DOI: 10.3390/su18189665 ISSN: 2071-1050

FRMCS Cybersecurity at Railroad-Road Crossings: Threat Model and Machine-Learning Attack Detection

Zbigniew Kasprzyk, Mariusz Rychlicki

Sustainable transport policy shifts traffic from road to rail, which presupposes safe and reliable railroad-road crossings. Migration of railway communications to the Future Railway Mobile Communication System (FRMCS) makes that safety depend on digital resilience: an attack on the communication layer translates directly into the physical state of a crossing. This paper develops a threat model for FRMCS at level crossings covering three attack classes that act on that state—repetition and injection of Euroradio telegrams, functional identity takeover, and abuse of the railway emergency call—and evaluates their detection by machine learning. Operational FRMCS traffic does not yet exist, so detectors were trained on 400,000 records generated from the 3GPP and UIC specifications in four phases of increasing difficulty. Over 20 independent replications, the random forest and XGBoost achieved a macro F1 score of 0.920 ± 0.003, were statistically indistinguishable, and inferred in under 1 ms per packet, meeting the real-time requirement for a crossing. Detection capability varies far more between attack classes than between models, and the gravest attack class is the hardest to detect. Costing the operational and environmental impact of an attack-induced safe state links detection to Sustainable Development Goal targets 9.1 and 11.2 and to NIS2 obligations.