EVDetect: a framework for orchestrated and AI-powered detection of cyber-attacks in EV charging networks

E-mobility has gained significant attention in recent years due to its contribution to reducing greenhouse gas emissions and the technological advancements introduced by digital interfaces. However, these interfaces also expose the grid to an expanded threat landscape, including attacks such as spoofing and Denial-of-Service. In this article, we propose EVDetect, a comprehensive intrusion-detection framework supporting exploratory unsupervised analysis and supervised Machine Learning (ML) for Electric Vehicle (EV) charging networks. Our methodology introduces a decoupled logging architecture that prevents logging noise and enables the retrospective use of historical models, supporting reproducible experimentation with tabular security data. Candidate models are evaluated using both functional (i.e., F1-macro) and non-functional (i.e., inference latency, CPU utilization, and model size) characteristics, with the latter providing relative computational comparisons on common reference hardware. The framework is evaluated on the CICEVSE2024 dataset. In the full-dataset binary experiment, the leading ensembles achieved F1-macro values of 0.87 - 0.88, with XGBoost providing the most favorable relative-efficiency profile. The full multiclass experiment achieved an F1-macro of approximately 0.66, highlighting the difficulty of distinguishing attack categories with overlapping power-consumption patterns. Overall, EVDetect supports reproducible comparison of functional and computational model characteristics, while deployment performance on EVSE-class hardware remains to be validated.

Authors

Institutions

Publication Details

Journal
Scientific Reports
Published
2026-10-06
DOI
https://doi.org/10.1038/s41598-026-67199-1
Primary Topic
Network Security and Intrusion Detection
Type
article
Field-Weighted Citation Impact
0.00
Controls
|||
ALL TIME
JAN
FEB
MAR
APR
MAY
JUN
JUL
AUG
SEP
OCT
article

EVDetect: a framework for orchestrated and AI-powered detection of cyber-attacks in EV charging networks

Ioannis Vagionas, Alexios Lekidis, Ioannis Topouzelidis, Kosmas Lazaridis
Scientific Reports
Network Security and Intrusion Detection
article

EVDetect: a framework for orchestrated and AI-powered detection of cyber-attacks in EV charging networks

Ioannis Vagionas, Alexios Lekidis, Ioannis Topouzelidis, Kosmas Lazaridis
article en

Abstract

E-mobility has gained significant attention in recent years due to its contribution to reducing greenhouse gas emissions and the technological advancements introduced by digital interfaces. However, these interfaces also expose the grid to an expanded threat landscape, including attacks such as spoofing and Denial-of-Service. In this article, we propose EVDetect, a comprehensive intrusion-detection framework supporting exploratory unsupervised analysis and supervised Machine Learning (ML) for Electric Vehicle (EV) charging networks. Our methodology introduces a decoupled logging architecture that prevents logging noise and enables the retrospective use of historical models, supporting reproducible experimentation with tabular security data. Candidate models are evaluated using both functional (i.e., F1-macro) and non-functional (i.e., inference latency, CPU utilization, and model size) characteristics, with the latter providing relative computational comparisons on common reference hardware. The framework is evaluated on the CICEVSE2024 dataset. In the full-dataset binary experiment, the leading ensembles achieved F1-macro values of 0.87 - 0.88, with XGBoost providing the most favorable relative-efficiency profile. The full multiclass experiment achieved an F1-macro of approximately 0.66, highlighting the difficulty of distinguishing attack categories with overlapping power-consumption patterns. Overall, EVDetect supports reproducible comparison of functional and computational model characteristics, while deployment performance on EVSE-class hardware remains to be validated.

Scientific Reports
University of Thessaly (GR), Hellenic Open University (GR)
Openalex Percentile: Top 10%
Network Security and Intrusion Detection
AI Navigator

Ask Laika to Summarize, Analyze, and Connect papers live on the map.

Summarize Papers & Methodologies

Extract key findings, datasets, and comparative methods across publications.

Benchmark Rankings & Visual Analytics

Rank top research institutions, authors, funders, topics, and journals by Field-Weighted Citation Impact (FWCI) and paper volume with instant charts.

Connect Distant Disciplines

Bridge topological clusters on the map to find hidden collaborative intersections.

EVDetect: a framework for orchestrated and AI-powered detection of cyber-attacks in EV charging networks — Ioannis Vagionas, Alexios Lekidis, et al. · Scientific Reports (2026) | TGRS Research Map | TGRS