Engineering Papers⌕ Search

SEARCH · Engineering Papers

Results for “controller area network”

Search indexed NASA NTRS and DOE OSTI research on propulsion, heat transfer, battery materials and energy systems. Follow report and document links to the original sources.

Quote a phrase for an exact phrase match. Source license links do not imply unrestricted reuse.

At least 37 records · Page 2

Firmware Tampering Detection in Heavy-Duty Vehicles through J1939 CAN Analysis

Modern heavy-duty vehicles rely on complex networks of Electronic Control Units (ECUs) that communicate using the J1939 protocol. While this system makes it easier to update and configure vehicle components, it also opens the door to serious cybersecurity risks if not properly secured. This work investigates the potential for firmware tampering through the J1939 communication protocol, which enables ECU configuration and reprogramming over the Controller Area Network (CAN) bus. By monitoring CAN traffic during legitimate maintenance operations and reverse-engineering OEM diagnostic software, we identified common and proprietary J1939 message identifiers, authentication patterns, and vulnerabilities within Unified Diagnostic Services (UDS). These findings demonstrate that inadequate authentication mechanisms can allow malicious actors to alter ECU firmware or disable safety functions, posing severe operational and safety risks. Our analysis contributes to the development of vehicle intrusion detection systems capable of recognizing abnormal reprogramming activity and future firmware fingerprinting methods to verify software integrity across ECUs. This work highlights the importance of standardizing secure firmware authentication across manufacturers to strengthen cyber resilience in heavy-duty vehicle systems.

33 ADVANCED PROPULSION SYSTEMS↗

Strym: A Python Package for Real-time CAN Data Logging, Analysis and Visualization to Work with USB-CAN Interface

In this report, we describe a data analysis tool developed for decoding and analyzing vehicle data obtained from a passenger vehicle’s onboard controller area network (CAN) bus. The tool developed in this paper provides a timeseries framework to perform domain-specific analysis at scale when interpreting data from a vehicle or a collection of vehicles in light of how to design intelligent vehicle applications. The tool, called Strym, exploits the CAN bus mechanism of modern vehicles to capture data using commercially available CAN-to-USB hardware Comma.ai Panda devices, managed through open-source software Libpanda. Strym permits the decoding of vendor-specific CAN messages in a vehicle-agnostic manner. Through this, a researcher can characterize data throughput, assess data quality, and perform analyses. Such analyses are useful in a number of research such as studying human driving behavior in mixed-autonomy, new driver models, rare-event detection, traffic flow estimation, and custom control of vehicles.

Performance evaluation, Smart cities, Intelligent ↗

A methodology to develop multi-physics dynamic fuel cell system models validated with vehicle realistic drive cycle data

Fuel cell (FC) technology has been identified as a technically attractive solution to decarbonize the transportation sector, especially for heavy-duty vehicles. In this context, the industry and the scientific community are in need of advanced fuel cell systems (FCS) models that are able to replicate real -world operating conditions. Due to the scarcity of said models in the open literature, this study aimed to develop a comprehensive methodology to calibrate and validate multi -physics dynamic FCS models. Therefore, the key contribution of this paper is the detailed description of the calibration process for each component and the calibration order. The specific focus here was to accurately describe the behavior of the FC stack as well as the cathode, anode, and cooling circuits of the balance of plant. The model was calibrated with the aid of experimental data from a Toyota Mirai FC electric vehicle, which was predominantly retrieved from the vehicle's Controller Area Network (CAN) bus system thereby negating the need for major intrusion into the powertrain system. The validation process was deemed successful with the model being able to truthfully replicate the characteristics of the FC vehicle operated on the World-wide harmonized Light duty Test Cycle (WLTC) 3b and US06 driving cycle. The time -resolved physical parameters such as the cathode pressure, mass flow, or the FC stack temperature were captured with high fidelity, while the overall performance parameters such as the H2 consumption in the stack and the system, and the compressor energy consumption were predicted accurately with a deviation lower than 0.47%, 1.75% and 1.89% with respect to the experimental data, respectively.

Lopez-Juarez, Marcos↗

Enhancing Automotive Intrusion Detection Through Multi-Modal Fusion: A CAN FD-LiDAR Approach

As vehicles become smarter and more autonomous, they increasingly depend on advanced sensors and communication technologies to operate securely. However, such growing dependence on technology—whether it’s CAN (Controller Area Network) for internal communication or LiDAR (Light Detection and Ranging) for sensing the world around them—also expands the attack surface for the types of cyber attacks. Traditional intrusion detection systems (IDS) typically monitor these systems in isolation, limiting their ability to detect sophisticated, crosssystem attacks. To address this, we propose a multi-modal fusion approach that combines real-world CAN FD signals (from the HCRL dataset) with LiDAR features (from the nuScenes dataset) to enhance attack detection. Our method employs a twostage ensemble approach. Calibrated XGBoost and LightGBM models initially process CAN FD (Fuzzing Data) and LiDAR data independently, detecting timing anomalies and space abnormalities. They are subsequently logarithmically combined with a logistic regression meta-model along with 17 engineered features capturing cross-modal behavior, prediction conflicts, and nonlinear interactions. This approach achieves an AUC of 0.87 and an F1-score of 0.82, surpassing single-modality baselines and early fusion methods, at merely 2 ms inference latency. Compared with deep learning competitors, it is 3 times more efficient, providing a lightweight, interpretable, and real time solution to automotive cybersecurity.

97 MATHEMATICS AND COMPUTING↗

Cy-Phy ADS: Cyber Physical Anomaly Detection Framework for EV Charging Systems

Today’s large-scale Electric Vehicle (EV) infrastructures are heavily dependent on information communication technologies to maintain their operation and to support communication within sub-system components as well as the outside world. These technologies are vulnerable to various cyber and physical threats. Timely identification and mitigation of these threats are critical for improving human safety, avoiding economic losses, and preventing catastrophic system failures. By addressing this, our work presents a ResNet Autoencoder (AE) based Cyber-Physical Anomaly Detection System (Cy-Phy ADS) for detecting anomalies in EV Controller Area Network (CAN) protocol communication. It consists of four main components: Cyber-Physical Feature Extractor, ResNet AE-based Anomaly Detection Framework, Cyber-Physical Health Metric (CPHM), and Visualization Dashboard. The presented framework was trained and tested using CAN data collected from the EV charging system testbed at the Idaho National Laboratory. The presented Cy-Phy ADS compared against six widely used unsupervised anomaly detection algorithms: One Class Support Vector Machine (OCSVM), Variational Autoencoder (VAE), LSTM Autoencoder (LSTM AE), Isolation Forest (IForest), Principle Component Analysis (PCA) and Local Outlier Factor (LOF). Here the presented approach showed the highest accuracy among the compared methods. Further, the proposed approach showed comparable performance in terms of precision, F1, and False positive rate. It also showed the lowest training and inference time compared to the neural network-based baseline algorithms compared against with. Additionally, the Cy-Phy ADS has advantages such as unsupervised training, the ability to provide a holistic metric for system health characterization, and non-linear feature extraction.

99 GENERAL AND MISCELLANEOUS↗

Analysis of a Runtime Data Sharing Architecture over LTE for a Heterogeneous CAV Fleet

This paper describes a lightweight runtime architecture for telemetry, communication, and control of cars deployed with advanced driver assistance systems where a human is in the loop with the car, via an LTE connection. The system architecture supports both local control decisions based on car sensors and safety algorithms as well as high-level input from external systems that may provide insight into traffic state ahead of sensor data. Implementation of the architecture is done in ROS and depends on open-source software packages for runtime decoding of information from the vehicle’s controller area network (CAN) and integration of GPS data from accompanying sensors. The contribution of the paper is to describe the overall architecture, the data it can communicate to other systems, performance of the system at runtime, and challenges faced when deploying the architecture across a heterogeneous fleet. Preliminary results from analysis of test data will provide insights into whether the use of high-latency communication can be effective for societal-scale intelligent transportation systems when applied in future scenarios

Richardson, Alex↗

Time-Based CAN IDS Paper Results Code

Modern vehicles are complex cyber-physical systems made of hundreds of electronic control units (ECUs) that communicate over controller area networks (CANs). This inherited complexity has expanded the CAN attack surface which is vulnerable to message injection attacks. These injections change the overall timing characteristics of messages on the bus, and thus, to detect these malicious messages, time-based intrusion detection systems (IDSs) have been proposed. However, time-based IDSs are usually trained and tested on low-fidelity datasets with unrealistic, labeled attacks. This makes difficult the task of evaluating, comparing, and validating IDSs. Here we detail and benchmark four time-based IDSs against the newly published ROAD dataset, the first open CAN IDS dataset with real (non-simulated) stealthy attacks with physically verified effects. We found that methods that perform hypothesis testing by explicitly estimating message timing distributions have lower performance than methods that seek anomalies in a distribution related statistic. In particular, these “distribution-agnostic” based methods outperform “distribution-based” methods by at least 55% in area under the precision-recall curve (AUC-PR). Our results expand the body of knowledge of CAN time-based IDSs by providing details of these methods and reporting their results when tested on datasets with real advanced attacks. Finally, we develop an after-market plug-in detector using lightweight hardware, which can be used to deploy the best performing IDS method on nearly any vehicle.

Moriano, Pablo [Oak Ridge National Lab. (ORNL), Oa↗

Algorithm for Calculating Mass of Gaseous Fuels in Enclosed Containers

This algorithm estimates the mass of gaseous fuels in enclosed tanks by utilizing measurements of pressure and temperature within the tank and leveraging thermodynamic relatio nships. For vehicle applications, information available on the vehicle's Controller Area Network bus is used to estimate tank size and gas properties.

Pamminger, Michael↗

CANRate

CANRate measures the maximum rate that CAN messages can be sent and received across a Controller Area Network.

Sikkema, IsaacCorwin (0000000263420286)↗

Driver Identification Dataset

The ORNL Driver Identification Dataset was created to collect and analyze driving behavior data from 50 different drivers. Each driver operated a 2014 Kenworth T270 Class 6 truck around Fort Collins, Colorado while various data sources recorded their driving behavior and vehicle performance. The dataset includes CANbus (Controller Area Network) data, GPS data, inertial measurement data, and biometric data from a heart rate monitor. A cyberattack was executed during each drive, which caused multiple dashboard warning lights to illuminate and set the tachometer and speedometer to zero, regardless of actual speed. The attack was stopped either after one minute or if the driver pulled over. By downloading the dataset, you agree to the following: 1) I will not use or disclose the data for any purpose other than Research as that term is defined in 10 CFR 745.102. 2) I will not, under any circumstances, request or accept private or linking identifiers for the data used. 3) I will not attempt to determine the identity of the individuals associated with the data. 4) I will use appropriate safeguards to prevent the use or disclose of the data for any purpose other than Research.

99 GENERAL AND MISCELLANEOUS↗

A comprehensive guide to CAN IDS data and introduction of the ROAD dataset

Although ubiquitous in modern vehicles, Controller Area Networks (CANs) lack basic security properties and are easily exploitable. A rapidly growing field of CAN security research has emerged that seeks to detect intrusions or anomalies on CANs. Producing vehicular CAN data with a variety of intrusions is a difficult task for most researchers as it requires expensive assets and deep expertise. To illuminate this task, we introduce the first comprehensive guide to the existing open CAN intrusion detection system (IDS) datasets. We categorize attacks on CANs including fabrication (adding frames, e.g., flooding or targeting and ID), suspension (removing an ID’s frames), and masquerade attacks (spoofed frames sent in lieu of suspended ones). We provide a quality analysis of each dataset; an enumeration of each datasets’ attacks, benefits, and drawbacks; categorization as real vs. simulated CAN data and real vs. simulated attacks; whether the data is raw CAN data or signal-translated; number of vehicles/CANs; quantity in terms of time; and finally a suggested use case of each dataset. State-of-the-art public CAN IDS datasets are limited to real fabrication (simple message injection) attacks and simulated attacks often in synthetic data, lacking fidelity. In general, the physical effects of attacks on the vehicle are not verified in the available datasets. Only one dataset provides signal-translated data but is missing a corresponding “raw” binary version. This issue pigeon-holes CAN IDS research into testing on limited and often inappropriate data (usually with attacks that are too easily detectable to truly test the method). The scarcity of appropriate data has stymied comparability and reproducibility of results for researchers. As our primary contribution, we present the Real ORNL Automotive Dynamometer (ROAD) CAN IDS dataset, consisting of over 3.5 hours of one vehicle’s CAN data. ROAD contains ambient data recorded during a diverse set of activities, and attacks of increasing stealth with multiple variants and instances of real (i.e. non-simulated) fuzzing, fabrication, unique advanced attacks, and simulated masquerade attacks. To facilitate a benchmark for CAN IDS methods that require signal-translated inputs, we also provide the signal time series format for many of the CAN captures. Our contributions aim to facilitate appropriate benchmarking and needed comparability in the CAN IDS research field.

97 MATHEMATICS AND COMPUTING↗

Time-Based CAN Intrusion Detection Benchmark

Modern vehicles are complex cyber-physical systems made of hundreds of electronic control units (ECUs) that communicate over controller area networks (CANs). This inherited complexity has expanded the CAN attack surface by the injection of malicious messages that vary their time-based characteristics. To detect these malicious messages, time-based intrusion detection systems (IDS) have been proposed. However, time-based IDS are usually trained and tested on low-fidelity datasets with unrealistic labeled attacks. This makes difficult the task of evaluating, comparing, and validating IDS. Here we detail and benchmark four time-based IDS in a dataset with real and advanced attacks. We found that methods with strong assumptions regarding the distribution of inter-arrival times have lower performance than distribution agnostic based methods. In particular, distribution agnostic based methods outperform distribution based methods at least on $55\%$ in area under the precision-recall (AUC-PR) curve. Our results expand the body of knowledge of CAN time-based IDS by providing details of these methods and reporting their results when tested on datasets with real and advanced attacks. We describe limitations, open challenges, and how lessons learnt from this research can inform the design of deployable time-based IDS in modern vehicles.

Blevins, Deborah↗

FleetREDI Dashboard Fleet DNA Data Summaries

Developing daily duty cycle summaries for every vehicle-day within NLR’s Fleet DNA database was a key output of the FleetREDI project. This project captured second-by-second GPS and controller area network (CAN) data on in-use medium- and heavy-duty fleet vehicles and then summarized the data to provide an overview of vehicle operation throughout the United States. These data summaries were then displayed in aggregated formats on the FleetREDI dashboard, where users can explore the data within Fleet DNA. Fleet DNA’s clearinghouse of commercial fleet vehicle operating data helps vehicle manufacturers and developers optimize vehicle designs and helps fleet managers choose advanced technologies for their fleets. This online tool, which provides data summaries and visualizations similar to real-world "genetics" for medium- and heavy-duty fleet vehicles, helps users understand the broad operational range of commercial vehicles across vocations and weight classes.

32 ENERGY CONSERVATION, CONSUMPTION, AND UTILIZATI↗

Driver Identification Midyear Report

First, we create a profile for each authorized driver based on their existing driving data. We then train a machine learning model on the driving data from this profile, yielding an individualized model for each driver. Finally during a drive, we pass the Controller Area Network (CAN) data to the model and authen ticate the driver’s identity in real-time. This verification or lack thereof could be used to alert supervisors of threats to their drivers or transported materials. Deviations from their normal driving behavior could indicate high-risk situations, medical events, or even insider threats.

98 NUCLEAR DISARMAMENT, SAFEGUARDS, AND PHYSICAL P↗

Recommendations for Secure Transport: Material Conveyance Physical Protection Technology

Nuclear material is at higher risk of theft and sabotage during transport than during any other phase of the nuclear fuel lifecycle. Nuclear materials are transported in the public domain where adversaries have an upper hand by taking advantage of the time and location of the theft or sabotage attempt. As such, even modest threat profiles for transport of nuclear and radioactive material can require substantial detection and delay measures to support timely response. Conveyance tracking augmented with technology that improves on-the-scene situational awareness at a remote monitoring center has been adopted as a de-facto standard approach for transportation security. At present, the extended tracking and situational awareness capabilities needed for a nuclear material shipment, as is provided by the purpose designed, Transportation – Security, Tracking and Reporting (T-STAR) System, do not exist in a single commercial off-the-shelf (COTS) solution. Typically, the COTS systems that excel in one area are deficient in other areas, presenting challenges to designing well-rounded, robust systems. Still, COTS solutions can offer the basic set of tracking and situational awareness capabilities by indicating last update time, current location, and route taken. By incorporating vehicle and driver performance measures via the vehicle’s controller area network (CAN bus) and video alongside other data streams allows telemetry and other shipment information to be assessed in novel ways.This paper describes the operation, capabilities and features of various conveyance protection systems and approaches, assesses emerging technologies and how they could be used through a unified interface, and enumerates additional ways to provide early detection using vehicle, onboard technologies, effective delay technologies and approaches and simple equipment to improve protection during transport.

Shannon, Michael↗

Harnessing the Power of AI: Status and Expansion of Current Domestic Transport Security Through Flexible Embedded Hardware

As applications of Artificial Intelligence (AI) continue to expand, there are increasing opportunities to leverage applied AI methodologies with mobile transportation focused embedded systems. Current applications of AI in transportation focus on a variety of areas, including fuel efficiency, safety, security, and other broad fields of optimization or detection. To leverage these AI workflows and methodologies in the field, teams must utilize complex embedded systems capable of implementing these AI-enabled algorithms in real-time. In this paper, we will investigate how these algorithms can be integrated into existing technologies leveraging vehicle data - such as the Controller Area Network Transport Security Tracking and Reporting Unit (C-STAR). The C-STAR technology is an embedded platform with onboard computation capable of running next generation algorithms in vehicle systems AI, such as preventative maintenance, driver authentication, and transport security. As deployed in the field, the C-STAR has a limited AI functionality –this paper will directly discuss how a device like C-STAR can be utilized and the advantages of integrating these new technologies. We will open with relevant background information and transportation projects that leverage AI, focusing specifically on those around transport security such as vehicle identification, anomaly detection, and deterrence. We will then extend this into potential opportunities and scaling for AI methodologies using platforms like the C-STAR. Finally, we will speak directly to the challenges of deploying AI-powered workflows, such as computing power needs, bandwidth, hallucinations, and other regulatory considerations.

Cook, Adian [ORNL] (ORCID:0000000160825395)↗

Commercialization of the Transportation-Security, Tracking, and Reporting System (T-STAR)

The Transportation-Security, Tracking, and Reporting System (T-STAR) was developed by the National Nuclear Security Administration, NA-21, Office of Radiological Security (ORS) to provide a transportation security system for detection and tracking during transport of Category 1 and Category 2 radiological material. Few off-the-shelf systems for conveyance tracking offer detection of a cargo compartment breach or a removal of the cargo. Systems that do offer this capability often require permanent installation through modifying of the conveyance itself. This is not sustainable in many countries where ORS is building use, storage, and transport security capacity. The development of T-STAR has moved from fielding robust prototypes deployed in countries ranging from North America, Latin America and Central Asia to a commercially produced product that can now be deployed to provide enhanced security during transit. Each prototype deployment resulted in important lessons learned, which informed the requirements for the final commercial product. T-STAR uses both cellular and Iridium satellite modems to provide redundant communications to provide the configuration, status, and alerts to a server monitoring the shipment, which is accessible using a multilanguage browser-based user interface. A wireless security system employing using Z-wave sensors for intrusion detection located in the conveyance provide low cost but effective solution for a wide range of conveyance types. Additional capabilities include the ability to monitor a vehicles’ CANBUS (Controller Area Network) system, an ethernet port for high throughput sensor information such as video cameras, and the ability to power and use advanced external sensor payloads. These features make the T-STAR a capable and expandable security gateway that can be deployed on a variety of conveyances from box trucks to open trailers. The ability to provide tracking, monitoring, and detection provide a key component in overall best practices designed to protect shipments of radioactive material.

Schultze, Michael [ORNL] (ORCID:0000000283205671)↗

The I-24 Trajectory Dataset

This dataset was created by recording CAN and GPS data from a single vehicle driving on I-24. The dataset includes values for Time, Velocity, Acceleration, Space Gap, Lateral Distance, Relative Velocity, Longitude GPS, Latitude GPS and more. This empirical dataset is useful for understanding/simulating real vehicle trajectories and vehicle controller performance.

controller area network↗