Lucian Popa 0003

dblp:237/7528 · DBLP profile ↗
← Back
8ranked-venue papers
2as first author
7since 2021 · last 2026
0000-0001-5357-7776ORCID · verified

Domains — the database's venue-derived domains; a paper can count in several

Security and privacy · 6 · 2 first-author · 5 since 2021Artificial intelligence and machine learning · 1 · 1 since 2021Computer networks · 1 · 1 since 2021Graphics, computer vision, multimedia, augmented reality and games · 1 · 1 since 2021
YearPublicationVenuePosition
2026 Constraint-Guided Clustering for Identifying in-Vehicle Electronic Control Units from Voltage Data
abstract
Identifying in-vehicle electronic control units based on voltage characteristics has been the subject of extensive research in cybersecurity. However, the results reported so far generally depend on restricted datasets and supervised learning. In this work, we show that clustering, i.e., unsupervised learning, of voltage characteristics, is in fact more challenging when done on a larger pool of electronic control units as several out-of-the-box clustering methods and metrics will fail to determine the correct number of clusters when exerted over a large dataset. To overcome this issue, we propose a new methodology that takes advantage of domain-specific constraints, which guide the search toward the correct number of electronic control units in a car, or even in a larger pool of units from several cars. We introduce two new metrics: correctness, which measures the success ratio with respect to the constraints, and divergence, which measures the consistency of the clustering, and show that they provide a strong indication for the optimal number of clusters. In this specific context, both metrics prove to be more reliable than the widely used Silhouette score, Davies-Bouldin and Calinski-Harabas indexes. We successfully test our methodology on the largest dataset available today for in-vehicle voltage characteristics and discover new insights regarding the number of devices.
Bogdan Groza, Patricia Iosif, Lucian Popa 0003
AAAI3
2026 Efficient voltage-based intrusion detection for in-vehicle networks: From density clustering to centroid classification
abstract
Detecting intrusions on in-vehicle networks from voltage characteristics has become a popular technique. However, an effective mechanism for voltage identification of Electronic Control Units requires both a sound clustering algorithm to determine the correct number of devices on the network and an efficient classifier that allows updates in order to handle changes due to environmental conditions. Firstly, we explore the use of HDBSCAN in order to cluster ECUs based on voltage characteristics. While HDBSCAN is a highly effective algorithm, which has the merit of having only a few parameters that need to be tuned, our results show that finding the optimal parametrization is not that straight-forward. We test two well-known methods and an empirical selection in order to determine optimal choices for the largest existing dataset that contains voltage samples from ten vehicles. Secondly, we use the Nearest Centroid classifier to identify ECUs based on their fingerprints, which offers the advantage of an extremely small memory footprint and an efficient updating mechanism for the centroids. Thus, the method is both efficient and capable of adapting to environmental changes, which is a known demand for voltage-based identification. The proposed methodology demonstrates a very high detection rate that is specific to voltage-based techniques, i.e., true acceptance rate greater than 99.93% and false acceptance rate lower than 0.03%, even when faced with changing environmental conditions when updates are used. It also features an easy to update mechanism and a minimal memory footprint that is 4 to 20 times smaller than baseline classifiers such as SVM and RF.
Patricia Iosif, Lucian Popa 0003, Bogdan Groza
Comput. Networks2
2022 PanoptiCANs - Adversary-Resilient Architectures for Controller Area Networks
Bogdan Groza, Lucian Popa 0003, Tudor Andreica, Pal-Stefan Murvay, Asaf Shabtai, Yuval Elovici
ESORICS (3)2
2022 ECUPrint - Physical Fingerprinting Electronic Control Units on CAN Buses Inside Cars and SAE J1939 Compliant Vehicles
abstract
We fingerprint 54 ECUs from 10 cars, one of them being a heavy-duty vehicle that is compliant to the SAE J1939 standard. These later specifications implemented in commercial vehicles offer concrete sender addresses in every CAN frame, making physical characteristics easier to link to specific ECUs. This is not the case for traffic collected inside passenger cars where the allocation of CAN bus identifiers is non-uniform, without explicit sender and receiver addresses, making ECU identification more challenging. While previous research has shown good separation between ECUs even when single features are used, e.g., skews or maximum voltage level, prior results are based on a small number of cars, while our larger experimental basis proves that single features are likely insufficient to separate between a large number of ECUs. Concretely, for a crisp separation, at least four features seem to be needed, i.e., mean voltage, max voltage, bit time and plateau time, while clock skews or any single voltage feature lead to overlaps. We provide clear experimental bounds on the intra and inter-distances regarding skews and voltage features, not neglecting environmental variations which may occur when the car is running.
Lucian Popa 0003, Bogdan Groza, Camil Jichici, Pal-Stefan Murvay
IEEE Trans. Inf. Forensics Secur.1
2021 CAN-SQUARE - Decimeter Level Localization of Electronic Control Units on CAN Buses
Bogdan Groza, Pal-Stefan Murvay, Lucian Popa 0003, Camil Jichici
ESORICS (1)3
2021 CANARY - a reactive defense mechanism for Controller Area Networks based on Active RelaYs
Bogdan Groza, Lucian Popa 0003, Pal-Stefan Murvay, Yuval Elovici, Asaf Shabtai
USENIX Security Symposium2
2021 CANTO - Covert AutheNtication With Timing Channels Over Optimized Traffic Flows for CAN
abstract
Previous research works have endorsed the use of delays and clock skews for detecting intrusions or fingerprinting controllers that communicate on the CAN bus. Recently, timing characteristics of CAN frames have been also used for establishing a covert channel for cryptographic authentication, in this way cleverly removing the need for cryptographic material inside the short payload of data frames. However, the main drawback of this approach is the limited security level that can be achieved over existing CAN bus traffic. In this work we significantly improve on this by relying on optimization algorithms for scheduling CAN frames and deploy the covert channel on optimized CAN traffic. Under practical bus allocations, we are able to extract 3-5 bits of authentication data from each frame which leads to an efficient intrusion detection and authentication mechanism. By accumulating covert channel data over several consecutive frames, we can achieve higher security levels that are in line with current real-world demands. To prove the correctness of our approach, we present experiments on automotive-grade controllers, i.e., Infineon Aurix, and bus measurements with the use of industry standard tools, i.e., CANoe.
Bogdan Groza, Lucian Popa 0003, Pal-Stefan Murvay
IEEE Trans. Inf. Forensics Secur.2
2019 Performance Evaluation of Elliptic Curve Libraries on Automotive-Grade Microcontrollers
abstract
As cryptography is quickly entering the automotive domain, public-key cryptographic functions are a vital building block and are part of recent industry-proposed standards. Elliptic curves provide a more compact representation for public/private keys making them more suitable for embedded devices with limited amounts of memory. Nonetheless, they provide more compact signatures and open road for identity-based cryptographic primitives by exploiting the flexibility of bilinear pairings. In this work we carry a performance evaluation on some modern libraries, e.g., MIRACL, RELIC, and compare them to the more classical WolfSSL. The evaluation is carried on a state-of-the-art representative controller from the automotive industry, i.e., a 32 bit Infineon TC297. Having a crisper image on computational requirements is relevant for future automotive and industrial applications.
Lucian Popa 0003, Bogdan Groza, Pal-Stefan Murvay
ARES1