Redefining V2G: How to use your vehicle as game controller
Timm Lauser, Jannis Hamborg
DEF CON 32 Main Stage · Day 1 · Main Stage
Overview
In a captivating presentation at DEF CON 32, Timm Lauser and Jannis Hamborg from Darmstadt University of Applied Sciences introduced a novel interpretation of the widely recognized acronym V2G. Traditionally standing for "Vehicle to Grid" communication, a critical component of smart energy infrastructure involving bidirectional charging and power grid interaction, Lauser and Hamborg playfully redefined it as "Vehicle to Game." This talk delved into their academic project designed to demystify complex automotive security concepts and motivate students through a hands-on approach: transforming a modern electric vehicle into an interactive game controller.

Key moments
- 0:00 Introduction: Redefining V2G from grid to game controller
- 1:10 Speakers introduce their automotive security research focus
- 2:10 Motivating students with their Volkswagen ID3 research car
- 2:50 Comprehensive overview of automotive attack vectors and surfaces
- 4:10 Practical research using Volkswagen ID3 and Tesla Model 3
- 5:20 Detailed in-car measurement setup with Vector boxes
- 6:20 Goal: Correlating physical vehicle data with bus messages
Redefining V2G: How to use your vehicle as game controller
Speakers: Timm Lauser, PhD Student, Darmstadt University of Applied Sciences; Jannis Hamborg, PhD Student, Darmstadt University of Applied Sciences
Conference: DEF CON 32
YouTube: https://www.youtube.com/watch?v=Dh220NQIkaQ
Overview
In a captivating presentation at DEF CON 32, Timm Lauser and Jannis Hamborg from Darmstadt University of Applied Sciences introduced a novel interpretation of the widely recognized acronym V2G. Traditionally standing for "Vehicle to Grid" communication, a critical component of smart energy infrastructure involving bidirectional charging and power grid interaction, Lauser and Hamborg playfully redefined it as "Vehicle to Game." This talk delved into their academic project designed to demystify complex automotive security concepts and motivate students through a hands-on approach: transforming a modern electric vehicle into an interactive game controller.
The core of their research lies in exploring the extensive attack surface of contemporary vehicles, moving beyond theoretical analyses to practical, real-world data acquisition and manipulation. By focusing on the internal bus systems and electrical signals of a Volkswagen ID3, the team demonstrated how intricate vehicle data can be extracted and repurposed for unconventional applications. This innovative project serves as both an educational tool and a testament to the myriad possibilities—and potential vulnerabilities—inherent in increasingly connected and computerized automobiles.
This redefinition of V2G highlights the evolving landscape of automotive technology, where vehicles are no longer mere modes of transport but complex, networked systems. The researchers' work underscores the critical importance of understanding these systems from a security perspective, not just for protecting against malicious attacks but also for fostering innovation and education within the cybersecurity community.
Background
▶ Watch: Introduction: Redefining V2G from grid to game controller (0:00)
The automotive industry is undergoing a profound transformation, moving towards highly connected, autonomous, and electric vehicles. This evolution, while promising enhanced safety, efficiency, and convenience, simultaneously introduces an unprecedented array of attack vectors and security challenges. Traditionally, academic research in Vehicle-to-Grid (V2G) communication has focused on the secure and efficient exchange of data between electric vehicles, charging infrastructure, and the power grid. This domain is crucial for enabling smart charging, demand response, and integrating renewable energy sources. However, the inherent complexity and proprietary nature of modern vehicle systems often create a barrier for new researchers and students seeking to engage with automotive security.
Recognizing this challenge, Timm Lauser and Jannis Hamborg, both PhD students at the ACSD (Automotive Cyber Security Darmstadt) research group in Germany, sought a more engaging and accessible entry point into the field. Their motivation stemmed from a desire to make automotive research "beginner friendly" and "motivating" for students, moving beyond purely theoretical discussions to hands-on experimentation. The problem they aimed to address was the lack of practical, relatable projects that could excite students about the intricacies of automotive cyber security. Manufacturers are often opaque about the internal workings and data flows of their vehicles, making independent research difficult without significant investment in reverse engineering and specialized tools.
Their approach involved shifting the focus from the abstract concept of V2G (Vehicle to Grid) to a tangible, interactive concept: V2G (Vehicle to Game). This redefinition provided a playful yet profound framework for exploring the same underlying security principles and data extraction techniques. By framing the vehicle as a "game controller," the project immediately appealed to a broader audience, demonstrating that the data streams within a car—such as speed, steering angle, acceleration, and braking inputs—are not only accessible but also manipulable for purposes beyond their original design. This practical, project-based learning environment aimed to expose students to the vast attack surface of modern cars, encompassing everything from long-range wireless communications to the intricate physical bus systems that govern internal operations, thereby fostering a deeper understanding of automotive security vulnerabilities and mitigation strategies.
Key Findings
▶ Watch: Motivating students with their Volkswagen ID3 research car (2:10)
The primary finding of Lauser and Hamborg's "Vehicle to Game" project is the demonstrable feasibility and educational value of transforming complex automotive data streams into accessible, interactive inputs. They successfully showcased that modern electric vehicles, specifically their Volkswagen ID3 research car, provide a rich source of real-time operational data that can be extracted and repurposed for novel applications. This capability underscores a significant aspect of automotive security: if data can be extracted and reinterpreted for a game, it can also be extracted and potentially manipulated for malicious purposes, highlighting critical vulnerabilities in vehicle architectures.
A key contribution of their work is the emphasis on a holistic view of vehicle data acquisition. By equipping their research cars with a comprehensive suite of measurement techniques, including Vector boxes for capturing internal bus communications and clamp sensors for monitoring high-voltage system currents, they established a methodology for correlating physical electrical measurements with digital bus messages. This correlation is vital for understanding the true behavior of vehicle systems, as manufacturers often do not disclose internal specifications. This hands-on approach proved invaluable for students, allowing them to bridge the gap between theoretical knowledge and practical application, identifying how physical actions (like pressing the accelerator) translate into specific digital signals on the car's internal networks.
Furthermore, the project highlighted the extensive and multifaceted attack surface of modern vehicles. While their V2G project focused on physical access to internal bus systems, their broader discussion outlined other critical areas, including long-range attacks (cellular communication for Over-The-Air updates, V2X communication for vehicle-to-vehicle or vehicle-to-infrastructure interactions) and short-range attacks (Bluetooth, Wi-Fi for infotainment systems). The success in extracting data from the physical bus systems for the "game controller" concept serves as a compelling proof point for the potential for similar unauthorized data access or control compromise across these diverse attack vectors. Ultimately, their research provides a strong argument for the necessity of practical, hands-on automotive security research, not only for identifying vulnerabilities but also for cultivating the next generation of cybersecurity professionals in this rapidly evolving domain.
Technical Deep Dive
▶ Watch: Comprehensive overview of automotive attack vectors and surfaces (2:50)
The "Redefining V2G" project by Timm Lauser and Jannis Hamborg provides a compelling technical deep dive into the practicalities of automotive security research, particularly concerning data acquisition from modern electric vehicles. Their methodology centers on understanding and exploiting the diverse attack vectors present in contemporary cars, with a particular focus on the physical bus systems within the vehicle.
The speakers meticulously outlined the various categories of attack vectors:
- Long-range attacks: These encompass communications that occur over significant distances. Examples include cellular communication used for Over-The-Air (OTA) updates and interaction with the Original Equipment Manufacturer (OEM) backend. Another critical long-range vector is V2X communication, where vehicles communicate with each other (V2V) to share location and speed data, or with roadside infrastructure (V2I) to receive information like allowed speed limits.
- Short-range attacks: This category includes localized wireless communications. Common examples are Bluetooth and Wi-Fi connections, primarily used for infotainment systems, smartphone integration (e.g., Apple CarPlay), and other in-cabin connectivity features.
- Physical attacks: These are arguably the most "car-specific" attack vectors and form the core of the V2G (Vehicle to Game) project. They involve direct access to the vehicle's internal networks and components. Modern cars utilize several bus systems to enable communication between various Electronic Control Units (ECUs). While specific bus protocols like CAN (Controller Area Network), LIN (Local Interconnect Network), FlexRay, or Automotive Ethernet were not explicitly detailed in the transcript, the general concept of accessing these internal bus systems was central to their work. These buses carry a wealth of operational data, from engine RPM and speed to steering angle, brake pressure, and pedal positions.
To achieve their "Vehicle to Game" objective, the researchers developed a sophisticated data acquisition setup on their Volkswagen ID3 electric vehicle. This setup was designed to provide a "holistic view" of the car's internal operations:
- Vector Boxes: These specialized devices, manufactured by the German company Vector, are crucial for capturing data from various bus systems inside the car. By connecting these boxes to the vehicle's internal networks, the team could record the digital messages exchanged between ECUs. This allowed them to observe, for example, how pressing the accelerator pedal generates specific data packets indicating throttle position or desired acceleration.
- Clamp Sensors: For a deeper understanding of the vehicle's electrical behavior, especially within its high-voltage electric propulsion system, the team employed current measuring sensors (clamp sensors). These inductive sensors can be clipped onto high-voltage system wires to measure the current flow without direct electrical contact. This capability is particularly relevant for electric vehicles, enabling researchers to correlate physical power consumption with corresponding commands and responses on the internal data buses. The ability to compare these physical measurements with recorded bus data is critical for validating the integrity of bus messages and for identifying potential anomalies or manipulations.
The ultimate goal of this technical setup was to extract the raw data necessary to simulate a game controller. By reverse-engineering or identifying specific messages on the bus systems that correspond to driver inputs (e.g., steering wheel rotation, pedal depression), they could map these real-time vehicle parameters to standard game controller inputs, such as those of an Xbox controller. This process requires a detailed understanding of the vehicle's internal communication architecture, message formats, and data encoding, which manufacturers typically do not publish. Through hands-on experimentation and analysis, the team successfully demonstrated that this proprietary information can be uncovered, paving the way for both innovative applications and critical security assessments.
Demo / Proof of Concept
▶ Watch: Detailed in-car measurement setup with Vector boxes (5:20)
While the transcript does not provide a detailed, step-by-step walkthrough of a specific game being controlled by the vehicle, the core of the "Redefining V2G" talk itself served as a conceptual Proof of Concept (PoC) and demonstration of feasibility. The speakers articulated their vision of using the vehicle as an interactive game controller, directly linking real-time car data to gaming inputs. The essence of the demonstration lay in showing that data from a live vehicle, specifically their Volkswagen ID3, could be extracted and mapped to control an external system, which in this case was conceptualized as an Xbox controller.
The underlying mechanism for this PoC involved the sophisticated data acquisition techniques described in the technical deep dive. By leveraging Vector boxes to tap into the car's internal bus systems, the researchers were able to capture a continuous stream of operational data. This data would include parameters such as vehicle speed, steering wheel angle, accelerator pedal position, and brake pressure—all fundamental inputs for controlling a driving simulator or any game that requires directional and speed control.
The "how it worked" aspect, though not explicitly detailed for a specific game, relies on the principle of signal mapping. Once the relevant data packets corresponding to driver inputs are identified and decoded from the vehicle's bus systems, these values can be translated into commands that a standard game controller would understand. For instance, a certain range of steering wheel angle values from the car could be mapped to the left/right input of a joystick, and accelerator pedal position could map to a trigger pull for acceleration. The speakers explicitly mentioned that an "Xbox controller" could be used and that one "can map it to anything you want," indicating the flexibility of their approach once the raw vehicle data is accessible. This conceptual demonstration powerfully conveyed that the vehicle's internal data, often considered proprietary and isolated, is indeed accessible and can be repurposed, thus proving the "Vehicle to Game" concept as a tangible reality, even if the specific game implementation was left to the audience's imagination.
Defensive Implications
▶ Watch: Goal: Correlating physical vehicle data with bus messages (6:20)
The "Redefining V2G" project, while framed as an educational and motivating endeavor, carries significant defensive implications for the automotive industry and vehicle owners. The fundamental ability to extract detailed operational data from a vehicle's internal bus systems, even for a benign purpose like controlling a game, highlights profound vulnerabilities that defenders must address.
Firstly, the project underscores the critical need for robust security by design within vehicle architectures, particularly concerning in-car network segmentation and access control. If an attacker gains physical access to a vehicle's internal bus systems, as demonstrated by the use of Vector boxes, they could potentially not only read sensitive data but also inject malicious commands. This could lead to unauthorized vehicle control, data exfiltration, or even safety-critical malfunctions. OEMs must implement stricter authentication and authorization mechanisms for internal network access, even for diagnostic ports, to prevent such compromises.
Secondly, the ease with which proprietary data can be reverse-engineered and repurposed (e.g., mapping car inputs to an Xbox controller) emphasizes the importance of data privacy and integrity. Vehicle data, including location, driving habits, and biometric information (if present), is extremely sensitive. Unauthorized access to this data, whether through physical or remote attack vectors, poses significant privacy risks to drivers. Defenders must focus on encrypting data at rest and in transit within the vehicle, and on implementing robust intrusion detection and prevention systems (IDPS) that can flag unusual activity on internal bus systems.
Furthermore, the work highlights the ongoing challenge posed by the opacity of OEM systems. Manufacturers' reluctance to share internal specifications necessitates independent research like this, which can inadvertently reveal vulnerabilities. Defenders should advocate for greater transparency and collaboration with the security research community, perhaps through bug bounty programs or standardized interfaces for security analysis. This would allow vulnerabilities to be identified and patched proactively, rather than being discovered by adversaries or through projects like V2G.
Finally, the project's focus on motivating students with practical research offers a defensive advantage: it helps cultivate a new generation of cybersecurity professionals equipped to tackle complex automotive security challenges. By understanding how data can be extracted and manipulated, these future defenders will be better prepared to design, implement, and test secure vehicle systems, thereby strengthening the overall resilience of the automotive ecosystem against a growing array of threats. The implications extend beyond just physical access, serving as a warning that any exposed interface—be it cellular, Wi-Fi, or internal bus—can be a gateway for compromise if not adequately secured.
Key Takeaways
- V2G Redefined: The talk creatively redefined "V2G" from "Vehicle to Grid" to "Vehicle to Game," demonstrating a novel approach to automotive security research and education.
- Practical Automotive Security: The project emphasizes the critical importance of hands-on, practical research using real vehicles (e.g., Volkswagen ID3) to uncover vulnerabilities and understand complex systems.
- Holistic Data Acquisition: Researchers achieved a comprehensive understanding of vehicle operations by correlating physical electrical measurements (via clamp sensors) with digital bus communications (via Vector boxes).
- Extensive Attack Surface: Modern vehicles possess a vast attack surface, encompassing long-range (cellular, V2X), short-range (Bluetooth, Wi-Fi), and particularly physical (in-car bus systems) vectors.
- Educational Motivation: The "Vehicle to Game" concept serves as an effective, beginner-friendly method to motivate students and foster interest in the intricate field of automotive cybersecurity.
- OEM Opacity Challenge: The need for independent research highlights the challenge posed by manufacturers' proprietary systems and the lack of publicly available internal documentation.
About the Speaker(s)
Timm Lauser is a PhD student at Darmstadt University of Applied Sciences in Germany. His research primarily focuses on automotive security, encompassing theoretical analysis of protocols and standards, as well as formal verification to ensure they meet specified security goals. He is part of the ACSD (Automotive Cyber Security Darmstadt) research group.
Jannis Hamborg is also a PhD student at Darmstadt University of Applied Sciences and a member of the ACSD Automotive Cyber Security Darmstadt research group. His research centers on resilience in both automotive and IoT systems, investigating how to mitigate the impact of ECU (Electronic Control Unit) failures or compromises by migrating functionality to other ECUs to enhance in-car safety. He completed his master's degree shortly before presenting this talk. Both speakers are actively involved in teaching, aiming to motivate students in automotive security research through engaging projects like "Vehicle to Game."
Reviews
Dr. Zero (Offensive Security Researcher) — STRONG ACCEPT
This talk by Lauser and Hamborg redefines V2G as "Vehicle to Game," presenting a clever and highly effective method for teaching automotive security. By transforming a VW ID3 into a game controller, they practically demonstrate the extensive attack surface and data accessibility within modern vehicles. While the underlying techniques of bus sniffing are known, the application as a motivational educational tool and the holistic data acquisition approach are novel and impactful, providing tangible lessons for both aspiring and experienced researchers on internal network compromise and the critical need for security by design.
Heather Calloway (CISO) — STRONG ACCEPT
This talk provides a clear and practical demonstration of how modern vehicle internal systems can be accessed and their data repurposed, even for something as benign as a game controller. While framed as an academic exercise to motivate students, it powerfully illuminates a critical attack surface and raises significant questions about automotive security governance, data integrity, and the real-world business exposure for manufacturers and operators. It's a valuable contribution to understanding the foundational vulnerabilities in connected vehicles.