Urban transportation intrusion detection is difficult because many compromised messages remain individually credible until they are checked against surrounding road, sensor, and signal states. This study investigated this problem by formulating it as a five-way message classification task over one benign class and four attack families, and by evaluating three detector families under matched access to transportation state: a local-rule baseline, a flat-feature multiclass logistic model, and a knowledge-graph detector with explicit graph reasoning. This study presents a two-part evaluation that combined a controlled simulator with a real-city analysis built from OpenStreetMap and Texas Department of Transportation (TxDOT) data for downtown Austin, Houston, and Dallas. In the fully observed configuration, both the flat-feature logistic and knowledge-graph detectors perform well, while the knowledge-graph detector preserves an explicit rule structure. In the three-city configuration, the knowledge-graph detector shows better portability across cities and lower inference latency. The ablation results further show that roadside sensing and topology account for most of the graph-based detector’s performance.
Pan et al. (Sat,) studied this question.