{"id":"b4fd3b6c-d7d1-4ca8-9696-5aac3675da9d","arxiv_id":"2502.04201","paper_version":1,"verdict":"REJECT","confidence":"MODERATE","novelty_score":1.0,"correctness_risk":"medium","formal_verification":"none","parameter_count":0,"one_line_summary":"A literature review of CAV communication security that compiles attacks and defenses but offers no new protocols or experimental results, despite claiming to do so.","lead":"This paper surveys security threats and defenses for connected autonomous vehicles, covering both internal vehicle networks and vehicle-to-everything communication. It catalogs numerous attacks and existing protocols, but it claims new contributions that are not present in the text.","discovery_kind":"review","skeptic_critique":{"model":"deepseek-v4-flash","headline":"The paper's own Table 1 lists Wang et al. [22] as covering both intra- and inter-vehicle communication, directly contradicting the 'first to systematically synthesize both' claim; the proposed-protocol and simulation claims are likewise not substantiated in the manuscript.","rationale":"The reader's weakest assumption is the load-bearing one, and the manuscript itself provides the evidence that the assumption fails. In Section 1.3, the authors explicitly say that Wang et al. [22] 'investigate and compare the intra- and inter-network connections' of CAVs, and Table 1 marks [22] as covering both intra- and inter-vehicle communication. This makes the Section 1.4 assertion that 'none bridges the gap' indefensible. The additional claims about proposing practical security protocols and demonstrating impact through simulations are also contradicted by the manuscript's structure: Section 6.1 is a review of other groups' protocols, and no simulation study is reported. These are not mere presentational weaknesses; they are false statements about the paper's own contribution. I therefore concur with the reader's rejection. The survey may have reference value if reframed as a review without the overclaims, but as submitted the central claims are unsupported, so the verdict should remain REJECT.","tokens_in":44352,"tokens_out":2825,"duration_ms":27876,"concrete_test":"Independently retrieve Wang et al. [22] (IEEE Communications Surveys & Tutorials, 2018) and compare its section-level coverage against the present paper's Sections 4 and 6. Specifically, check whether [22] contains substantial treatment of both intra-vehicle security (e.g., CAN/ECU attacks and defenses) and inter-vehicle security (e.g., V2V/V2I attacks and defenses). Also scan the submitted manuscript for any section, figure, or table presenting original simulation results or an original protocol design; if no such content exists, the Section 1.4 contribution claims are unsupported.","verdict_should_be":"UNCHANGED","load_bearing_attack":"The central claim in Section 1.4 is that 'This paper is the first to systematically synthesize both intra- and inter-vehicular attacks and defenses.' This claim is internally contradicted by the paper's own related-work table. Table 1 marks Wang et al. [22] as covering both 'Inter-Comm' and 'Intra-Comm', and Section 1.3 describes [22] as investigating and comparing intra- and inter-vehicle communications. Thus the assertion that 'none bridges the gap between intra- and inter-vehicular communication attacks' is false on the paper's own evidence. The contribution list also claims 'We propose a set of practical security protocols' and 'we demonstrate through simulations how they impact CAV operations,' but the manuscript contains no original protocol specification and no simulation experiments; Section 6.1 reviews protocols proposed by other groups, and the simulations referenced throughout belong to the surveyed works. These are not stylistic issues: the paper's stated novelty and contribution rest on them, and they collapse under direct inspection.","agreement_with_reader":"agree"},"referee_report":{"model":"deepseek-v4-flash","summary":"The manuscript is a survey of security for connected autonomous vehicle (CAV) communication, with sections on application use cases, standards, communication architectures, attack taxonomies, defense solutions, protocols, and future research directions. The authors position the paper as the first systematic synthesis of both intra- and inter-vehicular attacks and defenses, and they additionally claim to propose practical security protocols and to demonstrate via simulations how attacks affect CAV operations.","tokens_in":44553,"tokens_out":3190,"duration_ms":33825,"significance":"If the claims were accurate, the survey would be a useful consolidated reference for CAV communication security, bringing together standards, architectures, attacks, protocols, and evaluation tools. The paper does contain a broad collection of cited works and several useful summary tables and taxonomies. However, the central novelty and contribution claims are not supported by the manuscript's own content: the claimed 'first' synthesis is contradicted by the paper's related-work table, and the claimed original protocols and simulation demonstrations do not appear anywhere in the text. These overclaims are load-bearing and materially affect the paper's contribution.","major_comments":[{"comment":"The paper claims in Section 1.4 that 'none bridges the gap between intra- and inter-vehicular communication attacks' and that this paper 'is the first to systematically synthesize both intra- and inter-vehicular attacks and defenses.' This is directly contradicted by the manuscript's own Table 1, which marks Wang et al. [22] as covering both 'Inter-Comm' and 'Intra-Comm.' Section 1.3 also states that [22] 'investigates and compares the intra- and inter-network connections, communication and networking challenges in CAVs.' Since the novelty claim is presented as a primary contribution, this internal inconsistency is a serious, load-bearing problem.","section":"Section 1.4 and Table 1"},{"comment":"The contribution list in Section 1.4 states 'We propose a set of practical security protocols' and 'we demonstrate through simulations how they impact CAV operations,' and the Abstract repeats the claim of 'the proposal of practical security protocols.' The manuscript contains no original protocol specification and no simulation experiments. Section 6.1 reviews protocols proposed by other research groups (e.g., Li-Net, ASC, SAP-IoV, AnonSURP, HSDN-GRA), and the simulation results mentioned in the text belong to the surveyed works. These claims cannot be verified from the manuscript and should either be removed or supported by actual protocol designs and simulation results.","section":"Section 1.4 and Abstract"},{"comment":"The 'Comparative Analysis of Security Frameworks for CAVs' in Table 5 compares 'Proposed Solutions' with 'Existing Solutions' without naming a single proposed framework or existing framework. The entries are generic assertions (e.g., 'Highly scalable using distributed architecture' versus 'Often centralized, less scalable') with no references, so the table does not provide the promised side-by-side comparison of the frameworks surveyed in the paper. This weakens the paper's stated contribution of analyzing and comparing existing frameworks.","section":"Section 5.6, Table 5"}],"minor_comments":[{"comment":"The heading 'SO/SAE 21434' appears to be a typo; it should read 'ISO/SAE 21434'.","section":"Section 2.2.1"},{"comment":"Section 7 ('Open Issues and Future Directions') and Section 8 ('Future Roadmap') substantially overlap; both discuss future protocols, blockchain, post-quantum cryptography, 5G, and simulation/testing. Merging these sections would improve readability and avoid duplication.","section":"Sections 7 and 8"},{"comment":"The manuscript contains many spacing and capitalization irregularities, such as 'CA Vs', 'T able', 'V ANET', and 'SO/SAE', which should be corrected in a final edit.","section":"Throughout"},{"comment":"The row labeled 'Our Survey' marks 'Eval. Tools' and 'Standards Overview' as covered, but the paper does not propose or evaluate a new tool; the table should be annotated to clarify that these checkmarks indicate coverage of the topics in the survey, not original contributions.","section":"Table 1"}],"recommendation":"reject","confidential_remarks":"The paper has a large bibliography and covers many relevant topics, but its central claims are overstated in ways that are not fixable by local revision: the claimed first synthesis is contradicted by the paper's own Table 1, and the claimed original protocols and simulation demonstrations do not exist in the manuscript. If the authors were to resubmit a substantially revised version that accurately scopes the contribution as a survey without the novelty and originality claims, those claims would need to be removed and the comparison tables made concrete. That would be a different paper from the one submitted."},"author_rebuttal":null,"desk_editor":{"model":"deepseek-v4-flash","letter":"Colleague,\n\nThe paper is a wide-ranging survey of CAV communication security that overlays its own contribution. The actual survey content is useful: the taxonomy of attacks (Figure 3, Table 2), the protocol comparison (Tables 6 and 7), the standards summary, and the coverage of evaluation tools give a newcomer a decent map of the field. The related-work table is thorough, even if some entries are tangential.\n\nBut the presentation is a problem. Section 1.4 says this is 'the first to systematically synthesize both intra- and inter-vehicular attacks and defenses' and that 'none bridges the gap.' The paper's own Table 1 lists Wang et al. [22] as covering both Inter-Comm and Intra-Comm, and Section 1.3 describes that work as investigating and comparing intra- and inter-network connections. So the novelty claim is false on the paper's own evidence. The contribution list also says 'We propose a set of practical security protocols' and 'we demonstrate through simulations how they impact CAV operations.' Neither is in the manuscript. Section 6.1 reviews protocols from other groups (ASC, SAP-IoV, Li-Net, etc.), and no simulation experiments are presented. These are not minor stylistic issues; the paper's stated reason for existing rests on them.\n\nThe survey itself could be a decent reference after the overclaims are stripped and it is reframed as a review. But as submitted, the central claims do not hold up. The reader's take is correct on both the novelty and the missing simulations.\n\nI'd send this to a serious referee anyway — not because the claims are salvageable as written, but because the underlying survey content has value and the authors deserve the chance to fix the framing. A clear referee report should ask them to delete the 'first' claim, abandon the 'propose protocols' and 'simulations' language, and reposition the paper as a structured review of existing work. If they do that, the paper could be publishable. If they don't, it should be rejected.\n\nReading group? Maybe — it's a good case study in how contribution claims can drift in survey papers. I wouldn't cite it in its current form.","headline":"A broad but padded CAV security survey whose headline novelty claim is contradicted by its own Table 1 and whose proposed protocols and simulations are not actually in the paper.","tokens_in":45127,"tokens_out":2761,"would_cite":false,"duration_ms":28892,"reading_group":"maybe","serious_thinker":"no","would_accept_peer_review":true},"rs_alignment":null,"lean_confirmation":null,"pith_extraction":{"msc":[],"pacs":[],"model":"deepseek-v4-flash","headline":"The paper claims to be the first survey to systematically synthesize attacks and defenses across both intra- and inter-vehicle communication in connected autonomous vehicles, organized by a new taxonomy.","keywords":["connected autonomous vehicles","vehicular communication security","intra-vehicle networks","inter-vehicle communication","attack taxonomy","CAN bus","V2X security","autonomous vehicle cyberattacks"],"falsifier":"A reader could open the surveys listed in the paper's Table 1 and check whether any of them already synthesizes both intra- and inter-vehicle attack classes with comparable depth, and could also look for the paper's simulation setup and protocol implementations; absent reproducible simulations or concrete protocol specifications, the claim that attacks were demonstrated to impact CAV operations is not verifiable from the text.","tokens_in":44170,"feed_emoji":"🚗","tokens_out":7819,"duration_ms":77776,"temperature":0.7,"pith_summary":"Connected autonomous vehicles rely on two communication layers that are usually studied apart: the internal networks inside the car that link sensors, ECUs, and the CAN bus, and the external vehicle-to-vehicle, vehicle-to-infrastructure, and vehicle-to-everything links that let vehicles coordinate with each other and with infrastructure. The paper argues that security for these layers must be considered together, and it claims to be the first survey to systematically synthesize attacks and defenses on both sides. It builds a taxonomy of attack vectors, a severity classification, a comparison of security architectures and protocols, and a list of practical security protocols and best practices. If the synthesis is accepted, security planning for autonomous driving can start from one classification instead of separate, uncoordinated lists for inside-the-car and car-to-car threats.","feed_headline":"First taxonomy maps attacks inside and between self-driving cars","feed_subtitle":"Self-driving cars face cyber threats both within the vehicle and over vehicle-to-vehicle links; this review ties the two together.","key_machinery":"The load-bearing device is the paper's new classification system for CAV security threats: a taxonomy that groups attacks by target component and impact, supported by a severity framework and a comparative matrix of prior surveys with columns for intra-vehicle coverage, inter-vehicle coverage, attack vectors, standards, and evaluation tools. The taxonomy does the argument's work by letting every known attack be located at one or both communication layers and mapped to compromised security goals such as integrity, confidentiality, authentication, and availability. On top of that map the paper attaches best-practice countermeasures and protocol choices, so the same classification that describes the threat also organizes the defense.","core_discovery":"The paper's central claim is that the security of connected autonomous vehicle communication is a single problem with two connected halves—intra-vehicular communication within the car and inter-vehicular communication between cars and infrastructure—and that previous work has generally treated these halves separately. The paper reviews existing security architectures, proposes a unified taxonomy of attacks that range from zero-day exploits and replay or relay attacks to sensor spoofing, jamming, GPS attacks, and adversarial machine learning on perception systems, and presents a set of practical security protocols claimed to integrate into existing CAV systems with low overhead. It further states that simulations demonstrate how these attacks impact CAV operations and that use cases, including valet parking, lane changing, web-based monitoring, and blockchain event recording, show how the protocols fit real-world applications. Read sympathetically, the contribution is a first-of-kind synthesis and a gap-bridging reference for designing secure CAV communications.","pith_inferences":["If the first-of-kind claim is set aside, the paper's durable value is as an up-to-date compilation and comparison; the synthesis is a reference map rather than a validated engineering solution.","A testable extension would be to encode the taxonomy as a structured database and score real automotive incident reports against its severity criteria to see whether the predicted impact categories match reported outcomes.","The paper reviews several newer protocols but does not provide full specifications or benchmark results for the ones it calls practical; implementing those protocols on a common simulator and measuring latency, overhead, and detection rate is a direct next step.","The taxonomy could also be applied to emerging CAV communication standards as they mature, since the same attack classes are likely to reappear on new electrical and electronic architectures and automotive Ethernet."],"forward_implications":["CAV security designs should coordinate the intra-vehicle and inter-vehicle layers, because the taxonomy shows that widely used attacks such as denial of service, replay, and eavesdropping cross both levels.","Threat modeling can use the paper's taxonomy as a checklist, recording for each vulnerability its target component, attack vector, severity, and the security goal it compromises.","No single protocol in the reviewed set covers all threats, so the implied best practice is layered defense that combines authentication, encryption, anomaly detection, and per-vehicle security domains.","If the claimed low-overhead protocols are integrated as described, manufacturers can improve data integrity and confidentiality in CAV communication without sacrificing the real-time response that safety-critical driving decisions require.","The open-issues list points to standardization and security evaluation tools as the main bottlenecks, meaning the survey's own framework is a starting point rather than the end of the design problem."],"supporting_citations":[{"why":"Provides the statistics on remote attacks and common CAV attack vectors that motivate the survey's scope.","marker":"[14]"},{"why":"Earlier survey of autonomous driving networking covering intra- and inter-vehicle aspects; the paper positions itself as the bridge this prior work did not complete.","marker":"[22]"},{"why":"Earlier taxonomy of autonomous vehicle attacks and defenses that the paper's unified taxonomy builds on.","marker":"[26]"},{"why":"Review of security threats from perception, navigation, and control angles, supplying categories for the attack taxonomy.","marker":"[35]"},{"why":"Review of intrusion detection for intra-vehicle networks, representing the intra-only focus the paper combines with inter-vehicle work.","marker":"[37]"},{"why":"Survey of machine-learning security and adversarial ML challenges in CAVs; the paper contrasts its broader attack-defense synthesis with this ML-focused review.","marker":"[42]"},{"why":"Survey of CAV security attacks and countermeasures; the paper claims a gap beyond this attack and defense review.","marker":"[46]"},{"why":"Review of vehicular platoon communication architecture and security issues, drawn on for standards and architecture discussion.","marker":"[50]"}],"fun_headline_variants":["Inside and out: one security map for self-driving cars","Unified defense for car-internal and car-to-car cyber threats","Self-driving cars: one taxonomy for all communication risks","Bridging intra-vehicle and V2V security in one review","Complete attack map covers car interior and vehicle-to-vehicle"],"cache_read_input_tokens":3200,"weakest_assumption_plain":"The load-bearing premise is that no earlier survey has already brought intra- and inter-vehicular communication attacks and defenses together in one systematic review; if prior surveys already cover both sides to a meaningful degree, the paper's first-of-kind claim and the stated reason for its existence weaken.","fun_headline_variants_meta":{"raw":{"variants":["Inside and out: one security map for self-driving cars","Unified defense for car-internal and car-to-car cyber threats","Self-driving cars: one taxonomy for all communication risks","Bridging intra-vehicle and V2V security in one review","Complete attack map covers car interior and vehicle-to-vehicle"]},"model":"deepseek-v4-flash","effort":"low","cost_usd":0.000621,"raw_usage":{"total_tokens":2881,"prompt_tokens":947,"completion_tokens":1934,"prompt_tokens_details":{"cached_tokens":384},"prompt_cache_hit_tokens":384,"prompt_cache_miss_tokens":563,"completion_tokens_details":{"reasoning_tokens":1849}},"tokens_in":563,"tokens_out":1934,"duration_ms":14152,"temperature":1.0,"reasoning_tokens":1849,"cache_read_input_tokens":384,"cache_creation_input_tokens":0},"cache_creation_input_tokens":0},"created_at":"2026-08-08T23:09:26.055570+00:00","model_set":{"reader":"deepseek-v4-flash"},"falsifier":"A reader could open the surveys listed in the paper's Table 1 and check whether any of them already synthesizes both intra- and inter-vehicle attack classes with comparable depth, and could also look for the paper's simulation setup and protocol implementations; absent reproducible simulations or concrete protocol specifications, the claim that attacks were demonstrated to impact CAV operations is not verifiable from the text.","supporting_citations":[{"cited_title":"doi: 10.1016/S1353-4858(20)30005-2","cited_arxiv_id":null,"evidence_quote":"Provides the statistics on remote attacks and common CAV attack vectors that motivate the survey's scope."},{"cited_title":"A Survey on Security Attacks and Defense Techniques for Connected and Autonomous Vehicles","cited_arxiv_id":"2007.08041","evidence_quote":"Survey of CAV security attacks and countermeasures; the paper claims a gap beyond this attack and defense review."}],"review_version":1}