scilit] [PubMed]
- Li, C.; Khandelwal, S.; Shanker, S. FAV-NSS: An HIL Framework for Accelerating Validation of Automotive Network Security Strategies. In Proceedings of the 2025 IEEE 36th International Conference on Application-Specific Systems, Architectures and Processors (ASAP); IEEE: New York, NY, USA, 2025; pp. 25–32. [Google Scholar] [CrossRef] [Scilit]
- Feng, H.; Sun, M.; Wang, Y. MambaCNN: A Lightweight Intrusion Detection System Based on Mamba for the Internet of Vehicles. Cybersecurity 2026, 9, 64. [Google Scholar] [CrossRef] [Scilit]
- Song, J.; Qin, G.; Liang, Y.; Yan, J.; Sun, M. DGIDS: Dynamic Graph-Based Intrusion Detection System for CAN. Comput. Secur. 2024, 147, 104076. [Google Scholar] [CrossRef] [Scilit]
- Gao, F.; Liu, J.; Li, C.; Gao, Z.; Zhao, R. Signal-Relationship-Aware Explainable Intrusion Detection in Controller Area Networks Using Graph Transformers. Knowl.-Based Syst. 2025, 328, 114237. [Google Scholar] [CrossRef] [Scilit]
- Wang, X.; Xu, Y.; Xu, Y.; Wang, Z.; Wu, Y. Intrusion Detection System for In-Vehicle CAN-FD Bus ID Based on GAN Model. IEEE Access 2024, 12, 82402–82412. [Google Scholar] [CrossRef] [Scilit]
- Rangsikunpum, A.; Amiri, S.; Ost, L. BIDS: An Efficient Intrusion Detection System for In-Vehicle Networks Using a Two-Stage Binarised Neural Network on Low-Cost FPGA. J. Syst. Archit. 2024, 156, 103285. [Google Scholar] [CrossRef] [Scilit]
- Khandelwal, S.; Shanker, S. A Lightweight Multi-Attack CAN Intrusion Detection System on Hybrid FPGAs. In Proceedings of the 2022 32nd International Conference on Field-Programmable Logic and Applications (FPL), Belfast, UK, 29 August–2 September 2022; pp. 425–429. [Google Scholar] [CrossRef] [Scilit]
- Song, H.M.; Woo, J.; Kim, H.K. In-Vehicle Network Intrusion Detection Using Deep Convolutional Neural Network. Veh. Commun. 2020, 21, 100198. [Google Scholar] [CrossRef] [Scilit]
- Verma, M.E.; Bridges, R.A.; Iannacone, M.D.; Hollifield, S.C.; Moriano, P.; Hespeler, S.C.; Kay, B.; Combs, F.L. A Comprehensive Guide to CAN IDS Data and Introduction of the ROAD Dataset. PLoS ONE 2024, 19, e0296879. [Google Scholar] [CrossRef] [Scilit] [PubMed]
- Kordi, F.; Fortier, P.; Miled, A. FPGA-Based AI-Driven Hardware-in-the-Loop Platform for Low-Latency Real-Time ABS ECU Testing. Electronics 2026, 15, 2443. [Google Scholar] [CrossRef] [Scilit]
- Kordi, F.; Fortier, P.; Miled, A. FPGA-Based Dual Learning Model for Wheel Speed Sensor Fault Detection in ABS Systems Using HIL Simulations. Electronics 2026, 15, 58. [Google Scholar] [CrossRef] [Scilit]
- Longari, S.; Noseda, F.; Carminati, M.; Zanero, S. Evaluating the Robustness of Automotive Intrusion Detection Systems Against Evasion Attacks. In Cyber Security, Cryptology, and Machine Learning; Springer: Cham, Switzerland, 2023; pp. 337–352. [Google Scholar] [CrossRef] [Scilit]
- Aloraini, F.; Javed, A.; Rana, O. Adversarial Attacks on Intrusion Detection Systems in In-Vehicle Networks of Connected and Autonomous Vehicles. Sensors 2024, 24, 3848. [Google Scholar] [CrossRef] [Scilit] [PubMed]
- Longari, S.; Cerracchio, P.; Carminati, M.; Zanero, S. Assessing the Resilience of Automotive Intrusion Detection Systems to Adversarial Manipulation. ACM Trans. Cyber-Phys. Syst. 2025, 9, 31. [Google Scholar] [CrossRef] [Scilit]
- Mamun, Q.; Hasan, M.M.; Ho, T.D.; Pan, Z.; Shimamoto, S. Adversarial Attacks on Machine Learning-Based IDS for V2X Networks: A CICIoV2024 Study. In Proceedings of the 2025 IEEE 101st Vehicular Technology Conference (VTC2025-Spring), Oslo, Norway, 17–20 June 2025. [Google Scholar] [CrossRef] [Scilit]
- Santa Barletta, V.; Caivano, D.; Catalano, C.; del Vescovo, S.; Piccinno, A. Adversarial Manipulation of CAN Bus IDS. Discov. Artif. Intell. 2026, 6, 545. [Google Scholar] [CrossRef] [Scilit]
- Pooranian, Z.; Taheri, R.; Martinelli, F. LFD-IDS: Bagging-Based Data Poisoning Attacks Against Cyberattack Detection in Connected Vehicle. IEEE Trans. Intell. Transp. Syst. 2025, 26, 16800–16810. [Google Scholar] [CrossRef] [Scilit]
- Lai, Y.; Wei, J.; Chen, Y. Gradient Correlation Based Detection of Adversarial Attacks on Vehicular Networks. Comput. Netw. 2024, 255, 110868. [Google Scholar] [CrossRef] [Scilit]
- Lin, Y.-D.; Chan, W.-H.; Lai, Y.-C.; Yu, C.-M.; Wu, Y.-S.; Lee, W.-B. Enhancing CAN Security with ML-Based IDS: Strategies and Efficacies Against Adversarial Attacks. Comput. Secur. 2025, 151, 104322. [Google Scholar] [CrossRef] [Scilit]
- He, C.; Xu, X.; Jiang, H.; Jiang, J.; Chen, T. Cyber-attack detection for lateral control system of cloud-based intelligent connected vehicle based on BiLSTM-Attention network. Measurement 2025, 247, 116740. [Google Scholar] [CrossRef] [Scilit]



| Year | Company/System | Reported Incident |
|---|---|---|
| 2018 | Volkswagen | Remote code execution was reported in the infotainment system of the Golf GTE. |
| 2018 | Honda | An improperly configured cloud server exposed the personal information of more than 50,000 users. |
| 2019 | Mercedes-Benz | An onboard application was compromised and reportedly enabled the theft of more than 100 vehicles. |
| 2019 | Toyota | Four security vulnerabilities were reported in the navigation system of the 2017 NX300 model. |
| 2020 | Mercedes-Benz | A total of 9765 vehicles were recalled because of software problems affecting the communication module. |
| 2020 | Volkswagen | An attacker reportedly obtained a vehicle key by exploiting the digital-signature transponder. |
| 2021 | QNX operating system | Security researchers disclosed multiple vulnerabilities affecting the automotive QNX operating system. |
| 2022 | Honda | A weakness in the rolling-code mechanism enabled replay of a previously transmitted keyless-entry command. |
| 2023 | Toyota | A cloud misconfiguration allowed unauthorized access to databases managed by Toyota Connected Corporation. |
| 2023 | Tesla | At Pwn2Own Vancouver, researchers demonstrated remote code execution in the in-vehicle infotainment system and transmitted CAN messages affecting other ECUs. |
| 2024 | Tesla | At Pwn2Own Automotive, the Synacktiv team successfully used a two-bug exploit chain against the Tesla infotainment system [23]. |
| 2024 | Kia | A vulnerability in remote services allowed misuse of cloud APIs to perform vehicle operations such as locking, unlocking, and starting, potentially affecting more than one million vehicles. |
| Year | Ref. | Attack Classification | Defense Classification | Main Contribution |
|---|---|---|---|---|
| 2019 | [69] | Availability, confidentiality, and data integrity | Not reported | Classified automotive attacks and the corresponding defense techniques. |
| 2021 | [70] | Autonomous control systems, driving components, and V2X communication | Security architecture, intrusion detection, and anomaly detection | Provided a systematic analysis of attack and defense strategies for autonomous vehicles. |
| 2023 | [64] | Sensor and perception attacks, safety violations, and attacker capabilities | Not reported | Reviewed vulnerabilities affecting sensors and perception systems in autonomous vehicles. |
| 2023 | [71] | In-vehicle network, remote, and firmware attacks | Lightweight IDS models and AI-based anomaly detection | Reviewed in-vehicle network security challenges from a protocol-oriented perspective. |
| 2026 | [11] | Vehicle-SOC threat models and data-driven cyberattack patterns | SOC analytics and AI-supported detection workflows | Proposed an automotive intelligence framework to support vehicle-SOC analysts. |
| Year | Ref. | Test Platform | Testbed or Framework |
|---|---|---|---|
| 2017 | [85] | Software simulator | Testbed for Automotive Cybersecurity. |
| 2018 | [86] | Portable hardware/software testbed | Portable Automotive Security Testbed with Adaptability (PASTA). |
| 2019 | [76] | HIL testbed | Hardware-in-the-Loop-Based Automotive Embedded Systems Cybersecurity Evaluation Testbed. |
| 2023 | [87] | Software simulator | Cybersecurity Simulator for Connected and Autonomous Vehicles. |
| 2024 | [84] | Hybrid test platform | HackCar: A Test Platform for Attacks and Defenses on a Cost-Contained Automotive Architecture. |
| 2024 | [12] | HIL and fault-injection framework | Virtual Testing Framework for Real-Time Validation of Automotive Software Systems Based on HIL and Fault Injection. |
| 2025 | [75] | Vehicle-in-the-loop/HIL testbed | Cybersecurity Dynamometer Testbed for Vehicle-in-the-Loop Evaluation. |
| Year | Ref. | Test Platform | Attack/Anomaly | AI-Based Method and Purpose | Study/Framework |
|---|---|---|---|---|---|
| 2022 | [88] | Automotive HIL test bench | Injected sensor and actuator faults | Hybrid CNN–LSTM for detection and classification of abnormal behavior from HIL-generated traces | Intelligent fault detection and classification for HIL-based automotive software testing. |
| 2024 | [66] | AV testbed and simulation | GNSS/GPS spoofing | Vehicle-behavior modeling and ML using temporal features for spoofing detection | GPS-IDS: anomaly-based GPS spoofing detection for autonomous vehicles. |
| 2025 | [102] | FPGA-based HIL framework | Automotive network attacks | Real-time HIL acceleration and evaluation of IDS/IPS security strategies | FAV-NSS: HIL framework for validating automotive network-security strategies. |
| 2025 | [121] | Simulation and semi-physical HIL platform | False-data-injection attacks on the lateral control system | BiLSTM–Attention-based detection using physically guided vehicle, steering-system, and actuator features | Cyber-attack detection for the lateral control system of a cloud-based intelligent connected vehicle. |
| Architecture/ Attack Surface | Representative Threats | HIL/VIL Representation | Observable Signals/ Data | AI-Based Detection Approach | Evaluation Criteria/ Representative Sources |
|---|---|---|---|---|---|
| CAN/CAN FD/CAN XL | Injection, replay, masquerading, DoS, bus-off | Real or emulated CAN interfaces connected to ECUs or networked controllers; controlled message injection and traffic manipulation | CAN identifiers, payloads, timing, message frequency, ECU inputs/outputs | Sequence modeling, timing-based IDS, supervised or attention-based classification | Detection rate, false alarms, latency, attack classification; [90,98,101,102] |
| Automotive Ethernet/ gateways/ zonal networks | Spoofing, DoS, manipulated service traffic, cross-domain propagation, gateway compromise | Switched Ethernet links, gateway or zonal-controller models, heterogeneous CAN–Ethernet communication, service-oriented traffic | Packet/service traffic, communication timing, gateway events, ECU/network states | Traffic anomaly detection, supervised classification, temporal or service-behavior modeling | Cross-domain detection, gateway response, latency, propagation containment; [19,37,42] |
| V2X/C-V2X connectivity | Spoofing, replay, impersonation, message manipulation, DoS | Emulated or controlled V2X communication interfaces integrated with vehicle or VIL scenarios | V2X messages, timing, positioning data, vehicle state, communication events | Anomaly detection, temporal behavior modeling, position-consistency analysis | Detection accuracy, false alarms, robustness to mobility and operating conditions; [49,66,77] |
| Cloud/backend/ API/telematics | Unauthorized commands, authentication or authorization weaknesses, backend compromise, malicious cloud-to-vehicle requests | Emulated backend or telematics interfaces and controlled external commands connected to vehicle gateways or ECUs | API requests, telematics messages, ECU responses, network traffic, vehicle/control states | Behavioral anomaly detection and cross-layer correlation of off-board and in-vehicle events | Unauthorized-command detection, propagation to vehicle functions, response latency; [14,60] |
| OTA/firmware/ software supply chain | Malicious firmware, rollback, compromised update servers, unauthorized software modification | Controlled update process, firmware/version manipulation, emulated update infrastructure, ECU reflashing | Firmware version, update messages, authentication results, ECU state, network and control responses | Integrity/anomaly monitoring and behavioral detection of abnormal post-update operation | Update integrity, rollback prevention, successful containment and cyber–physical impact; [10,61,62] |
| Sensors/ perception/ cyber–physical interfaces | GNSS spoofing, sensor manipulation, falsified wheel-speed or control-relevant measurements | HIL/VIL sensor substitution or perturbation while maintaining closed-loop vehicle dynamics | Sensor measurements, actuator commands, controller states, vehicle-dynamic variables | CNN–LSTM, temporal anomaly detection, vehicle-behavior modeling | Detection accuracy, false alarms, detection latency, robustness across operating conditions; [66,88] |
Disclaimer/Publisher’s Note: The statements, opinions and data contained in all publications are solely those of the individual author(s) and contributor(s) and not of MDPI and/or the editor(s). MDPI and/or the editor(s) disclaim responsibility for any injury to people or property resulting from any ideas, methods, instructions or products referred to in the content. |
© 2026 by the authors. Licensee MDPI, Basel, Switzerland. This article is an open access article distributed under the terms and conditions of the Creative Commons Attribution (CC BY) license.
Share and Cite
Kordi, F.; Fortier, P.; Miled, A. AI-Enabled Hardware-in-the-Loop Validation for Automotive Cybersecurity: A Review of Cyber Threats, Testbeds, and Intelligent Detection. Sensors 2026, 26, 5840. https://doi.org/10.3390/s26185840
Kordi F, Fortier P, Miled A. AI-Enabled Hardware-in-the-Loop Validation for Automotive Cybersecurity: A Review of Cyber Threats, Testbeds, and Intelligent Detection. Sensors. 2026; 26(18):5840. https://doi.org/10.3390/s26185840
Chicago/Turabian StyleKordi, Farshideh, Paul Fortier, and Amine Miled. 2026. "AI-Enabled Hardware-in-the-Loop Validation for Automotive Cybersecurity: A Review of Cyber Threats, Testbeds, and Intelligent Detection" Sensors 26, no. 18: 5840. https://doi.org/10.3390/s26185840
APA StyleKordi, F., Fortier, P., & Miled, A. (2026). AI-Enabled Hardware-in-the-Loop Validation for Automotive Cybersecurity: A Review of Cyber Threats, Testbeds, and Intelligent Detection. Sensors, 26(18), 5840. https://doi.org/10.3390/s26185840

