Adaptive-Augmented Cyber-Physical Detection of Evasive DNS Tunneling Attacks in Electric Vehicle Charging and Vehicle-to-Grid Networks
Electric vehicle (EV) charging stations and vehicle-to-grid (V2G) systems depend on outbound Domain Name System (DNS) resolution for firmware retrieval, backend discovery, and fleet synchronization, making DNS tunneling an attractive covert command-and-control and data-exfiltration channel in charging infrastructure. Machine learning detectors trained on lexical and statistical DNS features achieve excellent in-distribution accuracy, yet they are rarely stress-tested against adaptive adversaries that deliberately reshape query characteristics toward benign traffic. This paper presents a station-independent evaluation framework and an adaptive-augmented, cyber-physical detection architecture for evasive DNS tunneling in EV charging and V2G networks. Using a 200-station synthetic dataset that couples 24 DNS features with 16 EV/Open Charge Point Protocol (OCPP)/V2G telemetry features and 14 cross-modal consistency features, we evaluate every detector over ten repeated grouped station-level splits and across three attack regimes: an adaptive-strength sweep (β = 0.25–0.95) of the interpolation mechanism used in training, a separately held-out constraint-aware adaptive mechanism excluded from all training and model selection, and multiplicative perturbation of the physical-anchor telemetry at relative scales of 5–20%. Under strong interpolation-based evasion at the training strength (β = 0.90), detectors relying on DNS evidence retain almost no detection capability at their original operating point (mean F1 = 0.041 ± 0.023), although part of their threshold-free ranking ability survives, and recalibrating the decision threshold alone does not repair the collapse. We propose a safe EV-anchored fusion detector that treats physical telemetry as a protected anchor, hardens a cross-modal branch with adaptive examples drawn only from training stations, and admits DNS evidence only through a bounded, validation-selected correction. Across the ten splits, the proposed detector sustains F1 = 0.909 ± 0.013 at β = 0.90 and F1 = 0.923 ± 0.016 under the held-out mechanism, retaining approximately 94–96% of its original F1 of 0.964 ± 0.006 at a false-positive rate near 5.5% (about 55 false alarms per 1000 benign windows), and it degrades gracefully (F1 ≥ 0.911) when the anchor telemetry is perturbed at up to 20% relative scale. The results indicate that anchoring detection in physical-side telemetry, with bounded and adaptively hardened cross-modal evidence, provides consistent performance across the evaluated repeated station partitions and is computationally feasible under the evaluated conditions.
Authors
- Sneh Trivedi
- Krutthika Hirebasur Krishnappa (ORCID: https://orcid.org/0000-0003-0117-0856)
Institutions
- Southern University and Agricultural and Mechanical College (US)
Publication Details
- Journal
- World Electric Vehicle Journal
- Published
- 2026-09-28
- DOI
- https://doi.org/10.3390/wevj17100503
- Primary Topic
- Vehicular Ad Hoc Networks (VANETs)
- Type
- article
- Field-Weighted Citation Impact
- 0.00