Search NASASearch

SEARCH · Search NASA

Results for “traffic monitoring”

Search indexed NASA NTRS and DOE OSTI research on propulsion, heat transfer, battery materials and energy systems. Follow report and document links to the original sources.

Quote a phrase for an exact phrase match. Source license links do not imply unrestricted reuse.

At least 19 records

Edge AI-Enhanced Traffic Monitoring and Anomaly Detection Using Multimodal Large Language Models

This paper addresses the challenge of traffic monitoring and incident detection in remote areas, utilizing multimodal large language models (LLMs) deployed on edge AI devices. The key novelty of the LLM is to convert real-time video streams into descriptive texts, enabling low-bandwidth transmissions and reliable detection of anomalies and incidents in environments of intermittent connectivity. The model is developed based on fine-tuning open-source LLMs and extending it with multi-modal capabilities to analyze video frames. Our work also involves deploying this model on edge devices such as Nvidia IGX Orin and is planned to be tested in realistic environments in future work. The methodology includes data set curation, iterative model fine-tuning and compression, and hardware-based optimization. This approach aims to enhance traffic safety and response speed in remote areas, marking a significant advancement in the application of AI for traffic monitoring and safety management.

Peruski, Ryan [University of Tennessee, Knoxville

Automatic Calibration and Health Monitoring of Infrastructure Sensors

Smart transportation infrastructure relies on networks of heterogeneous sensors - cameras, radars, and lidars - continuously monitoring traffic conditions. However, executing the initial spatial calibration of multiple sensors and the subsequent health monitoring presents significant operational challenges. Environmental factors, mechanical vibrations, and gradual drift cause spatial misalignment, degrading fusion performance and tracking accuracy. Traditional calibration approaches require manual intervention with specialized targets or survey equipment, resulting in service interruptions and high maintenance costs. This work presents an automated framework for initial calibration and continuous health monitoring without human intervention or service disruption. Our approach addresses two critical problems: (1) detecting when sensors become miscalibrated during operation, and (2) automatically re-establishing spatial alignment using only operational traffic data. The health monitoring component analyzes measurement innovations - differences between sensor observations and predicted object states - to detect systematic biases indicative of calibration drift. By computing bias magnitude, directional consistency, and rejection rates, the system identifies miscalibrations as small as 0.5 meters. Unlike traditional methods requiring known calibration targets, our diagnostic operates continuously on live traffic observations, enabling early detection before fusion quality degrades. The automatic recalibration algorithm leverages overlapping sensor fields-of-view and temporal correlation of vehicle observations. Using graph-based optimization, the system automatically discovers which sensor pairs observe common regions, estimates pairwise spatial transformations using RANSAC-based robust estimation, and jointly optimizes all sensor poses through bundle adjustment. The framework handles practical deployment challenges, including different sensor sampling rates (1-10 Hz), varying installation positions, unknown orientations, and limited overlap regions (>10%). When approximate sensor positions are available from installation surveys (+/-1m accuracy), the algorithm additionally estimates sensor orientations, refining both position and rotation to sub-meter and sub-degree accuracy. We validate the framework on multi-hour traffic datasets from six heterogeneous sensors with sampling rates ranging from 1 Hz to 10 Hz. Results demonstrate successful calibration even with sparse overlap (<20%) and automatic detection of miscalibrations exceeding 0.8 meters. This work enables a "deploy-and-forget" sensor infrastructure that maintains calibration autonomously, reducing maintenance costs while improving tracking accuracy. The techniques generalize beyond transportation to any multi-sensor monitoring application requiring robust spatial alignment, including smart cities, industrial monitoring, and surveillance systems.

24 POWER TRANSMISSION AND DISTRIBUTION

Modeling, Monitoring, and Controlling Road Traffic Using Vehicles to Sense and Act

This review offers a comprehensive overview of current traffic modeling, estimation, and control methods, along with resulting field experiments. It highlights key developments and future directions in leveraging technological advancements to improve traffic management and safety. Here, the focus is on macroscopic, microscopic, and micro-macro models, as well as state-of-the-art control techniques and estimation methods for deploying vehicles in traffic field experiments.

42 ENGINEERING

Open-Source Data for MAC-POSTS: Mobility Data Analytics Center - Prediction, Optimization, and Simulation Toolkit for Transportation Systems

MAC-POSTS (Mobility Data Analytics Center - Prediction, Optimization, and Simulation toolkit for Transportation Systems) is a toolkit for dynamic transportation network modeling. Developed by the Mobility Data Analytics Center (MAC) at Carnegie Mellon University, this package implements many classic dynamic transportation network models, as well as new models proposed by MAC members. It has served as one building block for many other models and research projects. As such, this package used to be treated as an internal research project of the MAC lab, and admittedly, the code base is messy, and the interface is hard to use. However, we are working hard to make it a generally usable and useful toolkit for dynamic transportation network modeling. We would really appreciate any feedback, comments, suggestions, or criticisms.

32 ENERGY CONSERVATION, CONSUMPTION, AND UTILIZATI

Firmware Tampering Detection in Heavy-Duty Vehicles through J1939 CAN Analysis

Modern heavy-duty vehicles rely on complex networks of Electronic Control Units (ECUs) that communicate using the J1939 protocol. While this system makes it easier to update and configure vehicle components, it also opens the door to serious cybersecurity risks if not properly secured. This work investigates the potential for firmware tampering through the J1939 communication protocol, which enables ECU configuration and reprogramming over the Controller Area Network (CAN) bus. By monitoring CAN traffic during legitimate maintenance operations and reverse-engineering OEM diagnostic software, we identified common and proprietary J1939 message identifiers, authentication patterns, and vulnerabilities within Unified Diagnostic Services (UDS). These findings demonstrate that inadequate authentication mechanisms can allow malicious actors to alter ECU firmware or disable safety functions, posing severe operational and safety risks. Our analysis contributes to the development of vehicle intrusion detection systems capable of recognizing abnormal reprogramming activity and future firmware fingerprinting methods to verify software integrity across ECUs. This work highlights the importance of standardizing secure firmware authentication across manufacturers to strengthen cyber resilience in heavy-duty vehicle systems.

33 ADVANCED PROPULSION SYSTEMS

Efficient Anomaly Detection Driven By Different Machine Learning Architectures And Models

The rapid growth and ubiquitous adoption of the internet and cyber-physical systems (CPS) have fundamentally transformed modern communication, work, and human-system interactions. While networks now form the backbone of critical digital ecosystems, enabling seamless data transmission across diverse, interconnected systems, this increased connectivity also expands the attack surface, making real-time detection of network intrusions and anomalies a pressing challenge. Detecting unusual activities within network infrastructure requires advanced data traffic analysis to differentiate between legitimate and malicious interactions. Traditional approaches to network anomaly detectionâ??such as rule-based and signature-based systemsâ??often depend on predefined patterns to identify known anomalies, limiting their effectiveness against emerging, stealthy, or previously unseen threats. These conventional methods suffer from high false alarm rates and fail to adapt to the ever-evolving nature of network traffic, particularly in large-scale, decentralized environments where data volume, velocity, and variety are constantly increasing. This dissertation presents artificial intelligence (AI)-driven approaches to anomaly detection that leverage graphics processing unit (GPU)-enabled high-performance computing (HPC) platforms for processing massive network traffic data and monitoring the components of cyber-physical systems (CPS) for potentially hazardous conditions. The research advances several key contributions: (1) Designing efficient machine learning techniques for CPS condition monitoring and anomaly detection; (2) enabling federated learning (FL) frameworks that enable distributed detection while preserving data privacy and system resilience; (3) exploring graph-based methodologies combining graph neural networks (GNN) and graph machine learning (ML) approaches for the Internet of Things (IoT) and automotive network security, and (4) performing distributed edge computing optimizations that integrate FL with scalable technologies for reduced communication overhead. Through extensive experiments, these methodologies demonstrate that complex anomaly detection and condition monitoring tasks can be achieved while balancing computational efficiency and detection accuracy through fine-grained network information processing. The frameworks developed in this research establish a robust foundation for network anomaly detection, providing scalable, adaptive, and privacy-preserving solutions for safeguarding CPS and IoT networks in an increasingly interconnected digital landscape. The practical implications of these research findings are significant, as they can inform the development of next-generation network security systems and contribute to the protection of critical infrastructure against sophisticated cyber attacks.

Marfo, William

Disparities in the air quality monitoring stations and PM₂.₅ in Chicago’s air quality landscape

Fine particulate matter (PM₂.₅) poses significant public and environmental health risks in urban areas. Chicago’s dense industry and traffic create variable air quality, yet monitoring is unevenly distributed, resulting in undersampling of air quality data in some city areas. This study applied a hybrid approach using GIS-based kernel density mapping, interpolation modeling (IDW, Spline, Kriging) of USEPA monitoring data, multi-scale temporal trend analyses (hourly to annual), and ESDA. Accordingly, the density surface showed that monitors are concentrated in the affluent north, northwest, and southwest sides of Chicago (up to ~ 0.07 stations per sq mile), while the south and southeast regions, with predominantly minority communities, have virtually no coverage. Overall, citywide coverage is minimal (~ 4–5 monitors total; ~0.02 per sq mile; ≈1 per 600,000 residents). Temporal analyses showed that the city’s mean annual PM₂.₅ (~ 10.8 µg/m³) exceeds USEPA/WHO standards (9 µg/m³), with summer means (~ 17.1 µg/m³) significantly higher than other seasons. Diurnally, a clear pattern was observed, with PM₂.₅ concentrations peaking overnight (00:00–03:00) and during the morning rush hours, and dipping during midday to late afternoon. Spatial distribution of PM₂.₅ identified hotspots near O’Hare Airport, the downtown Loop area, and south-side neighborhoods, contrasting with lower concentrations on the north side, revealing Chicago’s socioeconomic divides and resulting environmental inequities. The findings underscore the need for expanded monitoring and targeted interventions in under-monitored, high-pollution communities to advance equitable community health.

54 ENVIRONMENTAL SCIENCES

The Design and Evaluation of Zero Trust Architecture for Electric Vehicle Charging Infrastructure: EVs @ Scale Series on EV Charging Station Cybersecurity

Implementing a zero trust architecture can significantly bolster the security of electric vehicle (EV) charging infrastructure. EV charging infrastructure includes numerous networked interfaces, each of which can present potential vulnerabilities. When these vulnerabilities are exploited, they can compromise the entire system, leading to severe operational and security risks. Zero trust is a security model that operates on the principle of "never trust, always verify," which helps manage the attack surface and limit the scope of any potential compromises. Fundamentally, this model ensures that no entity, whether inside or outside the network, is trusted by default. The design principles of zero trust include continuous verification, strict deny-by-default access controls, and micro-segmentation. Continuous verification ensures that every request is thoroughly checked, regardless of its origin. Strict access controls enforce the principle of least privilege, allowing users and devices only the minimum necessary access to perform their functions. Micro-segmentation involves dividing the network into smaller, isolated segments to prevent lateral movement in case of a breach. In the context of EV charging infrastructure, zero trust can be implemented through various strategies. For example, multi-factor authentication (MFA) can be required for engineers to access the management interfaces and control systems of charging stations. Real-time monitoring and analysis of network traffic can help detect and respond to anomalies. Systems that do not need to communicate with each other can be micro-segmented to enhance security. All communications should adhere to predefined policies to be permitted. Additionally, encrypting communications can protect sensitive information exchanged between chargers and management systems. This paper presents a zero trust architecture specifically designed for EV charging infrastructure. Implementing zero trust not only mitigates risks but also builds a resilient infrastructure capable of withstanding and quickly recovering from cyber threats. The architecture addresses six defined security objectives. A comprehensive test plan is developed to assess the architecture against these objectives, and the results of the evaluation are reported. This approach is essential for maintaining the reliability and integrity of EV charging services in an increasingly interconnected and vulnerable digital landscape. This is the first in a planned series of papers exploring the implementation of zero trust in EV charging infrastructure. Each paper will delve into different aspects and applications of zero trust, highlighting how various work processes and requirements can lead to distinct architectural designs. These architectures will be tailored to address specific security challenges and operational needs within the EV charging ecosystem, ensuring a robust and adaptable security framework.

33 ADVANCED PROPULSION SYSTEMS

Real-time evaluation of cybersecurity threats to DER inverter grid-support functions

In this project we aim to contribute to the understanding of the type and severity of potential cybersecurity attacks to the grid-support functionalities of DER systems interconnected to the AC distribution grid via inverters. Our preliminary work focused on developing a small-scale testbed allowing to study cybersecurity threats to an isolated photovoltaic-battery system using a real-time simulator (Typhoon HIL602+) with a real DNP3 communication connection over TCP/IP, allowing for safe and efficient monitoring and manipulation of data traffic between the simulated hardware and supervisory control and data acquisition (SCADA) system. In this project we propose to expand upon this development by utilizing a) a recently acquired NovaCor RTDS (Real Rime digital Simulator) to emulate the DER-inverter-grid topology including main grid-support functions as defined by IEEE Std. 1547-2018, and b) an industrial control and automation device to enable realistic evaluation of control functions and utilization of communication protocols for real-time data transmission.

24 POWER TRANSMISSION AND DISTRIBUTION

Verifying Cyber Implementation Best Practices With Malcolm

Network traffic analysis can reveal a lot about what's right or wrong with a network's cybersecurity footing. Using Malcolm, a powerful open-source network traffic analysis tool suite for network security monitoring, cyber analysts and asset owners can validate cybersecurity best practices and uncover red flags in network configuration, including: proper network segmentation east-west (cross-segment) and north-south traffic unsecure or outdated network protocols authentication using clear text credentials rogue devices and services unexpected protocols (e.g., IPv6, DNS, DHCP, update checks, etc.) suspicious file transfers

99 GENERAL AND MISCELLANEOUS

Multi‐Sensor Trajectory Reconstruction of the 24 April 2025 Alaska Fireball and Implications for Planetary Defense

On 24 April 2025 at 18:30:57 UTC, a bright daytime fireball over Southcentral Alaska was detected by 37 seismic stations, 16 single infrasound sensors, and four infrasound arrays, yielding 30 ballistic and multiple fragmentation arrivals. Here, the unprecedented density of seismoacoustic coverage enabled detailed reconstruction of the event using acoustic signals, with fragmentation source locations further guiding the identification of Doppler weather radar signatures of a meteorite fall. Incorporation of a radar-derived terminal point yielded a final trajectory solution, which agreed closely with an independent optical trajectory solution from video analysis. The reconstructed entry parameters from seismoacoustic analysis indicate a velocity of 25.3 km/s, an entry angle of 19°, and an energy release of ∼38 t TNT equivalent. Assuming a chondritic composition, the pre-entry object diameter was ∼0.7 m. Using orbital parameters from the optical solution, we estimate meteoroid composition as most likely an L-type ordinary chondrite. The event occurred in the sub-Arctic, where space-based optical systems face challenges in detection, demonstrating the critical role of dense ground-based seismoacoustic networks in characterizing high-latitude atmospheric entries. This uniquely well-recorded event demonstrates the capability of dense seismoacoustic networks to constrain bolide trajectories, energetics, and fragmentation, with radar and optical data providing critical confirmation and complementary perspectives. These results bridge the methodological gap between planetary-defense monitoring of natural impactors and space-traffic analyses of artificial reentries, illustrating how multi-sensor integration can deliver calibration-grade trajectories even for unpredicted events.

Fireball

Operational Guidelines for Use of Radiation Portal Monitors in Nuclear Facilities

This article provides guidelines (not requirements) for the testing, operation, and maintenance of radiation portal monitors used to scan pedestrian and vehicular traffic entering or exiting nuclear facilities to prevent unauthorized removal of nuclear material. The intended audience is facility managers, supervisors, and operators who are responsible for establishing and maintaining radiation detection systems, who are likely well acquainted with physical security procedures, but may not have a familiarity with the operation of radiation detection.

Enders, Alexander [Oak Ridge National Laboratory (

MSU IETC ML for Modbus (AN EDGE)

This study explores machine learning for decoding Modbus RTU data using K-Nearest Neighbors (KNN) models. An initial KNN model trained on 8,000 packets achieved 95.15% accuracy. Although ML improves generalization, accuracy still falls short of deterministic methods. These findings have implications for Modbus traffic analysis, intrusion detection in industrial networks, and adaptive error correction in real-time monitoring systems. By refining ML-based decoding, future work could enable more efficient anomaly detection and predictive maintenance in industrial automation and cybersecurity applications.

Communication Protocol

Designing resilient IoT and Edge Computing with federated tinyML

The rapid growth of the Internet of Things (IoT) and Edge Computing (EC) has brought significant conveniences to modern society but has also greatly expanded the cyber attack surfaces, particularly as these technologies are being increasingly integrated into critical systems such as power grids, healthcare, and smart homes. Here, to improve IoT/EC’s cybersecurity posture, we leveraged Artificial Intelligence (AI) and Machine Learning (ML) by employing tinyML to monitor voluminous IoT data for cyber threats while addressing devices’ resource constraints, and utilizing Federated Learning (FL) to share local detection knowledge across the system while preserving privacy. Building on our three-layer architecture combining tinyML and FL to enhance autonomous cyber attack detection, this paper demonstrated that the architecture improves detection accuracy, reduces resource consumption, and enables lightweight, secure IoT device monitoring. These results were validated using the public N-BaIoT dataset as well as real IoT network traffic data collected under multiple attack scenarios from our testbeds. Additionally, we introduced an enhanced FL methodology with a novel preprocessing stage, including federated feature selection and global preprocessor construction, to address IoT/EC data heterogeneity. We developed a physical IoT testbed for attack simulations and data collection, implemented a tinyML-powered detector for realistic model validation, and also built a virtual testbed for scalable evaluations of FL models across diverse network environments.

Cognitive cyber

Analyzing Risks of Virtual Private Network Connections

The use of Splunk for analyzing VPN logs is an effective approach for identifying vulnerabilities in network endpoints. Splunk, a powerful platform for searching, monitoring, and analyzing machine-generated data, enables organizations to aggregate VPN logs in real-time, providing insights into network activity, user behavior, and potential security risks. By indexing VPN traffic and authentication logs, security teams can track abnormal patterns such as multiple failed login attempts, unusual IP addresses, or unexpected changes in bandwidth usage, all of which could indicate potential vulnerabilities or breaches. With Splunk’s advanced search and reporting capabilities, users can create custom dashboards and alerts to detect suspicious activities. Automated searches can flag endpoints exhibiting unusual behavior, while correlation analysis can identify links between compromised devices and broader network vulnerabilities. In particular, Splunk's machine learning capabilities can be leveraged to predict and prevent threats by identifying trends that might otherwise be missed in traditional log analysis. This proactive approach to monitoring VPN logs allows for the early detection of security weaknesses, enabling rapid response and minimizing potential damage to network integrity. By enhancing endpoint visibility, Splunk plays a crucial role in securing remote connections and safeguarding sensitive information. Additionally, Splunk’s automation and alerting features allow teams to create custom workflows that notify them of vulnerable or misconfigured endpoints identified through Shodan. This synergy between Splunk’s log analysis and Shodan’s device intelligence enhances an organization’s ability to proactively identify and mitigate security risks, improving the overall resilience of their VPN infrastructure.

97 MATHEMATICS AND COMPUTING

Heavy metal imprints in Antarctic snow from research and tourism

Antarctica, long regarded as one of the last pristine environments on Earth, is increasingly affected by human activity. As tourism surges and scientific operations expand, air pollution from local emissions is raising new environmental concerns. Here, in this study, we analyze surface snow samples collected along a ~2,000 km transect, from the South Shetland Islands (62°S) to the Ellsworth Mountains (79°S), to map the geochemical fingerprints of aerosol deposition. We identify distinct spatial patterns shaped by crustal, marine, biogenic, and anthropogenic sources. Notably, we detect heavy metal imprints in the snow chemistry of the northern Antarctic Peninsula, where major research stations are concentrated and marine tourism traffic is most intense. Our findings shed light on the extent of the impacts from energy-intensive local activities in Antarctica, underscoring the need for enhanced environmental monitoring and sustainable management strategies in this fragile region.

Cordero, Raúl R. [Univ. of Groningen, Leeuwarden (

Vedizar Fingerprinter

SAND2025-03289O Vedizar Fingerprinter simplifies the process of identifying devices on a network by analyzing traffic data. It uses a unique library to recognize different devices, making it easier for users to understand what is happening on their networks. This software is ideal for IT and operational technology environments, helping organizations monitor their networks effectively. By saving results in a database, it allows for easy access and review of device information. Users can enhance their network security and optimize performance without needing specialized hardware or technical expertise. Sandia National Laboratories is a multimission laboratory managed and operated by National Technology & Engineering Solutions of Sandia, LLC, a wholly owned subsidiary of Honeywell International Inc., for the U.S. Department of Energy’s National Nuclear Security Administration under contract DE-NA0003525.

Jacobellis, John [Sandia National Lab. (SNL-CA), L

Short-Term Energy and Meteorological Impacts on Thanksgiving CO2 in Salt Lake City

Abstract Long-term, high-frequency atmospheric CO2 measurements at multiple sites in the Salt Lake City (SLC), Utah, reveal that annual and monthly CO2 variability aligns with a priori estimates of emissions from anthropogenic and biological sources. In this study, we investigate whether short-term fluctuations in anthropogenic emissions, as captured in the Vulcan3 dataset for the United States, can be detected in atmospheric CO2 observations. Specifically, we focus on Thanksgiving holidays, when traffic and energy usage patterns differ from the rest of November. Onroad CO2 emissions exhibit a double peak during weekday morning and evening rush hours but remain relatively low on weekends and Thanksgiving. Interestingly, CO2 mole fractions during Thanksgiving were higher than the rest of November at all SLC monitoring sites, particularly from 2008 to 2013. This increase is partially attributed to elevated energy-related emissions — especially residential sources — and meteorological factors such as weak wind speeds, cold temperature, and a low planetary boundary layer height (PBLH).&#xD;&#xD; While CO₂ emissions and mole fraction patterns align over time, notable spatial differences exist. For instance, the near-highway site in Murray shows the highest CO₂ mole fractions despite low local emissions, suggesting pollution transport via highways and wind advection. Random Forest model-based SHapley Additive exPlanations (SHAP) analysis reveals that onroad emissions dominate CO2 contributions on weekdays and weekends, while energy-related emissions play a larger role during Thanksgiving, alongside meteorological drivers such as wind speed and PBLH. Across six urban cities, CO2 emissions display a consistent pattern: residential and commercial (onroad) emissions peak during Thanksgiving (weekday) with substantial (minimal) year-to-year variability. These findings highlight that urban CO₂ variability is driven by the combined influence of emissions and meteorology, underscoring the need for integrated mitigation strategies. Additionally, multi-site measurements are essential for accurate source attribution and the development of effective policy interventions. &#xD;

Ryoo, Ju-Mee (ORCID:0000000234256296)