GAN-CAN: A Novel Attack to Behavior-Based Driver Authentication Systems

06/09/2023
by   Emad Efatinasab, et al.
0

For many years, car keys have been the sole mean of authentication in vehicles. Whether the access control process is physical or wireless, entrusting the ownership of a vehicle to a single token is prone to stealing attempts. For this reason, many researchers started developing behavior-based authentication systems. By collecting data in a moving vehicle, Deep Learning (DL) models can recognize patterns in the data and identify drivers based on their driving behavior. This can be used as an anti-theft system, as a thief would exhibit a different driving style compared to the vehicle owner's. However, the assumption that an attacker cannot replicate the legitimate driver behavior falls under certain conditions. In this paper, we propose GAN-CAN, the first attack capable of fooling state-of-the-art behavior-based driver authentication systems in a vehicle. Based on the adversary's knowledge, we propose different GAN-CAN implementations. Our attack leverages the lack of security in the Controller Area Network (CAN) to inject suitably designed time-series data to mimic the legitimate driver. Our design of the malicious time series results from the combination of different Generative Adversarial Networks (GANs) and our study on the safety importance of the injected values during the attack. We tested GAN-CAN in an improved version of the most efficient driver behavior-based authentication model in the literature. We prove that our attack can fool it with an attack success rate of up to 0.99. We show how an attacker, without prior knowledge of the authentication system, can steal a car by deploying GAN-CAN in an off-the-shelf system in under 22 minutes.

READ FULL TEXT

page 9

page 12

research
11/22/2019

This Car is Mine!: Automobile Theft Countermeasure Leveraging Driver Identification with Generative Adversarial Networks

As a car becomes more connected, a countermeasure against automobile the...
research
08/25/2020

An Adversarial Attack Defending System for Securing In-Vehicle Networks

In a modern vehicle, there are over seventy Electronics Control Units (E...
research
01/23/2018

Who Killed My Parked Car?

We find that the conventional belief of vehicle cyber attacks and their ...
research
11/19/2019

Driver Identification Based on Vehicle Telematics Data using LSTM-Recurrent Neural Network

Despite advancements in vehicle security systems, over the last decade, ...
research
12/16/2022

Conditional Generative Adversarial Network for keystroke presentation attack

Cybersecurity is a crucial step in data protection to ensure user securi...
research
07/07/2023

Generation of Time-Varying Impedance Attacks Against Haptic Shared Control Steering Systems

The safety-critical nature of vehicle steering is one of the main motiva...
research
02/07/2019

Shoulder Surfing: From An Experimental Study to a Comparative Framework

Shoulder surfing is an attack vector widely recognized as a real threat ...

Please sign up or login with your details

Forgot password? Click here to reset