Brooke Kidmose

dblp:337/7810 · also Brooke Elizabeth Kidmose, Brooke Lampe · DBLP profile ↗
← Back
15ranked-venue papers
5as first author
15since 2021 · last 2025
0000-0002-6673-6163ORCID · verified

Domains — the database's venue-derived domains; a paper can count in several

Security and privacy · 6 · 2 first-author · 6 since 2021Computer networks · 4 · 1 first-author · 4 since 2021Artificial intelligence and machine learning · 2 · 1 first-author · 2 since 2021Systems, architecture and hardware · 2 · 2 since 2021Software engineering, systems software and programming languages · 1 · 1 since 2021Graphics, computer vision, multimedia, augmented reality and games · 1 · 1 since 2021
YearPublicationVenuePosition
2025 Towards Practical Automotive Intrusion Detection Systems: An Adaptive Rule-Based Approach
Lucien Kiven Tamo, Brooke Kidmose, Weizhi Meng 0001, Thanassis Giannetsos
NSS2
2024 An eID-Based Privacy-Enhanced Public Transportation Ticket System
Kanagaratnam Anojjan, Weizhi Meng 0001, Brooke Kidmose, Yu Wang 0017
ISPEC3
2024 can-fp: An Attack-Aware Analysis of False Alarms in Automotive Intrusion Detection Models
abstract
The automotive controller area network (CAN) bus functions as the communications backbone of automobiles around the globe. Unfortunately, the CAN bus was developed for the closed-system vehicles of the 1980s, not the inter-connected—even autonomous—vehicles hitting the roads today, meaning that the CAN bus is extraordinarily insecure. Much of the literature points to automotive intrusion detection as the solution; it is lightweight and does not involve re-engineering the CAN bus. That said, in safety-critical automotive environments, we can expect to see millions of messages every ten minutes; as such, accuracy is paramount. A false positive rate (FPR) of 0.00001 corresponds to about ten false positives every ten minutes. Therefore, in this paper, we investigate false positives generated by the machine learning models that constitute automotive intrusion detection systems (IDSs). In particular, we explore the timestamp and time delta features to determine if they have a positive or negative impact on the FPR. Then, we look into the patterns of false positives, and we discover that many false positives are produced during actual attacks. Essentially, when legitimate messages are interlaced with attack messages, anomalous patterns are produced, and legitimate messages are flagged as anomalous. The IDS has done its job and detected an attack-it simply misidentified legitimate messages as part of the attack. When it comes to automotive attacks, many of the mitigation strategies do not require precise identification of the attack messages; that is, it is enough to know that an attack is ongoing. As such, we exclude false positives that occur during attack conditions from the FPR, and we examine the results. We find that, for a number of machine learning models, discounting attack-related false positives can significantly improve the FPR.
Brooke Kidmose, Weizhi Meng 0001
PST1
2024 Pitfalls of Data Masking Techniques: Re-identification Attacks
Samir Hodzic, Andreas B. Kidmose, Brooke Kidmose, Lars R. Knudsen, Weizhi Meng 0001
SecureComm (3)3
2024 Evolutionary Analysis of Alloy Specifications with an Adaptive Fitness Function
Jianghao Wang, Clay Stevens, Brooke Kidmose, Myra B. Cohen, Hamid Bagheri
SSBSE3
2024 can-train-and-test: A curated CAN dataset for automotive intrusion detection
abstract
When it comes to in-vehicle networks (IVNs), the controller area network (CAN) bus dominates the market; automobiles manufactured and sold worldwide depend on the CAN bus for safety-critical communications between various components of the vehicle (e.g., the engine, the transmission, the steering column). Unfortunately, the CAN bus is inherently insecure; in fact, it completely lacks controls such as authentication, authorization, and confidentiality (i.e., encryption). Therefore, researchers have travailed to develop automotive security enhancements. The automotive intrusion detection system (IDS) is especially popular in the literature—due to its relatively low cost in terms of money, resource utilization, and implementation effort. That said, developing and evaluating an automotive IDS is often challenging; if researchers do not have access to a test vehicle, then they are forced to depend on publicly available CAN data—which is not without limitations. Lack of access to adequate CAN data, then, becomes a barrier to entry into automotive security research. We seek to lower that barrier to entry by introducing a new CAN dataset to facilitate the development and evaluation of automotive IDSs. Our datasets—dubbed can-dataset, can-log, can-csv, can-ml, and can-train-and-test—provide CAN data from four different vehicles produced by two different manufacturers. The attack captures for each vehicle model are equivalent, enabling researchers to assess the ability of a given IDS to generalize to different vehicle models and even different vehicle manufacturers. Our datasets contain replayable .log files as well as labeled and unlabeled .csv files, thereby meeting a variety of development and evaluation needs. In particular, the can-train-and-test dataset offers nine unique attacks, ranging from denial of service (DoS) to gear spoofing to standstill; as such, researchers can select a subset of the attacks for training and save the remainder for testing in order to assess a given IDS against unseen attacks. Many of our attacks, particularly the spoofing-related attacks, were conducted during live, on-the-road experiments with real vehicles. These attacks have known physical impacts. As a benchmark, we pit a number of machine learning IDSs against our dataset and analyze the results. We present our datasets—especially can-train-and-test—as a contribution to the existing catalogue of open-access datasets in hopes of filling in the gaps left by those datasets.
Brooke Kidmose, Weizhi Meng 0001
Comput. Secur.1
2024 Detecting Post Editing of Multimedia Images using Transfer Learning and Fine Tuning
abstract
In the domain of general image forgery detection, a myriad of different classification solutions have been developed to distinguish a “tampered” image from a “pristine” image. In this work, we aim to develop a new method to tackle the problem of binary image forgery detection. Our approach builds upon the extensive training that state-of-the-art image classification models have undergone on regular images from the ImageNet dataset, and transfers that knowledge to the image forgery detection space. By leveraging transfer learning and fine tuning, we can fit state-of-the-art image classification models to the forgery detection task. We train the models on a diverse and evenly distributed image forgery dataset. With five models—EfficientNetB0, VGG16, Xception, ResNet50V2, and NASNet-Large—we transferred and adapted pre-trained knowledge from ImageNet to the forgery detection task. Each model was fitted, fine-tuned, and evaluated according to a set of performance metrics. Our evaluation demonstrated the efficacy of large-scale image classification models—paired with transfer learning and fine tuning—at detecting image forgeries. When pitted against a previously unseen dataset, the best-performing model of EfficientNetB0 could achieve an accuracy rate of nearly 89.7%.
Simon Lucas Jonker, Malthe Jelstrup, Weizhi Meng 0001, Brooke Kidmose
ACM Trans. Multim. Comput. Commun. Appl.4
2023 Securing Offshore Installations Against Automatic Identification System Spoofing
abstract
The AIS (Automatic Identification System) is a maritime navigation safety communication system that transmits data, such as vessel location and identification, both to nearby vessels and to coastal facilities. Unfortunately, AIS spoofing is a growing concern: malicious actors could transmit false AIS messages in order to mislead vessels and potentially cause accidents. In this work, we developed a tool for AIS message validation. Under evaluation, the tool delivered promising results in terms of AIS spoofing detection and prevention, thereby demonstrating the tool's efficacy and potential to complement existing detection and prevention techniques.
Grzegorz Jacek Kot, Weizhi Meng 0001, Brooke Kidmose
GLOBECOM3
2023 BlockPAT: A Blockchain-Enabled Second-Hand Physical Asset Tokenization Management System
abstract
In this work, we develop BlockPAT, a blockchain-enabled management system for the tokenization of second-hand physical assets, e.g., laptops. With this system, the information gap between buyers and sellers in the second-hand market will be eliminated, and with the help of a price oracle, the liquidity of the second-hand market can be greatly improved. Furthermore, our system is built upon the latest ZK-rollups solution; thus, the overall transaction cost and time delay will be limited to an affordable value.
Wei-Yang Chiu, Weizhi Meng 0001, Brooke Kidmose
ICDCS4
2023 Delay-masquerading Technique Upheld StrongBox: A Reinforced Side-Channel Protection
abstract
In recent years, Graphical Processing Unit (GPU) is not only becoming a piece of hardware that accelerates graphics but also playing a key role in accelerating the fields of machine learning and artificial intelligence. The GPU’s heightened importance has led to increasing concern about the confidentiality of a GPU’s computing data as well as its internal communications. Although the GPU Trusted Execution Environment (TEE) has been implemented as a solution toward this issue, side-channel attacks in GPUs still remain as an open problem. In this work, we introduce Delay-masquerading Technique Upheld StrongBox (DTUBox) to strengthen the resilience of existing GPU TEE over StrongBox against side-channel attacks by injecting obfuscated noise with our developed algorithm, making the correlations difficult to reference between a task and workload. In our evaluation, we demonstrate that with only around 5% performance overhead, our approach could effectively lower the correlation rate to 38% between the original behavior sequences and the obfuscated sequences.
Shuoqiang Zeng, Wei-Yang Chiu, Peichen Liu, Weizhi Meng 0001, Brooke Kidmose
ICPADS6
2023 Look Closer to Touch Behavior-enabled Android Pattern Locks: A Study in the Wild
abstract
Android pattern lock is one of the most popular unlocking mechanisms on the Android platform. In order to enhance the security of Android’s unlocking functionality, a number of researchers have tried to combine touch biometrics with the pattern lock. Several studies have reported adequate— even excellent—authentication results, but, unlike fingerprint-and face recognition-based authentication, no biometrics-enabled pattern lock exists in the Android marketplace. Furthermore, most studies of biometrics-enabled pattern locks were conducted in controlled lab environments. As such, in this work, our goal is to investigate and validate the performance of touch behavior-enabled Android pattern locks in a more practical scenario, in which users have to download the application and learn to use it by themselves (as was often the case during the pandemic). During the course of our investigation, we collected substantial data, namely, the properties provided by the Android API for motion events, as well as measurements that could be extracted from the devices’ sensors. Our investigation found that touch-enabled Android pattern locks could achieve an average equal error ratio of 23.5% for user authentication—without changing the process from the user’s perspective. Next, we modified the user experience such that each user would train the authenticator with different fingers, similar to fingerprint-based authentication. With this modification, an average equal error ratio of 13.5% was achieved.
Gergely Tuskó, Weizhi Meng 0001, Brooke Kidmose
TrustCom3
2023 can-train-and-test: A New CAN Intrusion Detection Dataset
abstract
The controller area network (CAN) bus facilitates communication between a vehicle's microcontrollers, known as electronic control units (ECUs). Developed in 1983, the CAN bus is exceedingly robust—and exceedingly insecure. The CAN bus lacks conventional security controls (e.g., authentication, authorization, access control, encryption—to name a few). Significant research work has focused on improving automotive security; however, it has been challenging to add security to the CAN bus ex post facto.The automotive intrusion detection system (IDS) has been popularized in the literature as a relatively low-cost, low-effort security improvement for the CAN bus. Unfortunately, would-be IDS designers are often confronted with a shortage of adequate datasets to facilitate IDS development and evaluation. For intrusion detection systems built from machine learning models, the dataset shortage is particularly problematic; machine learning models require a lot of data for training and testing. The shortage of CAN datasets might impede or even deter would-be automotive IDS researchers.In this work, we introduce a new CAN dataset, dubbed can-train-and-test, to ameliorate the shortage of CAN datasets for IDS development and evaluation. Our dataset contains CAN data from four different vehicles manufactured by two different organizations—Chevrolet (General Motors) and Subaru. We provide attack-free traffic captures as well as captures that demonstrate nine distinct types of attacks—e.g., denial of service (DoS), fuzzing, standstill. We conduct all nine attacks against each of the four vehicles; thus, IDS designers can use the attack captures to evaluate an IDS's ability to generalize to different vehicles. We provide (1) replayable .log files, (2) unlabeled .csv files, and (3) labeled .csv files in order to meet a variety of IDS development and evaluation needs.
Brooke Kidmose, Weizhi Meng 0001
VTC Fall1
2023 A survey of deep learning-based intrusion detection in automotive applications
abstract
Modern automobiles depend on internal vehicle networks (IVNs) to control systems from the anti-lock brakes to the transmission to the locks on the doors. Many IVNs, particularly the Controller Area Network (CAN) bus, were developed with little regard for security, since the IVNs of the past were isolated from the outside world. In the present day, the assumption of isolation no longer applies. Cellular service, Wi-Fi, and Bluetooth are just a few examples of the connectivity of contemporary automobiles. Researchers have explored a number of automotive security enhancements, but such enhancements are often roadblocked by implementation challenges, complexity, and expense. An intrusion detection system (IDS) is a promising automotive security enhancement that requires little, if any, adjustment to a vehicle’s existing infrastructure. Deep learning techniques can augment the capability of automotive IDSs, improving detection accuracy and precision. This paper provides a comprehensive overview of deep learning-based IDSs in automotive networks. We assemble various deep learning schemes, categorize them according to their topologies and techniques, and highlight their distinct contributions. In addition, we analyze each scheme’s evaluation in terms of datasets, attack types, and metrics. We summarize the results of the schemes and assess the advantages and disadvantages of different deep learning architectures.
Brooke Kidmose, Weizhi Meng 0001
Expert Syst. Appl.1
2022 IDS for CAN: A Practical Intrusion Detection System for CAN Bus Security
abstract
Modern automobiles depend heavily on electronics, controlled by the vehicle's internal network. The controller area network (CAN bus) is the predominant protocol, known for its reliability but also its grievous lack of security. Unfortunately, security is expensive and automotive manufacturers seem disinclined to invest in CAN bus protection. Thus, consumers are left with few options to improve security. In this work, we develop IDS for CAN – an Android application that functions as an intrusion detection system (IDS) for the CAN bus system. In particular, it communicates with a standard ELM 327-type device, plugged into the diagnostic port that is mandatory in the United States and Europe. The application will detect suspicious traffic on the CAN bus and generate an alert to notify the user. In our evaluation, we investigate the performance with both datasets and real vehicles. The results indicate the practicability and the effectiveness of our proposed system. Our application will allow consumers to take charge of automotive security.
Brooke Kidmose, Weizhi Meng 0001
GLOBECOM1
2022 TDL-IDS: Towards A Transfer Deep Learning based Intrusion Detection System
abstract
With the development of Internet of Things (IoT), network security has become very important as cyber-attackers can easily compromise such distributed networks and systems. An intrusion detection system (IDS) is a basic and essential security mechanism to detect malicious traffic. In the literature, in addition to traditional machine learning algorithms, many deep learning schemes have been examined to enhance the detection performance. However, insufficient amounts of labeled samples are still a challenge for real-world implementation, especially in some scenarios such as smart home and Internet of Vehicles. To address this issue, we explore transfer learning as a promising solution. In this work, we develop TDL-IDS, a transfer deep learning based IDS that can work with limited labeled data items. Our approach first uses Long Short Term Memory (LSTM) to train a model on the source domain and then leverages transfer learning to continue the training process on the target domain. In the evaluation, we use NSL-KDD as the source domain, and AWID as the target domain. Our results indicate that TDL-IDS can outperform many similar approaches.
Xingguo Sun, Weizhi Meng 0001, Wei-Yang Chiu, Brooke Kidmose
GLOBECOM4