Please use this identifier to cite or link to this item: http://dspace.aiub.edu:8080/jspui/handle/123456789/3029
Title: Edge-optimized real-time detection of DoS attacks in EV charging networks via Kernel-level behavioral modeling and transformer–MLP fusion
Authors: Tanjim, Raif
Ahmed, Tanvir
Hannan, Nasif
Mostafa, Mobashwar
Shufian, Abu
Ghosh, Debashish Kumar
Keywords: Edge AI
Deep learning and cybersecurity
Real-time intrusion detection
EV charging network for smart grid
Issue Date: 2-Jul-2026
Publisher: Elsevier International Journal of Electrical Power & Energy Systems
Citation: 1376
Abstract: As EVSE systems become increasingly digitized and interconnected within smart grids, the need for real-time and lightweight cybersecurity solutions has become increasingly critical. This work presents an efficient intrusion detection framework based on a hybrid Transformer–MLP architecture designed to detect DoS attacks using low-level kernel event logs from EVSE systems. The proposed model integrates a self-attention-based Transformer encoder to capture complex feature dependencies, while the MLP component enables efficient and effective decision mapping. A comprehensive preprocessing pipeline, including feature leakage removal, normalization, and stratified data splitting, ensures reliable data preparation for robust learning. The training process incorporates stratified k-fold cross-validation and evaluation on an independent test set to enhance model generalization. Experimental results demonstrate near-perfect performance across key evaluation metrics, including Precision, Accuracy, Recall, F1-score, ROC-AUC, and PR-AUC. Additional analyses, including ROC and PR curves, confusion matrices, learning curves, and robustness evaluations, further validate the model's discriminative capability and robustness under moderate perturbations. Beyond accuracy, the model is lightweight and resource-efficient, making it suitable for deployment on edge-level devices such as charging station controllers or gateway firmware. This enables real-time, on-device intrusion detection without reliance on centralized computation, facilitating timely responses to cyber threats. While the proposed framework demonstrates strong performance, it has been evaluated within a controlled testbed environment and primarily on DoS attack scenarios. Further validation across diverse real-world deployments and a broader range of attack types is necessary to fully assess its generalization capability.
URI: http://dspace.aiub.edu:8080/jspui/handle/123456789/3029
ISSN: 1879-3517
Appears in Collections:Publications From Faculty of Engineering

Files in This Item:
File Description SizeFormat 
Shufian_2026_Elsevier (IJEPES 3).docxShufian_2026_Elsevier (IJEPES 3)3.34 MBMicrosoft Word XMLView/Open


Items in DSpace are protected by copyright, with all rights reserved, unless otherwise indicated.