Failure paths in connected vehicle fleets
Connected vehicles act on each other's broadcasts, so one corrupted message can spread. A car that brakes because of a spoofed hazard becomes, to the cars behind it, a real hazard. We predict, detect, and contain that cascade at runtime.
The idea
At each control step we draw the fleet as a directed graph of who can
influence whom: an edge u→v when u leads v within V2V range in the same
or an adjacent lane. Each edge carries the probability that the follower acts
on the leader’s broadcast — high when tailgating, low when hanging back:
p_uv = P_MAX * exp(-max(0, THW_uv - THW0) / LAM)
Weighting each edge by -log(p_uv) turns the most likely failure chain into
a shortest path. Because the graph changes every step, paths are found on a
time-expanded DAG over the trailing window of the last H snapshots, which
keeps cause before effect. A runtime monitor scores risk with one multi-source
Dijkstra pass per step — 0.2–1.3 ms for 10–60 vehicles on a single core —
and quarantines vehicles when risk exceeds a threshold tau.
What we found
Three simulators, one model, identical constants throughout.
highway-env gives the clean attribution design: the baseline has exactly
zero collisions, so every collision is attributable to the attack. One spoofer
drives P(coll) from 0 to 0.86, and the monitor’s fail-safe is monotone in
tau — a resolved availability–safety frontier.
The headline is an ablation we did not expect:
Path reasoning buys availability, not safety. Quarantine-on-sight reaches P(coll) 0.000 but fires 22.1 false quarantines per episode. The path monitor reaches 0.035 at 8.1 — roughly 3× fewer disruptions — while a path-only quarantine policy fails outright at 0.79.
We keep the negative results too: the argmax path matches the realized failure chain only 12–14% of the time. The score predicts; the specific path does not.
SUMO also produced an honest non-replication: detection time is flat in
H. The spoofer spawns adjacent to the critical set, so there is no
propagation distance for lookahead to anticipate. The value of lookahead is a
property of threat geometry, not of the method.
Where the design breaks
Under full dynamics the attribution design does not transfer. CARLA’s nominal traffic is not collision-free in a dense platoon, and the baseline collision rate sits above the attack arm with heavily overlapping intervals:
| arm | n | P(coll) | min TTC | compromised | MRMs |
|---|---|---|---|---|---|
| baseline | 30 | 0.27 | 1.56 | 0.0 | 0.0 |
| attack | 30 | 0.17 | 1.52 | 11.9 | 0.0 |
| fail-safe τ=0.05 | 30 | 0.10 | 1.68 | 0.0 | 27.0 |
| fail-safe τ=0.20 | 30 | 0.20 | 1.58 | 0.5 | 21.7 |
So CARLA’s collision column is never attack-attributable, and we do not treat it as such. The interpretable signals are the mechanism metrics: the attack compromises about 12 of 30 vehicles in every run, and the τ=0.05 fail-safe empties the compromised set completely.
Get the code
Everything — model, monitor, all three experimental harnesses, and the run data behind every number above — is on GitHub under an MIT license. Full-resolution videos are attached to the latest release.
The accompanying paper is under review; citation details will appear here on acceptance.