Quantifying First-Hop Collision Risk from GPS/V2V Spoofing Attacks in a String-Stable CACC Platoon
Akashdeep Bhardwaj, Shawon RahmanCooperative adaptive cruise control (CACC) platoons rely on Vehicle-to-Vehicle communication and GPS to maintain sub-second headways, creating cyberattack surfaces underrepresented in standard surrogate-safety metrics. We built a fully equation-based, Routh–Hurwitz- and Lp-string-stability-verified simulation of a ten-follower (eleven-vehicle, including the leader) CACC platoon (point-mass dynamics, actuator lag, PD spacing control) and subjected it to a two-channel GPS-spoofing attack corrupting both the attacked vehicle’s control loop and its broadcast position; velocity and acceleration broadcasts, and the CACC feed-forward term they drive, are left uncorrupted, so the reported boundaries are conditional on this restricted, single-channel threat model and should be read as a lower bound on attack severity rather than a worst case. Across a 64-cell severity–duration grid (2–20 m, 1–10 s; h = 0.6 s), minimum time-to-collision fell from 31.7 s to a simulated collision in 6/64 cells (9.4%), driven more by magnitude than duration; the disturbance decays sharply after the first hop rather than cascading down the platoon, so the resulting risk is local, not cascading. A 48-cell headway grid showed h ≥ 0.7 s eliminated all collisions at the originally tested attack duration (3/8 → 0/8 at fixed severity), a result that held under two alternative controller-gain sets tested for sensitivity and was largely, though not universally, robust to a substantially stiffer third set. A position sweep found risk invariant across nine of ten platoon positions. Batch-computed first-hop propagation and tail-to-origin amplification ratios showed the disturbance transiently amplifies (ratio > 1) at its first hop in a third of tested attacks despite decaying three orders of magnitude by the platoon’s tail, a behavior distinct from the front-injected Lp string stability verified separately. Peak root-mean-squared jerk stayed within the comfortable range (≤1 m/s3) in every tested cell, including collisions, showing collision and comfort risk are governed by different parameters. Embedding a representative detection and elastic-control layer alongside headway optimization eliminated collisions within the tested range and remained robust at three times that severity, where headway alone failed; because the detector’s residual is computed directly from the true offset magnitude and detector failure is not modeled, this joint-defense result is illustrative rather than a validated-detector-calibrated estimate. These results give a reproducible, quantified basis for headway- and detection-based mitigation policy in connected-vehicle platoons.