Research Paper:
LSTM–AttnAE: A Hybrid Model for Sybil Attack Detection in VANETs
Hailing Bao
, Ligang Cong
, Xu Liu
, Qingyun Liang
, and Rongpu Wang

School of Computer Science and Technology, Changchun University of Science and Technology
No.7186 Weixing Road, Changchun, Jilin 130022, China
Corresponding author
As a core component of intelligent transportation systems, vehicular ad hoc networks (VANETs) are critical to traffic efficiency and public safety. However, their security is severely threatened by Sybil attacks, whose stealthy and destructive nature complicates detection. To address this issue, this study proposes LSTM–AttnAE, a hybrid anomaly detection model that integrates LSTM, autoencoder, and attention mechanisms. Unlike conventional methods, it leverages LSTM for temporal feature extraction, an autoencoder for self-learning normal behavioral patterns, and an attention module to dynamically prioritize critical features (boosting detection sensitivity). Experiments on the VeReMi extended dataset showed that the model outperformed traditional approaches, achieving 99% precision and 98% recall. This study provides an effective technical solution for VANET security and new insights into anomaly detection in complex networks.
Framework of the LSTM-AttnAE model
- [1] H. Hadri et al., “Sybil attack detection in vehicular ad hoc networks (VANETs): A comprehensive survey,” Innovations in Systems and Software Engineering, Vol.21, pp. 453-474, 2025. https://doi.org/10.1007/s11334-025-00603-7
- [2] J. R. Douceur, “The Sybil attack,” Int. Workshop on Peer-to-Peer Systems, pp. 251-260, 2002. https://doi.org/10.1007/3-540-45748-8_24
- [3] M. S. Bouassida et al., “Sybil nodes detection based on received signal strength variations within VANET,” Int. J. Netw. Secur., Vol.9, No.1, pp. 22-33, 2009.
- [4] B. Yu et al., “Detecting Sybil attacks in VANETs,” J. Parallel Distrib. Comput., Vol.73, No.6, pp. 746-756, 2013. https://doi.org/10.1016/j.jpdc.2013.02.001
- [5] J. Grover et al., “A Sybil attack detection approach using neighboring vehicles in VANET,” Proc. of the 4th Int. Conf. on Security of Information and Networks, pp. 151-158, 2011. https://doi.org/10.1145/2070425.2070450
- [6] X. Feng and J. Tang, “Obfuscated RSUs vector based signature scheme for detecting conspiracy Sybil attack in VANETs,” Mob. Inf. Syst., Vol.2017, No.1, Article No.4682538, 2017. https://doi.org/10.1155/2017/4682538
- [7] S. S. Sefati and S. G. Tabrizi, “Detecting Sybil attack in vehicular ad-hoc networks (VANETs) by using fitness function, signal strength index and throughput,” Wirel. Pers. Commun., Vol.123, No.3, pp. 2699-2719, 2022. https://doi.org/10.1007/s11277-021-09261-x
- [8] B. Xiao et al., “Detection and localization of Sybil nodes in VANETs,” Proc. of the 2006 Workshop on Dependability Issues in Wireless Ad Hoc Networks and Sensor Networks, 2006. https://doi.org/10.1145/1160972.1160974
- [9] W. Li and D. Zhang, “RSSI sequence and vehicle driving matrix based Sybil nodes detection in VANET,” 2019 IEEE 11th Int. Conf. on Communication Software and Networks (ICCSN), pp. 763-767, 2019. https://doi.org/10.1109/ICCSN.2019.8905261
- [10] Y. Yao et al., “Voiceprint: A novel Sybil attack detection method based on RSSI for VANETs,” 2017 47th Annual IEEE/IFIP Int. Conf. on Dependable Systems and Networks (DSN), pp. 591-602, 2017. https://doi.org/10.1109/DSN.2017.10
- [11] Y. Yao et al., “Multi-channel based Sybil attack detection in vehicular ad hoc networks using RSSI,” IEEE Trans. Mob. Comput., Vol.18, No.2, pp. 362-375, 2018. https://doi.org/10.1109/TMC.2018.2833849
- [12] Y. Yao et al., “Power control identification: A novel Sybil attack detection scheme in VANETs using RSSI,” IEEE J. Sel. Areas Commun., Vol.37, No.11, pp. 2588-2602, 2019. https://doi.org/10.1109/JSAC.2019.2933888
- [13] S. Rakhi and K. R. Shobha, “LCSS based Sybil attack detection and avoidance in clustered vehicular networks,” IEEE Access, Vol.11, pp. 75179-75190, 2023. https://doi.org/10.1109/ACCESS.2023.3294469
- [14] R. V. Saraswathi et al., “Support vector based regression model to detect Sybil attacks in WSN,” Int. J. Adv. Trends Comput. Sci. Eng., Vol.9, No.3, pp. 4090-4096, 2020. https://doi.org/10.30534/ijatcse/2020/236932020
- [15] S. Ercan et al., “Misbehavior detection for position falsification attacks in VANETs using machine learning,” IEEE Access, Vol.10, pp. 1893-1904, 2021. https://doi.org/10.1109/ACCESS.2021.3136706
- [16] C. H. O. Quevedo et al., “An intelligent mechanism for Sybil attacks detection in VANETs,” 2020 IEEE Int. Conf. on Communications (ICC), 2020. https://doi.org/10.1109/ICC40277.2020.9149371
- [17] S. Azam et al., “Collaborative learning based Sybil attack detection in vehicular ad-hoc networks (VANETs),” Sensors, Vol.22, No.18, Article No.6934, 2022. https://doi.org/10.3390/s22186934
- [18] E. Abdelkreem et al., “Feature engineering impact on position falsification attacks detection in vehicular ad-hoc network,” Int. J. Inf. Secur., Vol.23, No.3, pp. 1939-1961, 2024. https://doi.org/10.1007/s10207-024-00830-2
- [19] D. E. Laouiti et al., “Sybil attack detection in VANETs using an AdaBoost classifier,” 2022 Int. Wireless Communications and Mobile Computing (IWCMC), pp. 217-222, 2022. https://doi.org/10.1109/IWCMC55113.2022.9824974
- [20] S. Rethinavalli and R. Gopinath, “Classification approach based Sybil node detection in mobile ad hoc networks,” Int. J. Adv. Res. Eng. Technol., Vol.11, No.12, pp. 3348-3356, 2020.
- [21] M. Al-Qurishi et al., “A prediction system of Sybil attack in social network using deep-regression model,” Future Gener. Comput. Syst., Vol.87, pp. 743-753, 2018. https://doi.org/10.1016/j.future.2017.08.030
- [22] A. Balaram et al., “Highly accurate Sybil attack detection in vanet using extreme learning machine with preserved location,” Wirel. Netw., Vol.29, No.8, pp. 3435-3443, 2023. https://doi.org/10.1007/s11276-023-03399-1
- [23] J. Kamel et al., “A misbehavior authority system for Sybil attack detection in C-ITS,” 2019 IEEE 10th Annual Ubiquitous Computing, Electronics Mobile Communication Conference (UEMCON), pp. 1117-1123, 2019. https://doi.org/10.1109/UEMCON47517.2019.8993045
- [24] N. C. Velayudhan et al., “An optimisation driven deep residual network for Sybil attack detection with reputation and trust-based misbehaviour detection in VANET,” J. Exp. Theor. Artif. Intell., Vol.36, No.5, pp. 721-744, 2024. https://doi.org/10.1080/0952813X.2022.2104387
- [25] Y. Rajendra, V. Subramanian, and S. K. Shukla, “Sybil attack detection in ultra-dense VANETs using verifiable delay functions,” Peer-to-Peer Networking and Applications, Vol.17, No.3, pp. 1645-1666, 2024. https://doi.org/10.1007/s12083-024-01673-3
- [26] Y. Chen et al., “MDFD: A multi-source data fusion detection framework for Sybil attack detection in VANETs,” Computer Networks, Vol.224, Article No.109608, 2023. https://doi.org/10.1016/j.comnet.2023.109608
- [27] R. Sultana et al., “Detecting Sybil attacks in VANET: Exploring feature diversity and deep learning algorithms with insights into Sybil node associations,” J. of Network and Systems Management, Vol.32, Article No.51, 2024. https://doi.org/10.1007/s10922-024-09827-7
- [28] T. Gao et al., “A content-based method for Sybil detection in online social networks via deep learning,” IEEE Access, Vol.8, pp. 38753-38666, 2020. https://doi.org/10.1109/ACCESS.2020.2975877
- [29] Y. Zhong et al., “Sybil attack detection in VANETs: An LSTM-based BiGAN approach,” 2023 Int. Conf. on Data Security and Privacy Protection (DSPP), pp. 113-120, 2023. https://doi.org/10.1109/DSPP58763.2023.10404993
- [30] U. Michelucci, “An introduction to autoencoders,” arXiv:2201.03898, 2022. https://doi.org/10.48550/arXiv.2201.03898
- [31] D. Tang et al., “A deep learning approach to detecting multiple types of Sybil nodes in VANETs,” Proc. of the 18th IEEE/ACM Int. Conf. on Utility and Cloud Computing (UCC), 2025. https://doi.org/10.1145/3773274.3774695
- [32] D. Bahdanau et al., “Neural machine translation by jointly learning to align and translate,” arXiv:1409.0473, 2014. https://doi.org/10.48550/arXiv.1409.0473
- [33] Y. Zhang et al., “Attention is all you need: Utilizing attention in AI-enabled drug discovery,” Brief. Bioinform., Vol.25, No.1, Article No.bbad467, 2024. https://doi.org/10.1093/bib/bbad467
- [34] Y. T. Gebrezgiher, S. R. Jeremiah, S. Gritzalis, and J. H. Park, “VAE-based real-time anomaly detection approach for enhanced V2X communication security,” Applied Sciences, Vol.15, No.12, Article No.6739, 2025. https://doi.org/10.3390/app15126739
- [35] M. Said Elsayed et al., “Network anomaly detection using LSTM based autoencoder,” Proc. of the 16th ACM Symp. on QoS and Security for Wireless and Mobile Networks, pp. 37-45, 2020. https://dl.acm.org/doi/10.1145/3416013.3426457
This article is published under a Creative Commons Attribution-NoDerivatives 4.0 Internationa License.