A privacy threat-modeling study applies the LINDDUN framework to connected electric-vehicle data flows, identifying risks across collection, identity, location, and third-party services. The research translates those findings into technical safeguards, governance practices, and user-control measures for privacy-conscious automotive system design and regulatory compliance at scale.
— New research applies the LINDDUN privacy threat-modeling framework to the data connected electric vehicles exchange with cloud platforms and third-party services, an area of rising concern for U.S. regulators, automakers, and drivers.
As connected electric vehicles collect and transmit increasing volumes of location, identity, and behavioral data, privacy engineer Mingjie Chen has published research offering automotive engineering, compliance, and policy audiences a structured method for identifying privacy risks and weighing safeguards. In the paper “Exploration of the Application of the LINDDUN Model in Privacy Protection for Electric Vehicle Users,” published in Engineering Advances (Vol. 5, Iss. 4, 2025), Chen adapts an established privacy threat-modeling framework to modern electric-vehicle data flows and translates it into technical and governance safeguards.
Connected-vehicle data privacy and security have become a growing U.S. priority. In 2024, Federal Trade Commission staff highlighted the legal and privacy risks of collecting, using, and sharing connected-vehicle data and urged data minimization. In January 2025, the FTC brought its first connected-vehicle data enforcement action against General Motors and OnStar, with the resulting settlement finalized in January 2026. States have also taken action. California’s Privacy Protection Agency began reviewing connected-vehicle privacy practices in 2023 and reached a settlement with an automaker in 2025, while Oregon expanded its privacy law in 2025 to cover certain vehicle data handled by motor-vehicle manufacturers and their affiliates regardless of its usual consumer-number thresholds.
A modern electric vehicle works like a data platform on wheels, producing sensitive records of where a driver goes, how they drive, and who they are. That information passes among onboard systems, manufacturer clouds, and third-party providers, improving convenience while widening the paths through which personal data can leak or be misused. Chen’s research targets this gap, offering engineering and compliance teams a structured approach for examining privacy risks during system design.
Chen’s work provides a repeatable analytical process. He applies LINDDUN’s seven threat categories, including linkability and disclosure of information, across three dimensions, namely data collection and transmission, identity and location privacy, and third-party service interfaces. The paper includes four threat-modeling tables that organize the relevant entities, data stores, data flows, and processes. This helps translate an abstract framework into a structured reference that engineering and compliance teams can adapt to specific systems.
From that analysis, Chen derives layered safeguards. On the technical side, he recommends end-to-end encryption, anonymization and de-identification, dynamic access control, multi-factor authentication, real-time monitoring, homomorphic encryption, and differential privacy. On the governance side, he calls for legitimacy review before data is collected, data minimization, periodic audits, and dedicated privacy governance committees. The research also emphasizes users’ rights to be informed, to choose, and to delete their data.
“Electric vehicles have quietly become one of the most data-rich products people use every day, yet privacy is still too often bolted on at the end,” said Mingjie Chen. “My goal was to give engineers and regulators a shared, repeatable way to find these risks early, so protection is built into the vehicle rather than added after a problem appears.”
Mingjie Chen brings a cross-disciplinary background spanning privacy engineering, software engineering, and machine learning research. He holds a Master of Science in Information Technology, Privacy Engineering, from Carnegie Mellon University and is a Certified Information Privacy Technologist (CIPT) credentialed by the International Association of Privacy Professionals (IAPP). His work applies privacy threat modeling and privacy-enhancing technologies in the automotive and connected-vehicle domain, and his broader research includes privacy-preserving AI training via federated learning, real-time compliance monitoring, and privacy-oriented AI compliance tooling.
By applying an established threat-modeling framework to a fast-growing, data-intensive domain, Chen’s study shows how structured privacy analysis can support connected-vehicle and smart-mobility services as they expand. The study concludes that effective connected-vehicle privacy protection requires technical safeguards, organizational governance, meaningful user control, and greater coordination across platforms and providers.
Contact Info:
Name: Mingjie Chen
Email: Send Email
Organization: Mingjie Chen
Website: https://scholar.google.com/citations?user=foBwMxEAAAAJ
Release ID: 89198684
In the event of encountering any errors, concerns, or inconsistencies within the content shared in this press release, we kindly request that you immediately contact us at [email protected] (it is important to note that this email is the authorized channel for such matters, sending multiple emails to multiple addresses does not necessarily help expedite your request). Our dedicated team will be readily accessible to address your feedback within 8 hours and take appropriate measures to rectify any identified issues or facilitate press release takedowns. Ensuring accuracy and reliability are central to our commitment.
The information provided in this article was created by MarketersMEDIA Newswire, our news partner. The author's opinions and the content shared on this page are their own and may not necessarily represent the perspectives of Siam News Network.
