How GraMa works

Your car is full of small computers that talk to each other all the time, and they believe every message they hear. Someone who gets onto that network can make a lot of trouble. GraMa is a way of catching them, learned from many cars at once without collecting anyone's data. Everything below moves, and you can pause it, slow it down or play with it.

  1. 01Inside the car
  2. 02Attacks
  3. 03Windows
  4. 04Traffic as a map
  5. 05Reading the map
  6. 06Learning across cars
  7. 07Hacked cars
  8. 08An attacker who knows the defence
  9. 09The experiments

01Inside the car

A car has dozens of small computers, called ECUs. One runs the engine, one the brakes, one the dashboard, and so on. They all share one pair of wires, the CAN bus, and every message sent on it reaches every ECU.

A message is short: an ID that says what it is about, and up to 8 bytes of data. Nothing says who sent it and nothing checks it. If a message has the right ID, everyone believes it.

The box under the car lists the messages the way a mechanic's tool would show them: the time, the ID, and the bytes. Slow it down or pause it to read them.

The two coloured lines are the two wires of the bus. Each dot is a message on its way to every ECU. The IDs are real ones from the dataset; which box sends which ID is made up for the picture.

02Attacks

Plug a device into the car's diagnostic port, or take over one of its ECUs, and you can send messages of your own.

Flooding the bus (a denial of service) means sending one high-priority message over and over. Real messages keep losing the race for the wire, so they arrive late or not at all. Watch the engine's messages stop getting through.

Faking messages (spoofing) means sending made-up values. Here the attacker claims the car is doing 213 km/h, and the dashboard shows it.

The red messages in the list are real attack messages from the dataset. Notice that their IDs never show up in normal driving.

How busy the bus is
Engine messages getting through
Dashboard shows
62 km/h

03Windows

GraMa doesn't judge one message at a time; a single message rarely tells you much. It looks at chunks of 64 messages, called windows. Each window starts 32 messages after the one before, so they overlap.

Then it looks at 8 windows in a row, 288 messages, which is a fraction of a second of traffic. If the newest window has attack messages in it, that stretch counts as an attack. In this example the attack starts near the end.

Each thin bar is one message, and the red ones are the attacker's. The bracket is the window being read.

04Traffic as a map

Each window is turned into a little map. Every ID that appeared becomes a dot, and two dots are joined when one message came right after the other. Normal driving has a steady rhythm, so the map looks much the same from one window to the next.

An attacker breaks the rhythm. Their fake ID turns up as a new dot in the middle, joined to everything around it.

Each dot also carries a few numbers about itself: the average of each of its 8 bytes in this window, how much of the window it took up, and whether it was unusually busy. Click a dot to see them.

    Click a dot to see its numbers.

    Real windows have 64 messages; this one shows 16 so you can follow it.

    05Reading the map

    The maps are read in two steps.

    First, graph attention looks at each map on its own. Every dot checks its neighbours and decides which of them matter most, and then the whole map is boiled down to one short summary of that window. A dot that doesn't belong stands out.

    Second, Mamba reads the 8 summaries in order, the way you read sentences one after another, keeping a running memory as it goes. That is how it notices a problem that builds up over several windows.

    At the end it gives its answer: normal, or which kind of attack. The whole model is about 300 KB, small enough for a car.

    06Learning across cars

    One car only sees its own traffic. To learn from many cars without collecting what they recorded, GraMa uses federated learning. In each round some cars train the detector on their own traffic and send back only what changed in the model, never the traffic itself. The server combines those changes and sends the improved detector to every car.

    Cars don't all see the same things. One might mostly see normal driving, another might have been attacked a lot. The slider changes how different the cars are. Far to the left, each car sees mostly one kind of traffic, and learning gets harder.

    07Hacked cars

    There's a catch. A hacked car can send back a poisoned change on purpose, to quietly break everyone's detector. The experiments try five tricks: training on wrong answers, teaching the model that attacks are normal, making the change ten times bigger, a small, sneaky push that hides among the honest changes (known as ALIE), and an attacker who knows how the defence works (the next section).

    The server can protect itself in different ways. Plain averaging lets everything in. Clipping shrinks any change that is too big. FLAME groups the changes by direction and trims them. GraMa's defence puts all the changes on a small map, finds the tight group of honest cars, and leaves out the ones far away from it.

    Try it below: pick an attack, a defence and how many cars are hacked. It's a flat, simplified picture; a real change has about 78,000 numbers in it.

    3 of 10
    honest car hacked car where the honest cars point where the server ends up

    08An attacker who knows the defence

    The hardest attacker to stop knows exactly how the server protects itself.

    Think of each car's change as a package it sends to the server. A hacked car's package carries poison, shown in red. The server checks every package at a checkpoint, its defence, and turns away the ones that look wrong.

    The hacked cars build a copy of that checkpoint. Before sending anything, they test their package on the copy. If it is turned away, they water the poison down and test again. If it gets through, they add a little poison back. After seven tests they send the strongest package that got through.

    So some poison always reaches the server. A defence holds up only if the poison that gets past it is too weak to do real harm.

    09The experiments

    The experiments ask a few plain questions. Does GraMa catch attacks as well as an older kind of detector, a CNN-BiGRU? How much does it hurt when the cars see very different traffic? Which defence holds up best as more cars are hacked? Which parts of GraMa actually matter? Is it small and quick enough for a car? And does a defence still hold up when the attacker knows exactly how it works?

    The dataset needed care. Each attack file is a few messages repeated thousands of times, and two of the files change partway through. Testing only on the end of each file would test on messages the model never saw. So the test messages are slices taken from all along each file.

    RecordingMessagesDifferent onesIDs used
    normal driving1,223,7373,54772 different IDs
    flooding (DoS)74,66321291
    fake gas pedal9,9912513
    fake RPM54,90010476, then 513 for the last 36%
    fake speed24,9515344, then 513 for the last 20%
    fake steering19,9773128