There is a newer version of the record available.

Published December 5, 2025 | Version v1

GEM-CAN: Real-World CAN-Bus Attack Scenarios on an Autonomous Vehicle for Intrusion Detection

Description

This dataset provides labeled CAN-bus traffic captured from a GEM e6 autonomous vehicle under normal operation and controlled cyberattacks. It includes ~143K frames spanning nominal driving (~100K), DoS floods using ID 0x00000000 (~41K), and data-tampering injections targeting brake and steering functions (~1.3K). Each entry records timestamp, arbitration ID, DLC, payload bytes, and a Normal/Attack label, with metadata detailing attack windows, bus load, bitrate, and test conditions. Data were collected via PCAN-View/PCAN-USB on a closed track while the vehicle operated autonomously. The dataset provides real-vehicle evidence of availability and integrity attacks—supporting reproducible evaluation of lightweight automotive intrusion detection systems.

Files

GEM_CAN_Dataset.zip

Files (1.0 MB)

Name Size Download all
md5:02cd463677e37cf9becdd4374e9db26c
1.0 MB Preview Download

Additional details

Funding

Office of the Assistant Secretary for Research and Technology
Center for Regional and Rural Connected Communities (CR2C2) 69A3552348304

References

  • Tavasoli, M., Sarrafzadeh, A., Karimoddini, A., Khaleghi, M., Phuapaiboon, T., Goines, A., Harris, A., & Griffith, J. (2025). Trust-aware federated defense against data poisoning in ML-driven IDS for CAVs. In Proceedings of the 22nd Annual International Conference on Privacy, Security, and Trust (PST 2025). IEEE.
  • ISO 11898-1:2015, Road vehicles — Controller Area Network (CAN) — Part 1: Data link layer and physical signalling, ISO, 2015.
  • H.M. Song, H.R. Kim, H.K. Kim, Intrusion detection system based on analysis of time intervals of CAN messages for in-vehicle network, ICOIN, 2016, pp. 63–68.
  • C. Miller, C. Valasek, Remote exploitation of an unaltered passenger vehicle, Black Hat USA, 2015.