Context Aware Anomaly Detection in Automotive CAN Without Decoding
Ravi Rajput (Principal Architect · New Tech Global)
DEF CON 33 · Day 1 · Main Stage
Overview
In this DEF CON presentation, Ravi Rajput, a Principal Architect at New Tech Global, addresses the critical challenge of securing the Controller Area Network (CAN) bus in modern vehicles. The talk, titled "Context Aware Anomaly Detection in Automotive CAN Without Decoding," introduces an innovative approach to detect malicious activity on the CAN bus using unsupervised machine learning, specifically Long Short-Term Memory (LSTM) networks and Variational Autoencoders (VAE). The core of Rajput's methodology lies in identifying deviations from normal message patterns and timing, rather than relying on traditional, often unscalable, decoding methods.

Key moments
- 0:00 Introduction, speaker background, and talk agenda
- 1:57 Challenges and limitations of the automotive CAN bus
- 2:58 Unsupervised machine learning for CAN anomaly detection
- 4:09 Introducing LSTM and LSTM VAE algorithms
- 6:44 Illustrating LSTM's anomaly detection with car speed
- 9:00 Addressing uncertainty and false positives with LSTM-VAE
- 10:30 Data pipeline for model training and evaluation
Context Aware Anomaly Detection in Automotive CAN Without Decoding
Speakers: Ravi Rajput, Principal Architect, New Tech Global
Conference: DEF CON
YouTube: https://www.youtube.com/watch?v=VchCd-o25z0
Overview
In this DEF CON presentation, Ravi Rajput, a Principal Architect at New Tech Global, addresses the critical challenge of securing the Controller Area Network (CAN) bus in modern vehicles. The talk, titled "Context Aware Anomaly Detection in Automotive CAN Without Decoding," introduces an innovative approach to detect malicious activity on the CAN bus using unsupervised machine learning, specifically Long Short-Term Memory (LSTM) networks and Variational Autoencoders (VAE). The core of Rajput's methodology lies in identifying deviations from normal message patterns and timing, rather than relying on traditional, often unscalable, decoding methods.
The automotive industry faces a significant cybersecurity hurdle due to the inherent vulnerabilities of the CAN bus, which lacks fundamental security features like authentication, encryption, or integrity checks. Rajput's research proposes a scalable and robust solution to this problem by leveraging advanced machine learning algorithms. By focusing on the temporal and contextual aspects of CAN messages, the system can discern subtle anomalies that signify potential attacks, such as replay attacks or fuzzing, without requiring prior knowledge of specific vehicle models or signal meanings. This talk is crucial for anyone involved in automotive cybersecurity, offering practical insights into building resilient in-vehicle intrusion detection systems.
Background
▶ Watch: Introduction, speaker background, and talk agenda (0:00)
The CAN bus serves as the central nervous system for communication between Electronic Control Units (ECUs) in modern vehicles. Despite its ubiquity, the CAN protocol was designed decades ago without security in mind. It operates as a broadcast architecture, meaning every connected ECU can both send and receive any message, with no built-in authentication, encryption, integrity checks, or access control. Furthermore, CAN is a stateless protocol, which makes it challenging to detect malicious injections that manipulate the vehicle's state inconsistently. This lack of inherent security creates a significant attack surface, allowing malicious actors to inject arbitrary messages, trigger unintended actions, or disrupt critical vehicle functions.
Traditional anomaly detection methods on the CAN bus often rely on rule-based systems or require protocol decoding to understand the meaning of each message and its payload. The primary challenge with these approaches is scalability. Every vehicle model, and even different variants within the same model, can have unique CAN ID structures, signal meanings, and encoding schemes. This necessitates extensive reverse engineering and manual rule creation, making it impractical to deploy and maintain across large fleets or different vendors. Additionally, rule-based systems struggle with state awareness and can be brittle, leading to high false positive rates when faced with the inherent noise and variability of real-world automotive networks. The need for a more adaptable, context-aware, and scalable solution, particularly one that doesn't require decoding, is therefore paramount.
Key Findings
▶ Watch: Unsupervised machine learning for CAN anomaly detection (2:58)
Ravi Rajput's research yielded several crucial findings regarding the efficacy of context-aware, unsupervised machine learning for CAN bus anomaly detection:
- Detection of Unseen and High-Frequency IDs: The system effectively identifies unusual or previously unseen CAN IDs on the bus. Furthermore, it flags instances where rarely observed IDs suddenly appear at a high frequency, indicating potential spoofing or injection attacks. This capability is vital for detecting attacks that introduce new, unauthorized messages into the network.
- Payload Entropy Spikes as Attack Indicators: Significant payload entropy spikes were identified as a reliable indicator of malicious activity, particularly fuzzing attacks. Fuzzing often involves sending random or semi-random data, which naturally increases the entropy of the message payloads, making this a distinct signature for detection.
- Timing Deviations for Replay Attack Detection: The model successfully detects timing deviations in message sequences. This is particularly effective against replay attacks, where legitimate messages are re-sent at incorrect times or out of sequence. The underlying LSTM VAE model specifically captures these temporal inconsistencies, manifesting as "latent shift" or "KL spike in divergence."
- Robustness of LSTM VAE: The LSTM VAE algorithm demonstrated superior robustness compared to standard LSTM autoencoders, especially in noisy and bursty automotive environments. Its ability to learn the distribution of valid behavior, rather than rigid patterns, and to express confidence in its detections significantly reduces false positives. This makes it a more practical choice for real-world deployment on ECUs or in vehicle security operations centers (VSOCs).
- Scalability Without Decoding: A fundamental finding is that effective anomaly detection can be achieved without decoding CAN messages. By focusing on meta-features like timing deltas, CAN ID frequencies, and payload entropy, the approach bypasses the need for vehicle-specific knowledge, making it inherently scalable across diverse vehicle models and manufacturers.
Technical Deep Dive
▶ Watch: Introducing LSTM and LSTM VAE algorithms (4:09)
The core of Rajput's solution lies in the application of advanced unsupervised machine learning algorithms, specifically LSTM (Long Short-Term Memory) networks and their variational autoencoder extension, LSTM VAE. These models are particularly well-suited for processing sequential data, which is characteristic of CAN bus traffic.
The process begins with feature engineering from raw CAN bus logs. Instead of attempting to decode the payload, the system extracts meta-features that describe the message's behavior and context. These features include:
- Timestamp: The time at which a message was observed.
- CAN ID: The identifier of the message, indicating its priority and source.
- Payload Bytes: The raw data carried by the message.
From these raw elements, the following derivative features are computed in a sliding window over the message sequence:
- Delta T (Timing Delta): The time difference between consecutive messages. This feature is crucial for capturing the rhythmic nature of CAN communication and detecting temporal anomalies.
- Entropy: Calculated from the payload bytes within a window. High entropy often indicates random or pseudo-random data, characteristic of fuzzing attacks.
- Frequency of CAN ID: The occurrence rate of specific CAN IDs within a given time window. Unusual spikes or drops in frequency can signal malicious activity.
These features are then normalized (e.g., using min-max or z-score scaling) to ensure consistent input for the neural network.
The chosen algorithms, LSTM and LSTM VAE, are types of recurrent neural networks (RNNs) designed to handle sequences. Unlike traditional feed-forward networks, LSTMs have internal memory cells that allow them to learn long-term dependencies in data. Rajput likens this to a musician playing a piece: missing a single note disrupts the entire melody. Similarly, an LSTM perceives CAN messages not as isolated events but as a continuous, time-ordered sequence. The network comprises three internal "gates"—forget, input, and output—which regulate what information is remembered, updated, or passed on, maintaining a cell state that encapsulates the sequence's history.
The architecture employed is a sequence-to-sequence autoencoder. An encoder network processes an input sequence of CAN frames, compressing it into a latent vector (a lower-dimensional representation). A decoder then attempts to reconstruct the original input sequence from this latent vector. The model is trained on "normal" CAN traffic, learning to minimize the reconstruction error (typically Mean Squared Error, MSE) between the original and reconstructed sequences. During inference, if the reconstruction error for a new, unseen sequence exceeds a predefined threshold, it is flagged as an anomaly. This indicates that the new sequence deviates significantly from the learned normal patterns.
The more advanced variant, LSTM VAE (Variational Autoencoder), extends the standard autoencoder by introducing a latent distribution rather than a fixed latent vector. This means the encoder outputs parameters (mean and variance) of a probability distribution from which the latent vector is sampled. This latent sampling process introduces a controlled form of noise, which makes the VAE more robust and capable of learning the distribution of valid behaviors rather than just a fixed pattern. This is particularly advantageous in the noisy and bursty environment of automotive networks, where static thresholds can lead to high false positive rates.
The loss function for the LSTM VAE is composed of two parts:
- Reconstruction Loss: Measures how accurately the decoder rebuilds the input sequence.
- KL Divergence Loss: Measures how far the learned latent distribution deviates from a standard normal distribution. This term regularizes the latent space, ensuring it is well-structured and allowing the model to express confidence in its anomaly detections. A "KL spike in divergence" can specifically indicate a replay attack, signifying a shift in the underlying data distribution.
By learning the distribution of valid behavior, the LSTM VAE can tolerate natural variations in CAN traffic while still effectively highlighting true anomalies. This ability to model uncertainty is a key differentiator from simpler autoencoder approaches, making it highly suitable for robust intrusion detection systems (IDS) in automotive contexts.
Demo / Proof of Concept
▶ Watch: Addressing uncertainty and false positives with LSTM-VAE (9:00)
Ravi Rajput provided a live demonstration (though truncated due to time constraints) to illustrate the practical application of his anomaly detection system. The demonstration utilized the iccc tool (likely a reference to can-utils or a similar CAN interface utility) to interact with a simulated CAN bus environment.
The setup involved capturing two distinct log files:
normal.log: This log contained typical CAN bus traffic generated by performing normal vehicle activities, such as increasing speed or turning (though the speaker specifically mentioned increasing speed and left/right, the actual actions were focused on door lock/unlock). This log served as the training data for the machine learning model, allowing it to learn the baseline "normal" behavior.attack.log: This log was captured while simultaneously performing normal activities and injecting malicious traffic. The specific target for the attack was CAN ID19b, which corresponds to the door lock and unlock mechanism. The demonstration involved "fuzzing" this particular CAN ID, meaning sending a rapid sequence of potentially malformed or out-of-context messages to it.
The data pipeline for the demo involved:
- Log Collection: Capturing
normal.logandattack.log. - Feature Extraction: From each log, extracting the timestamp, CAN ID, and payload bytes. Non-standard frames were filtered out.
- Feature Engineering: Calculating the time delta (delta t) between messages, payload entropy, and the frequency of CAN IDs within a sliding window.
- Sequence Generation & Normalization: Constructing sequences of these features and normalizing them (e.g., min-max scaling).
- Model Training & Inference: The LSTM VAE model was trained on
normal.log. During the evaluation phase, it processedattack.logto identify anomalies.
Due to time constraints, Rajput presented pre-computed results from an earlier run. These results showcased:
- Graphs illustrating the computed time delta and entropy features.
- An MSE (Mean Squared Error) loss graph from the sequence generator, indicating the model's reconstruction error over time.
- The system's ability to detect anomalies, specifically highlighting CAN ID
19bas the most anomalous. The output clearly showed a significant entropy peak associated with19bduring the attack period, which the more robust LSTM VAE algorithm successfully identified as the highest anomaly. This demonstrated the model's capability to pinpoint the specific CAN ID under attack based on its deviation from learned normal patterns.
The demo, despite its brevity, effectively illustrated the practical workflow and the tangible output of the context-aware anomaly detection system, reinforcing the claim that such an approach can identify malicious activity without requiring deep decoding of CAN payloads.
Defensive Implications
▶ Watch: Data pipeline for model training and evaluation (10:30)
The context-aware anomaly detection system presented by Ravi Rajput offers significant defensive implications for automotive cybersecurity. Its ability to detect anomalies without decoding CAN messages provides a scalable and robust approach to enhance vehicle security.
Defenders should consider the following actions and strategies:
- Implement Unsupervised ML-based IDS: Vehicle manufacturers (OEMs) and Tier-1 suppliers should integrate unsupervised machine learning models, specifically those leveraging LSTM VAEs, into their in-vehicle intrusion detection systems (IDS). This moves beyond traditional rule-based systems, which are prone to being outsmarted by novel attacks and are difficult to maintain across diverse vehicle platforms.
- Deploy Lighter Models on ECUs: The concept of deploying "lighter versions" of these models directly onto Electronic Control Units (ECUs) is a critical defensive strategy. By embedding detection capabilities closer to the source of CAN traffic, anomalies can be identified and potentially mitigated in near real-time, reducing latency in response to attacks. This requires careful optimization of model size and computational demands to fit within the resource constraints of typical ECUs.
- Integrate with VSOC and SIEM Solutions: The anomaly detection output can serve as a vital input for Vehicle Security Operations Centers (VSOCs) and broader Security Information and Event Management (SIEM) solutions. By feeding detected anomalies—such as unusual CAN ID frequencies, payload entropy spikes, or timing deviations—into these centralized platforms, security teams can gain comprehensive visibility into the health of their vehicle fleets. This enables faster incident response, forensic analysis, and proactive threat hunting across multiple vehicles.
- Focus on Meta-Features for Scalability: For fleet operators and service providers, the emphasis on meta-features (timing deltas, CAN ID frequency, payload entropy) rather than payload decoding is a game-changer for scalability. This approach allows for a unified detection system that can be deployed across heterogeneous vehicle models from different manufacturers without requiring extensive, model-specific reverse engineering, significantly lowering deployment and maintenance costs.
- Prioritize Detection of Replay and Fuzzing Attacks: The research specifically highlights the effectiveness against replay attacks (via timing deviations and KL divergence spikes) and fuzzing attacks (via entropy spikes). Defenders should prioritize their IDS configurations and alert thresholds to specifically detect these common and impactful attack vectors, which can lead to vehicle manipulation or denial of service.
- Continuous Learning and Adaptation: While unsupervised, these models still benefit from continuous retraining with evolving "normal" vehicle behavior. Defenders should establish mechanisms for periodically updating the models with new baseline data to adapt to software updates, new features, or changes in operational patterns, ensuring the IDS remains effective over the vehicle's lifecycle.
Key Takeaways
- The CAN bus lacks fundamental security features, making it vulnerable to attacks like spoofing, replay, and fuzzing.
- Traditional, rule-based, or decoding-dependent anomaly detection methods are not scalable across diverse vehicle fleets.
- Unsupervised machine learning, specifically LSTM and LSTM VAE networks, offers a robust and scalable solution for CAN anomaly detection without decoding messages.
- Key features for detection include CAN ID frequency, timing deltas, and payload entropy, which effectively identify malicious patterns.
- LSTM VAE is particularly effective due to its ability to learn the distribution of normal behavior and handle the inherent noise of automotive networks, reducing false positives.
- The system can detect replay attacks through timing deviations (latent shift, KL divergence spikes) and fuzzing attacks through payload entropy spikes.
- Deployment possibilities include lightweight models on ECUs and integration with VSOC and SIEM solutions for comprehensive fleet security.
About the Speaker(s)
Ravi Rajput is a Principal Architect in information security at New Tech Global. He possesses extensive expertise in automotive cybersecurity and has a background in advanced penetration testing. Rajput is the creator of Autoac OS, an operating system specifically designed for automotive penetration testing, which he launched at Black Hat Arsenal Asia. Autoac OS has achieved millions of downloads and is utilized by various Original Equipment Manufacturers (OEMs). Beyond his professional roles, Ravi is a core team member of the Telecom Village at DEF CON and has a strong presence in the cybersecurity conference circuit, having presented at prestigious events such as DEF CON, Black Hat, Nelcon, and several other "besides" conferences. His work consistently focuses on practical, impactful solutions in the realm of vehicle security.
Reviews
Dr. Zero (Offensive Security Researcher) — SOLID
Legitimate automotive security research applying LSTM VAE to CAN anomaly detection without protocol decoding — a real problem with a reasonable solution. The core idea is sound and the no-decode framing for fleet scalability is the talk's genuine contribution, but the approach isn't novel enough to stand out at DEF CON in 2024, and the truncated demo undercuts the credibility of the claims.
Heather Calloway (CISO) — WEAK
Technically credible work on a real problem — CAN bus lacks authentication, ML-based detection without decoding is a legitimate scalability advance — but the talk never bridges from research artifact to institutional action. The defensive implications section reads like a vendor whitepaper checklist, not a decision path for anyone who actually owns automotive security risk.