When Authentication Is Not Enough: Breaking Behavior-Based Driver Authentication Systems
Listen
Radio episode about this paper
Transcript
Introduction to the show: ident: Security Radio. Generated commentary on the latest security and cryptography papers.
Nadia: Today's paper: "When Authentication Is Not Enough".
Elias: This paper addresses critical security and practical implementation gaps in existing behavioral-based driver authentication systems, which are increasingly driven by Artificial Intelligence (AI) for enhanced vehicle security.
Nadia: First, who's behind it and why it matters.
Title and authors: Nadia: Let's talk about the title and authors of this paper, "When Authentication Is Not Enough: Breaking Behavior-Based Driver Authentication Systems." It really sets a tone that we need to rethink how we approach vehicle security when AI is involved in driver identification.
Elias: And the authors—Efatinasab, Marchiori, Donadel, Brighente, and Conti—they come from strong mathematical and engineering backgrounds at places like the University of Padua and Delft University of Technology. That suggests a very solid foundation in both the theoretical modeling of systems and the practical implementation challenges.
Priya: I'm curious about what this title implies for our field; it seems to suggest that current behavioral systems are insufficient because they overlook critical security aspects related to how they interact with the vehicle itself.
Nadia: Precisely, Priya; it points out that focusing only on the AI's ability to recognize behavior without considering its connection to the network creates a major vulnerability for real-world deployment.
Elias: From a cryptographic viewpoint, I see this as a warning that we can't just build an accurate model and assume security is handled; we need security measures baked into the system design from the start.
The paper's summary: Nadia: So, to summarize what they propose in "When Authentication Is Not Enough: Breaking Behavior-Based Driver Authentication Systems," they are introducing the first security-aware system model for behavioral-based driver authentication and identification systems.
Elias: They build on this by developing two lightweight architectures, a Random Forest and a single-layer Gated Recurrent Unit, which they claim can achieve an accuracy of up to zero point nine nine nine on real driving data while being compatible with commercial vehicle networks.
Priya: The summary mentions how they collect data directly from the CAN bus, but I want to know more about the specific aggregation techniques they use for those time windows, as that affects what kind of behavioral patterns are actually being analyzed.
Nadia: They describe collecting data periodically, using sixteen-second time windows with an eight-second step size for DL models, which then get batched into groups of four to generate a prediction every forty seconds, or for the classical ML architecture they predict for each collected sample every second.
Elias: That distinction between those two data processing methods is important because it shows they've considered different ways to handle sequential versus static data within their models.
The paper's improvements: Nadia: Moving into the improvements, the authors aren't just proposing new algorithms; they are suggesting a whole new security-aware system model that accounts for deployment in real-world automotive contexts.
Elias: They formalize a realistic vehicle network threat model, which involves considering how an attacker could physically access the CAN bus and inject malicious packets because they note that broadcast nature without encryption makes it simple to intercept messages twenty-nine.
Priya: That threat model is pretty sobering; it means they have to contend with attackers who can physically plug into the vehicle and try to interfere with those messages, which moves us closer to real-world vulnerability testing.
Nadia: And on the security side, they introduce two novel evasion attacks: SMARTCAN, which uses a smart-replay attack by replaying legitimate traffic using only modifiable features while stealing the car, and GANCAN, which uses Reinforcement Learning to craft fake packets starting from noise.
Elias: Those attacks are compelling because they show that even with their sophisticated models, there's still a way for an attacker to succeed by targeting what the model is trained on versus what it isn't.
Conclusion: Nadia: So, wrapping up the discussion on "When Authentication Is Not Enough: Breaking Behavior-Based Driver Authentication Systems," the main implication is that behavioral systems need to be implemented as ECUs directly on the CAN bus to reduce tampering risks from malicious parties.
Elias: I think it’s also crucial to integrate robust CAN message authentication protocols, like AUTOSAR SecOC, as a fundamental layer of security underneath any behavioral pattern recognition.
Priya: From a privacy angle, the paper emphasizes that they are developing systems that focus on privacy-preserving model training and deployment, which is vital since they are dealing with sensitive driving behavior data.
Nadia: And for us in terms of practical application, the authors introduce a concept called "combinatorial accuracy," which reduces false positive alerts by waiting for multiple consecutive decisions before triggering a notification.
Elias: That combinatorial accuracy is interesting because it lowers the probability of false alarms at the cost of a couple of seconds of delay, which is a trade-off we have to consider when designing safety systems.
Priya: I think that trade-off between reducing false positives and introducing latency is something engineers will have to weigh carefully when they implement these models in actual vehicles.
Nadia: Well, this paper lays down the groundwork for making behavioral authentication more secure by developing the first security-aware system model and showing how to build defenses against evasion attacks like SMARTCAN and GANCAN.
Elias: It shows that simply having a high accuracy score isn't enough; the security context around the AI is what truly matters for adoption.
Priya: We definitely need to keep watching these kinds of works because addressing the implementation gaps between research and practice is where the most important progress for real-world safety will happen.
Department of Mathematics University of Padua · Faculty of Electrical Engineering, Mathematics and Computer Science Delft University of Technology
cs.CR
Submitted: 2023-06-09
Updated: 2026-09-30
Journal ref: European Symposium on Research in Computer Security (ESORICS 2026), 2026, Lecture Notes in Computer Science, vol 16968
DOI: 10.1007/978-3-032-38692-2_30
Code: https://github.com/commaai/opendbc
Project page: https://kentindell.github.io/2023/04/03/can-injection
License: http://creativecommons.org/licenses/by-nc-nd/4.0/
Importance score: 78/100
The gist: This paper addresses critical security and practical implementation gaps in existing behavioral-based driver authentication systems, which are increasingly driven by Artificial Intelligence (AI) for
Key concepts
- Behavioral-Based Driver Authentication Systems
- These are systems that use Artificial Intelligence to identify drivers based on their driving behavior. The paper focuses on the security gaps in these systems when they interact with vehicle networks.
- CAN bus
- The CAN bus is a network used within vehicles. The paper discusses collecting data directly from this bus, noting that broadcast nature without encryption makes it vulnerable to interception.
- Combinatorial Accuracy
- This is a concept introduced to reduce false positive alerts. It involves waiting for multiple consecutive decisions before triggering an alert, which lowers the probability of false alarms but introduces a delay.
- Evasion Attacks (SMARTCAN and GANCAN)
- These are novel attacks that show sophisticated models can still be bypassed. SMARTCAN uses smart-replay to steal a car by replaying legitimate traffic, while GANCAN uses Reinforcement Learning to craft fake packets from noise.
Terminology
Summary
This paper addresses critical security and practical implementation gaps in existing behavioral-based driver authentication systems, which are increasingly driven by Artificial Intelligence (AI) for enhanced vehicle security. While these models propose powerful methods to identify drivers through unique biometric behavior, they have been insufficiently scrutinized from a security perspective regarding their connection to vehicle networks and vulnerability to adversarial attacks. The authors bridge this gap by proposing the first security-aware system model for behavioral-based driver authentication, developing lightweight architectures and novel evasion attacks, thereby aiding practitioners in safely adopting these systems.
System Model and Architectures
The research proposes two lightweight driver authentication systems designed for constrained environments: a Random Forest (RF) architecture and a single-layer Gated Recurrent Unit (GRU) architecture. These models are engineered to be efficient while outclassing the state-of-the-art, achieving an accuracy of up to 0.999 on real driving data. The system model formalizes a realistic vehicle network threat model, focusing on the security implications of deploying these systems within a real-world automotive context.
The key components of the proposed system model include:
((
(1) We propose the first security-aware system model for behavioral-based driver identification and authentication. Based on our design, we develop two new lightweight behavior-based driver authentication and identification systems whose requirements are compatible with commercial vehicle networks. Our two proposed architectures, i.e., a Random Forest (RF) and a single-layer Gated Recurrent Unit (GRU), are designed to be efficient in a realistic system model and outclass the state-of-the-art, achieving an accuracy of up to 0.999.
Data Collection and Processing
The data collection technique involves retrieving messages directly from the CAN bus, assuming the authenticator has already been equipped with the necessary information to decode messages and know which IDs are associated with which ECUs. Data is collected periodically:
-
For DL models leveraging causality between samples, data is aggregated in time windows of 16 seconds with a step size of 8. Time windows are then aggregated in batches with a size of 4, resulting in a prediction every 40 seconds.
-
For classical ML architecture, a prediction is generated for each collected sample (i.e., each second).
The dataset utilized is the widely adopted OCSLab dataset, which comprises 94,380 data points from 10 different drivers and 54 distinct features extracted from CAN bus messages. Preprocessing steps include normalization and undersampling to rebalance class distribution.
Threat Model and Evasion Attacks
The paper introduces a realistic threat model where potential attackers can physically access the vehicle’s CAN bus network, deploying a covert malicious device to inject packets. The attacker is assumed to know the DBC file of the vehicle and the features used by the authentication model. To mitigate safety risks, only 22 out of 46 features are identified as modifiable without affecting vehicle behavior (e.g., engine coolant temperature, intake air pressure).
Two novel evasion attacks are proposed:
-
SMARTCAN: This attack assumes the attacker has access to legitimate user data but not the authenticator model implementation. It uses a
smart-replay attack
by replaying legitimate traffic using only modifiable features while stealing the car, allowing authentication despite interference in driving safety. -
GANCAN: This attack assumes the attacker has access to the authenticator model response but not legitimate driving behavior. It employs Reinforcement Learning (RL) to optimize a generator that crafts legitimate fake packets starting from noise, overwriting only modifiable features while non-modifiable and borderline features are extracted from the attacker’s own driving behavior.
Evaluation and Key Findings
The systems were evaluated using True Positive (TP), False Positive (FP), False Negative (FN), and True Negative (TN) metrics, along with Accuracy, F1 score, and Attack Success Rate (ASR).
(2) We introduce SMARTCAN and GANCAN, the first attacks against behavioral-based driver authentication and identification systems. Our attacks use evasion techniques to avoid detection and only inject minimal amounts of data to preserve driving functions while achieving success rates of up to 1.000.
Baseline evaluations showed that our models can outclass the state-of-the-art, with the RF model achieving an accuracy of up to 0.998 in identification and authentication. The paper introduces combinatorial accuracy,
a concept that reduces false positive alerts by waiting for multiple consecutive decisions before triggering a notification, which significantly lowers the probability of false alarms at the cost of a couple of seconds of delay.
Takeaways for Practitioners
The paper concludes with five key takeaways aimed at bridging the gap between research and practice:
-
Behavioral-based driver authentication systems should be implemented as ECUs in the CAN bus to reduce the probability of tampering from malicious parties.
Improvements for AI systems
Based on the provided research paper, here are specific improvements that can be made to existing behavioral-based driver authentication systems, and what those improved AI systems could achieve:
I. System Architecture and Deployment Improvements (Addressing RQ1 & RQ4)
-
A paradigm shift in deployment from external OBD-II port devices to an integrated ECU implementation directly on the CAN bus.
-
Integration of a robust CAN message authentication protocol (e.g., leveraging AUTOSAR SecOC) as a fundamental layer of security for all vehicle network communications, rather than relying solely on behavioral pattern recognition for security.
-
The AI system will transition from being just an identification tool to acting as a continuous, real-time anomaly detection and intrusion prevention system embedded within the vehicle's control logic.
-
By implementing this architecture, the AI system can achieve:
-
Continuous, tamper-resistant monitoring of driver behavior at the lowest possible network level without requiring external hardware access or relying on vulnerable external ports like OBD-II.
II. Model Architecture and Efficiency Improvements (Addressing RQ2)
-
The adoption of lightweight, resource-efficient architectures, specifically favoring single-layer Gated Recurrent Unit (GRU) networks over deeper or more complex models, while retaining high accuracy (up to 0.999).
-
Implementation of specialized feature selection techniques using Explainable AI (XAI) methods like SHAP values to dynamically identify and prioritize the most critical CAN features for authentication, reducing computational load without sacrificing security.
-
The improved system will be able to:
-
Provide high-accuracy driver identification and authentication in real-time on resource-constrained in-vehicle ECUs (like a Raspberry Pi 4B), ensuring continuous operation without constant reliance on cloud resources or powerful external GPUs.
-
Ensure user privacy by mandating local training and inference, meaning sensitive driving behavior data never leaves the vehicle's secure environment.
III. Robustness Against Adversarial Attacks (Addressing RQ4)
-
The system must be hardened against evasion attacks such as SMARTCAN (data replay) and GANCAN (model poisoning/generation).
-
The improved AI will incorporate adversarial training techniques, optimizing the generator models to bypass fixed discriminators rather than relying on simple incremental training, thereby increasing resilience against sophisticated data manipulation.
-
This hardened system will be able to:
-
Maintain a near-perfect security posture (ASR close to 1.0) even when an attacker has knowledge of the target model or data (GANCAN scenario), ensuring that malicious packet injection is infeasible or extremely time-consuming (requiring significant offline training time).
-
The system will be able to:
-
Detect and mitigate attempts to impersonate legitimate drivers by analyzing feature interactions and temporal dependencies, distinguishing between genuine behavioral evolution and malicious data injections.
IV. Operational Reliability and Usability Improvements (Addressing RQ3)
-
The implementation of a
Combinatorial Accuracy
mechanism, using the geometric distribution formula to require multiple consecutive unauthorized batch detections before triggering an alert. -
The improved system will be able to:
-
Drastically reduce false positive rates (dropping by orders of magnitude) while maintaining high security, providing a fair trade-off between safety alerts and user experience.
-
The final system will be capable of:
-
Providing actionable, low-false-alarm notifications to the vehicle owner only after multiple independent behavioral anomalies are confirmed, ensuring that legitimate drivers have an uninterrupted driving experience while still protecting the vehicle from theft or misuse.
V. Strategic Positioning Improvements (Addressing RQ5)
-
The system will be strategically positioned as a second-factor continuous authentication mechanism layered on top of traditional physical keys, rather than replacing them as the sole means of access.
-
The improved AI system will be capable of:
-
Detecting and reporting unauthorized use or theft attempts even after an initial breach (e.g., key compromise), acting as a persistent security layer that monitors driving state for potential fraud or unauthorized operation, thereby enhancing overall vehicle security posture without sacrificing the convenience of physical access.
Abstract
Researchers extensively explored behavior-based driver authentication systems in vehicles. Pushed by advances in Artificial Intelligence (AI), these systems employ powerful models to identify drivers based on unique biometric behaviors. However, existing work prioritizes AI performance metrics, neglecting secure integration with real-world automotive environments and the threat of adversarial attacks that can fool the authentication system. In this paper, we propose for the first evasion attacks against behavior-based driver authentication systems, allowing an attacker to impersonate the legitimate driver. Our attacks exploit long-standing CAN bus weaknesses that allow the injection of forged frames without jeopardizing the attacker's safety while stealing the vehicle. When legitimate data samples are available, we propose SMARTCAN, a safety-aware replay attack. If the attacker can only use the authenticator as an oracle, we propose GANCAN, which trains a Generative Adversarial Network's generator using reinforcement learning on the authenticator's responses. Our attacks achieve a success rate up to 100% against all the considered models and, in the worst case, require 22 minutes to steal a vehicle. Acknowledging our identified vulnerabilities, we discuss the requirements for a safe and effective deployment of these systems in real-world scenarios.
Sources
- How Deep Are the Fakes? Focusing on Audio Deepfake: A Survey
- Automobile Theft Detection by Clustering Owner Driver Data
- Driver Identification via the Steering Wheel
- This Car is Mine!: Automobile Theft Countermeasure Leveraging Driver Identification with Generative Adversarial Networks
- A Survey and Comparative Analysis of Security Properties of CAN Authentication Protocols
Related papers
- SoK: AI-Augmented Binary Reversing
- Relaxed Sender Anonymity for CBDC Interbank Settlement: A Zero-Knowledge Approach on Permissioned EVM
- Calibration-Family Overfit: Why Trusted Sabotage Monitors Don't Transfer Across Lineages
- Efficient Fuzzy PSI under One-Sided Assumptions
- Sealing the Audit-Runtime Gap for LLM Skills
- Token Composition: A Graph Based on EVM Logs