Failure paths in connected vehicle fleets

Connected vehicles act on each other's broadcasts, so one corrupted message can spread. A car that brakes because of a spoofed hazard becomes, to the cars behind it, a real hazard. We predict, detect, and contain that cascade at runtime.

A single spoofed broadcast cascading backwards through a highway-env platoon
A single spoofer (dark red) compromises 26 of 31 vehicles as the false hazard propagates backwards through the platoon.

The idea

At each control step we draw the fleet as a directed graph of who can influence whom: an edge u→v when u leads v within V2V range in the same or an adjacent lane. Each edge carries the probability that the follower acts on the leader’s broadcast — high when tailgating, low when hanging back:

p_uv = P_MAX * exp(-max(0, THW_uv - THW0) / LAM)

Weighting each edge by -log(p_uv) turns the most likely failure chain into a shortest path. Because the graph changes every step, paths are found on a time-expanded DAG over the trailing window of the last H snapshots, which keeps cause before effect. A runtime monitor scores risk with one multi-source Dijkstra pass per step — 0.2–1.3 ms for 10–60 vehicles on a single core — and quarantines vehicles when risk exceeds a threshold tau.

What we found

Three simulators, one model, identical constants throughout.

highway-env gives the clean attribution design: the baseline has exactly zero collisions, so every collision is attributable to the attack. One spoofer drives P(coll) from 0 to 0.86, and the monitor’s fail-safe is monotone in tau — a resolved availability–safety frontier.

The headline is an ablation we did not expect:

Path reasoning buys availability, not safety. Quarantine-on-sight reaches P(coll) 0.000 but fires 22.1 false quarantines per episode. The path monitor reaches 0.035 at 8.1 — roughly 3× fewer disruptions — while a path-only quarantine policy fails outright at 0.79.

We keep the negative results too: the argmax path matches the realized failure chain only 12–14% of the time. The score predicts; the specific path does not.

SUMO attack run SUMO fail-safe run
SUMO, 3 lanes, 50 seeds. Left: the attack stalls the corridor. Right: quarantine empties the compromised set and restores throughput from 10.3 to 30 vehicles entered — the denial-of-service framing.

SUMO also produced an honest non-replication: detection time is flat in H. The spoofer spawns adjacent to the critical set, so there is no propagation distance for lookahead to anticipate. The value of lookahead is a property of threat geometry, not of the method.

Where the design breaks

CARLA attack, chase view CARLA attack, top-down view
CARLA Town04, asynchronous, 30 vehicles, 30 valid runs per arm.

Under full dynamics the attribution design does not transfer. CARLA’s nominal traffic is not collision-free in a dense platoon, and the baseline collision rate sits above the attack arm with heavily overlapping intervals:

armnP(coll)min TTCcompromisedMRMs
baseline300.271.560.00.0
attack300.171.5211.90.0
fail-safe τ=0.05300.101.680.027.0
fail-safe τ=0.20300.201.580.521.7

So CARLA’s collision column is never attack-attributable, and we do not treat it as such. The interpretable signals are the mechanism metrics: the attack compromises about 12 of 30 vehicles in every run, and the τ=0.05 fail-safe empties the compromised set completely.

Get the code

Everything — model, monitor, all three experimental harnesses, and the run data behind every number above — is on GitHub under an MIT license. Full-resolution videos are attached to the latest release.

The accompanying paper is under review; citation details will appear here on acceptance.