Electric Vehicles (EVs) are becoming a major part of everyday transportation: manufacturers sold about 21 million EVs worldwide in 2025, and Lithium Iron Phosphate (LiFePO4, LFP) batteries supplied more than 55% of deployed EV battery capacity. At the same time, production is highly concentrated. China manufactured about 70% of electric cars and more than 80% of battery cells worldwide in 2025. This concentration makes the security of the battery supply chain increasingly important, since a malicious modification introduced before vehicle deployment could remain hidden throughout normal operation and affect Electric Vehicles worldwide. LFP batteries make this problem particularly relevant because their voltage does not change much across their state-of-charge range. A battery can therefore appear electrically normal even while its internal energy distribution changes. The Battery Management System (BMS), which estimates battery state and controls charging, protection, and cell balancing, consequently becomes a critical point of trust. In this thesis we show how that trust can be abused. We introduce Silent Drain, a supply-chain attack that turns the BMS’s own active cell-balancing function against the battery. Instead of issuing obviously invalid commands, the attacker uses legitimate balancing actions to gradually create cell imbalance while remaining within the protection limits implemented by the system. We evaluate the attack through ten matched nominal and compromised one-year simulations, each covering 730 WLTC Class 3b drives and 16 984 km. Silent Drain reduces median usable-energy State of Health (SOH) of the battery pack from 96.62% to 92.11% in just one year, leaving approximately 1.90 kW h of deliverable energy unavailable, while triggering none of the implemented BMS fault flags. From the driver’s perspective, the attack remains difficult to notice: annual grid-energy consumption rises by only 0.856%, and the final daily recharge is extended by just 3.18 s. At the cell level, however, the attack leaves clear signatures in SOC imbalance and balancing activity. At the scale of the approximately 11 million LFP-equipped EVs sold in 2025, an attack that silently accelerates battery end-of-life could turn a hidden BMS compromise into a massive fleet-wide economic loss. These results show that a compromised BMS can quietly reduce the usable energy of an EV battery without causing an obvious failure. They also motivate new defenses that compare real battery behavior with trusted nominal models and monitor how the BMS uses normally legitimate control functions.

Silent Drain: A Novel Stealthy Degradation Attack against LiFePO₄ Battery Packs

AMADORI, ELEONORA
2025/2026

Abstract

Electric Vehicles (EVs) are becoming a major part of everyday transportation: manufacturers sold about 21 million EVs worldwide in 2025, and Lithium Iron Phosphate (LiFePO4, LFP) batteries supplied more than 55% of deployed EV battery capacity. At the same time, production is highly concentrated. China manufactured about 70% of electric cars and more than 80% of battery cells worldwide in 2025. This concentration makes the security of the battery supply chain increasingly important, since a malicious modification introduced before vehicle deployment could remain hidden throughout normal operation and affect Electric Vehicles worldwide. LFP batteries make this problem particularly relevant because their voltage does not change much across their state-of-charge range. A battery can therefore appear electrically normal even while its internal energy distribution changes. The Battery Management System (BMS), which estimates battery state and controls charging, protection, and cell balancing, consequently becomes a critical point of trust. In this thesis we show how that trust can be abused. We introduce Silent Drain, a supply-chain attack that turns the BMS’s own active cell-balancing function against the battery. Instead of issuing obviously invalid commands, the attacker uses legitimate balancing actions to gradually create cell imbalance while remaining within the protection limits implemented by the system. We evaluate the attack through ten matched nominal and compromised one-year simulations, each covering 730 WLTC Class 3b drives and 16 984 km. Silent Drain reduces median usable-energy State of Health (SOH) of the battery pack from 96.62% to 92.11% in just one year, leaving approximately 1.90 kW h of deliverable energy unavailable, while triggering none of the implemented BMS fault flags. From the driver’s perspective, the attack remains difficult to notice: annual grid-energy consumption rises by only 0.856%, and the final daily recharge is extended by just 3.18 s. At the cell level, however, the attack leaves clear signatures in SOC imbalance and balancing activity. At the scale of the approximately 11 million LFP-equipped EVs sold in 2025, an attack that silently accelerates battery end-of-life could turn a hidden BMS compromise into a massive fleet-wide economic loss. These results show that a compromised BMS can quietly reduce the usable energy of an EV battery without causing an obvious failure. They also motivate new defenses that compare real battery behavior with trusted nominal models and monitor how the BMS uses normally legitimate control functions.
2025
Silent Drain: A Novel Stealthy Degradation Attack against LiFePO₄ Battery Packs
Cyber-Physical
Electric Vehicles
BMS Security
Supply-Chain
EV Battery Simulator
File in questo prodotto:
File Dimensione Formato  
Amadori_Eleonora.pdf

accesso aperto

Dimensione 7.06 MB
Formato Adobe PDF
7.06 MB Adobe PDF Visualizza/Apri

The text of this website © Università degli studi di Padova. Full Text are published under a non-exclusive license. Metadata are under a CC0 License

Utilizza questo identificativo per citare o creare un link a questo documento: https://hdl.handle.net/20.500.12608/115856