Wouter Hellemans

dblp:322/3720 · DBLP profile ↗
← Back
6ranked-venue papers
5as first author
6since 2021 · last 2025
0000-0003-2344-044XORCID · corroborated

Domains — the database's venue-derived domains; a paper can count in several

Security and privacy · 4 · 3 first-author · 4 since 2021Systems, architecture and hardware · 1 · 1 first-author · 1 since 2021Applied, interdisciplinary, general and emerging computing · 1 · 1 first-author · 1 since 2021
YearPublicationVenuePosition
2025 CarDS - Controller Area Network and Automotive Ethernet Realistic Data Set
abstract
Intrusion Detection Systems (IDSs) serve as a crucial defense mechanism against cyberattacks targeting the In-Vehicle Network (IVN) of modern, interconnected vehicles. To develop and test new IDS approaches, researchers require realistic IVN data featuring real attacks on moving vehicles. To this end, this paper presents Controller Area Network and Automotive Ethernet Realistic Data Set (CarDS), a novel dataset targeting both the Controller Area Network (CAN) and Automotive Ethernet (AE) traffic of a modern, multi-domain and multi-protocol IVN. Existing datasets are often simulated or limited to basic IVN architectures consisting of only a single CAN bus. Additionally, there are no realistic datasets for AE, despite its growing importance in high-speed in-vehicle communication. CarDS addresses these limitations by providing a labeled, time-synchronized dataset of CAN and AE traces that includes both comprehensive benign profiles and sophisticated attacks. Our traces are captured from an electric vehicle from 2020 featuring a domain-oriented architecture comprising 10 internal CAN buses and 6 AE buses. Specifically, our dataset covers 9h 07m 09s of real IVN data and features 397,383,125 CAN and 180,604,377 AE messages distributed over different scenarios in 258 traces.
Wouter Hellemans, Jannis Hamborg, Timm Lauser, Md Masoom Rabbani, Bart Preneel, Christoph Krauß, Nele Mentens
ACSAC1
2025 SPARK: Secure Privacy-Preserving Anonymous Swarm Attestation for In-Vehicle Networks
abstract
In recent years, vehicles have evolved into cyberphysical autonomous systems that rely on sensor data from various sources within the vehicle. With the emergence of Vehicle-to-Everything (V2X) technology, the scope of the collaborative functionality in vehicles is now expanding to the inter-vehicular level. To support these modern capabilities, the complexity of the Electronic Control Units (ECUs) and the In-Vehicle Network (IVN) architecture is rapidly increasing. As a result, IVNs are now swarms of devices that communicate safety-critical data. Unfortunately, current vehicular networks lack security, opening the path to numerous cyberattacks. A typical solution for verifying the integrity of multiple devices is swarm attestation. However, in a typical IVN setting, only the Original Equipment Manufacturer (OEM) has access to the legitimate configuration of the ECUs and does not want to disclose this information due to intellectual property and security concerns. Therefore, state- of-the-art swarm attestation schemes, which do not provide privacy guarantees, are unsuitable for IVNs.This paper proposes Secure Privacy Preserving Anonymous Swarm Attestation for In-Vehicle Networks (SPARK), which builds upon a novel group signature scheme to enable privacy-preserving, anonymous, and traceable swarm attestation of IVNs. We validate SPARK through a proof-of-concept implementation using a standardized hardware Trusted Platform Module (TPM 2.0) and representative hardware platforms. The results demonstrate the real-world applicability of SPARK.
Wouter Hellemans, Nada El Kassem, Md Masoom Rabbani, Edlira Dushku, Liqun Chen 0002, An Braeken, Bart Preneel, Nele Mentens
EuroS&P1
2025 PRIVÉ: Towards Privacy-Preserving Swarm Attestation
abstract
In modern large-scale systems comprising multiple heterogeneous devices, the introduction of swarm attestation schemes aims to alleviate the scalability and efficiency issues of traditional single-Prover and single-Verifier attestation. In this paper, we propose PRIVÉ, a privacy-preserving, scalable, and accountable swarm attestation scheme that addresses the limitations of existing solutions. Specifically, we eliminate the assumption of a trusted Verifier, which is not always applicable in real-world scenarios, as the need for the devices to share identifiable information with the Verifier may lead to the expansion of the attack landscape. To this end, we have designed an enhanced variant of the Direct Anonymous Attestation (DAA) protocol, offering traceability and linkability whenever needed. This enables PRIVÉ to achieve anonymous, privacy-preserving attestation while also providing the capability to trace a failed attestation back to the compromised device. To the best of our knowledge, this paper presents the first Universally Composable (UC) security model for swarm attestation accompanied by mathematical UC security proofs, as well as experimental benchmarking results that highlight the efficiency and scalability of the proposed scheme.
Nada El Kassem, Wouter Hellemans, Ioannis Siachos, Edlira Dushku, Stefanos Vasileiadis, Dimitrios S. Karas, Liqun Chen 0002, Constantinos Patsakis, Thanassis Giannetsos
SECRYPT2
2025 Toward a Real-Time Intrusion Detection System for Modern In-Vehicle Networks
abstract
Over the past decade, it has been demonstrated that the In-Vehicle Network (IVN) of a modern Intelligent Transportation System (ITS) is vulnerable to several cyberattacks. Given the collaborative nature of these systems, detecting (remote) cyberattacks is of utmost importance in ensuring trusted interactions. One key technique that has been explored to detect adversarial presence in IVNs are Intrusion Detection Systems (IDSs). However, many existing solutions focus on legacy architectures or are not practically feasible due to their hardware requirements or inability to operate in real-time. To this end, we propose Modular Reduced Temporal Convolutional Network (MR-TCN), an efficient IDS architecture that can effectively be accelerated on hardware to enable real-time intrusion detection in low-cost embedded platforms. Additionally, we evaluate variants of MR-TCN on a Field-Programmable Gate Array (FPGA) platform across a diverse range of IVN traffic (i.e., CAN CC, CAN FD, and Automotive Ethernet), demonstrating its suitability in real-world applications.
Wouter Hellemans, Laurens Le Jeune, Md Masoom Rabbani, Bart Preneel, Nele Mentens
IEEE Trans. Intell. Transp. Syst.1
2023 Yes we CAN!: Towards bringing security to legacy-restricted Controller Area Networks. A review
abstract
With the demand for advanced functionality such as autonomous driving, the complexity and connectivity of modern vehicles have faced an overwhelming expansion in recent years. Although the numerous interfaces pave the way for a better user experience, recent research has demonstrated that they can also serve as an attack surface for cybercriminals. Therefore, researchers have been challenged to develop a wide variety of security solutions aiming to solve specific issues.
Wouter Hellemans, Md Masoom Rabbani, Bart Preneel, Nele Mentens
CF1
2022 FOCUS: Frequency Based Detection of Covert Ultrasonic Signals
Wouter Hellemans, Md Masoom Rabbani, Jo Vliegen, Nele Mentens
SEC1