27 August 2026

Your Leading International Construction and Infrastructure News Platform
Header Banner – Finance
Header Banner – Finance
Header Banner – Finance
Header Banner – Finance
Header Banner – Finance
Header Banner – Finance
Header Banner – Finance
Inside Georgia’s Work to Secure the Connected Highway

Inside Georgia’s Work to Secure the Connected Highway

Inside Georgia’s Work to Secure the Connected Highway

A remotely operated gate controlling access to an express lane looks like a piece of highway equipment. Behind it, however, sits something increasingly familiar from factories, power stations and water treatment plants: a programmable logic controller connected to a communications network and capable of turning digital instructions into physical action.

Georgia’s highway network contains a growing collection of these connected systems. Fibre-optic communications, traffic detectors, CCTV cameras, variable message signs, roadside sensors and programmable logic controllers feed information into the Georgia Department of Transportation’s traffic management infrastructure and allow operators to monitor and manage conditions across the network.

Georgia Tech researchers and the Georgia Department of Transportation (GDOT) are now examining how those systems can be protected as highway operations become more connected and automated. The nine-month research programme began in December 2025 and is applying machine learning to transportation network cybersecurity, including the detection of abnormal data that could indicate a cyber threat.

Alongside that work, researchers are using digital twins to study the behaviour of the programmable logic controllers that provide the connection between digital networks and physical highway equipment. It puts road infrastructure into cybersecurity territory already familiar to operators of industrial plants and utilities, where protecting a network is also about ensuring that connected equipment continues to behave as intended.

Briefing

  • Georgia Tech and GDOT began the cybersecurity research programme in December 2025, with completion scheduled for September 2026.
  • The project is developing a software prototype for preparing transportation network data for machine-learning anomaly detection.
  • Researchers are studying programmable logic controllers used to control physical highway equipment, including gates associated with reversible traffic lanes.
  • Digital twins allow researchers to examine controller behaviour against simulated network and traffic conditions.
  • The work is intended to provide a foundation for securing greater automation within Georgia’s future transportation network.

From Traffic Management to Cyber-Physical Infrastructure

Intelligent transportation systems have been developing for decades, and Georgia was an early adopter. GDOT’s NaviGAtor system brings together information from CCTV cameras, vehicle detection systems, roadway weather equipment and other roadside devices. The state’s Traffic Management Center uses that information for incident management, traffic control and traveller information.

The communications beneath those services are extensive. GDOT documentation describes field equipment communicating over fibre-optic infrastructure using IP and Ethernet technologies, with cameras, vehicle detection equipment, changeable message signs and ramp-metering systems connected into the wider transportation management architecture.

Traditional information technology cybersecurity is heavily concerned with data, systems and access. Operational technology introduces another dimension because computers are connected to equipment that does something in the physical world. A PLC may receive sensor data, process it and issue commands to machinery. Within transportation infrastructure, such controllers can operate motors associated with gates at toll, high-occupancy or reversible lanes. The computer and the piece of highway machinery therefore form part of the same operational system.

Teague Buchanan, GDOT’s Assistant Administrator for IT Applications, said: β€œWe are starting to see these networked devices in the marketplace starting to leverage the power of AI.”

More capable equipment may provide transportation agencies with better automation and decision-making, but it also increases the need to understand how those devices communicate, what normal behaviour looks like and how abnormal activity can be identified before it affects operations.

Teaching the Network What Normal Looks Like

The GDOT research programme, identified as RP 25-24, is formally titled the Foundational Study for Transportation Network Cyber Threat Detection Using AI/ML.

Its initial objective is relatively contained. Georgia Tech is developing a foundational software prototype capable of identifying, sourcing and packaging data so that it can be used by machine-learning anomaly-detection models. The research programme also calls for the partners to assess one representative cyber threat and measure detection performance using standard measures including classification accuracy, precision and recall.

The project is establishing whether transportation network data can be organised and analysed well enough for machine learning to recognise potentially suspicious behaviour. A model can learn patterns associated with ordinary network activity and identify deviations worthy of investigation. An anomaly does not necessarily indicate an attack; equipment failures, unusual operating conditions and communications problems can also produce unexpected behaviour, making reliable classification an important part of the work.

Yatis Dodia, a senior research engineer at the Georgia Tech Research Institute and Georgia Tech School of Cybersecurity and Privacy, described the programme as foundational.

β€œWith GDOT, we’ve launched a foundational effort to think more about cybersecurity, the cyber resilience of transportation-related networks, and how aspects of AI could be leveraged to ensure safety, security, and trust in these critical transportation systems,” he said.

A transportation agency cannot casually experiment with cyberattacks against equipment operating beside live traffic. Georgia Tech researchers are therefore creating a simulated copy of GDOT network infrastructure to study how programmable logic controllers behave while interacting with a representation of the wider transportation system.

Digital Twins for Highway Cybersecurity

Digital twins are already finding roles across infrastructure and industrial engineering because they allow behaviour to be examined without interfering with the physical asset. In cybersecurity research, that separation allows researchers to introduce abnormal conditions, examine communications and investigate controller responses without using an operational highway as the laboratory.

Saman Zonouz, an associate professor in Georgia Tech’s School of Cybersecurity and Privacy and School of Electrical and Computer Engineering, has researched PLC security across transportation, healthcare, manufacturing and power systems.

β€œWhen we study a PLC, we don’t just look at it as a box,” Zonouz explained. β€œWe operate it next to the digital twin β€” the simulation of the network infrastructure and the traffic. That allows us to analyze what the PLC is doing when it interacts with that simulation, giving us better information than if we had just analyzed the controller by itself.”

A controller may be functioning perfectly according to its internal logic while acting on an inappropriate or malicious external instruction. Signals can arrive through wired or wireless connections and originate from numerous pieces of equipment elsewhere in the system. Researchers therefore need to understand the environment in which a controller operates, the information it receives and whether the resulting physical behaviour is consistent with legitimate highway operations.

The PLC Problem Moves onto the Road

PLCs have controlled industrial processes for decades and are fundamental to modern manufacturing, utilities and automation. Their growing presence in connected infrastructure has nevertheless attracted substantial cybersecurity attention.

Zonouz’s wider research at Georgia Tech focuses on cyber-physical and embedded systems security, including attack detection and response. Previous Georgia Tech research has examined vulnerabilities associated with PLCs whose interfaces and control capabilities have become increasingly connected through conventional network and web technologies.

Transportation inherits some of those concerns as roadside equipment evolves, complicated by the long working lives of infrastructure assets. Consumer IT equipment may be replaced within a few years, while traffic control equipment, communications cabinets, roadside sensors and associated infrastructure can remain operational far longer. Networks can consequently contain equipment from different generations and suppliers while the communications architecture around them continues to evolve.

GDOT’s intelligent transportation infrastructure already combines surveillance, detection, control and information dissemination across a distributed network. As more intelligence moves into individual devices, securing the central traffic management system alone is insufficient. The behaviour and communications of field equipment become part of the security architecture as well.

Security Before Greater Automation

GDOT’s interest in the problem comes before full automation rather than after it. Infrastructure systems can be difficult to redesign once equipment, communications standards, procurement requirements and operating procedures have become established.

Buchanan expects transportation automation to increase.

β€œRight now, not everything in the transportation system is automated, but it will eventually get that way,” he said. β€œWe realize that using AI powered devices also carries a risk. We need to build in security upfront so we can implement this technology while avoiding the risks associated with it.”

Connected infrastructure procurement increasingly needs to consider how equipment is authenticated, how software is updated, what data devices generate, how abnormal behaviour can be detected and how systems should respond when communications cannot be trusted. A device expected to remain beside a highway for many years also needs a security strategy capable of surviving changes in both technology and threats.

Automation makes those questions more consequential because systems may eventually perform more operational functions without continuous human intervention. A traffic camera providing information to an operator is one level of automation. Software interpreting sensor information and recommending a response goes further. A connected system able to initiate a physical response introduces another level again.

Building the Security Foundation

The current Georgia programme remains deliberately modest. It is a foundational study rather than the deployment of a statewide autonomous cybersecurity platform, with the initial work scheduled to conclude in September 2026. Researchers are expected to provide GDOT with findings that can inform future cybersecurity and automation planning.

The timing gives GDOT an opportunity to establish the data, models and security requirements before more sophisticated automation becomes embedded in the highway network. Georgia already has much of the physical and communications foundation: distributed roadside equipment feeding information into traffic management systems that can monitor conditions, communicate with drivers and support operational responses.

A gate controlling a reversible express lane shows how quickly the distinction between digital and physical infrastructure can disappear. Its operation may depend upon controllers, communications links, software, sensors and commands passing through a much larger system. As those systems take on more of the work involved in managing the highway, every part of that chain has to operate as intended.

Inside Georgia's Work to Secure the Connected Highway

Key Industry Questions

  1. What is Georgia Tech developing for GDOT? The project is developing a foundational software prototype for sourcing and preparing transportation network data for machine-learning anomaly detection, alongside research into the security of connected transportation equipment.
  2. What does machine learning do in this application? Machine-learning models can examine patterns within network data and identify abnormalities that may warrant investigation as potential cyber threats.
  3. Why are programmable logic controllers important to highway cybersecurity? PLCs can translate digital information and commands into physical actions. In transportation systems they may control equipment such as gates associated with reversible or managed lanes.
  4. Why use a digital twin? A digital twin allows researchers to reproduce aspects of the network, traffic environment and controller interaction without experimenting on operational highway infrastructure.
  5. Does an anomaly automatically indicate a cyberattack? No. Unusual data can have legitimate causes, which is why detection accuracy and the ability to distinguish different conditions are important.
  6. Is Georgia’s highway network already automated? It already contains substantial automated and remotely managed infrastructure, but GDOT expects the degree of automation to increase.
  7. Why address cybersecurity before adding more AI? Security requirements are easier to incorporate into system architecture, procurement and operating procedures before automation becomes deeply embedded in infrastructure.
  8. When is the initial research expected to finish? The GDOT research programme is scheduled for completion in September 2026.

Strategic Takeaways

  1. Highway cybersecurity increasingly concerns physical operations as well as the protection of information and computer networks.
  2. PLCs create an important bridge between connected digital infrastructure and machinery capable of affecting traffic operations.
  3. Machine-learning anomaly detection depends heavily on understanding and preparing operational data before sophisticated models can be useful.
  4. Digital twins provide transportation agencies with a practical environment for investigating cyber-physical behaviour without disrupting live infrastructure.
  5. Cybersecurity requirements are likely to become an increasingly important part of ITS equipment specifications and infrastructure procurement as automation expands.
Content Adverts
Content Adverts
Content Adverts
Content Adverts
Content Adverts
Content Adverts
Content Adverts
Content Adverts
Content Adverts

About The Author

Anthony brings a wealth of global experience to his role as Managing Editor of Highways.Today. With an extensive career spanning several decades in the construction industry, Anthony has worked on diverse projects across continents, gaining valuable insights and expertise in highway construction, infrastructure development, and innovative engineering solutions. His international experience equips him with a unique perspective on the challenges and opportunities within the highways industry.

Related posts

Content Adverts
Content Adverts
Content Adverts
Content Adverts
Content Adverts
Content Adverts
Content Adverts
Content Adverts
Content Adverts