Pith. sign in

REVIEW 3 major objections 6 minor 68 references

Safety Interventions against Adversarial Patches in an Open-Source Driver Assistance System

T0 review · 3 major / 6 minor · reviewed 2026-08-16 · deepseek-v4-flash

Pith's one-line read Auto-braking and drivers can beat ML fixes for camera patches.

desk verdict A useful, honestly scoped simulation study of safety interventions against perception faults in OpenPilot, but the title overstates the attack model—the paper injects fixed DNN-output errors from prior work rather than evaluating real adversarial patches. read the letter →

arxiv 2504.18990 v2 pith:HEVVT6BX submitted 2025-04-26 cs.CR cs.SE

classification cs.CRcs.SE
keywords adversarialpatchesADASautomaticemergencybrakingfaultinjectiondriverinterventionOpenPilotperceptionattackssafetycoordination
verification ladder T0 review T1 audit T2 compute T3 formal

The pith

A machine-rendered reading of the paper's core claim, the machinery that carries it, and where it could break.

The reading

The paper asks whether the safety machinery already built into a modern Level-2 driver assistance system—automatic emergency braking, forward-collision warnings, command-range safety checks, and the human driver—can absorb the effects of adversarial patches that fool the camera, and whether an added machine-learning safeguard would do better. By simulating such a system under attacks that corrupt relative-distance and lane-curvature predictions, it finds that existing mechanisms are the main line of defense: AEB fed by an independent sensor prevents up to 100% of simulated forward collisions, driver reactions prevent 40–69% of accidents depending on attack type, and the ML baseline prevents only 23–40%. It also finds that priority conflicts can erode safety, as when high-priority AEB overrides a driver's better-suited response to lateral attacks. If this is right, the resilience discussion shifts from adding new ML defenses to hardening the sensors behind AEB and coordinating interventions.

What carries the argument

The load-bearing mechanism is a time-to-collision-based emergency-braking controller, with $ttc = RD/RS$ (relative distance divided by relative speed), that issues a forward-collision warning and then applies staged braking (90%, 95%, then full force) as TTC falls below speed-dependent thresholds. The paper varies one property of that mechanism: whether AEB receives the same corrupted perception predictions that drive the controller, no sensor input at all, or an independent secure sensor stream. Around this controller sit a command-range safety checker that blocks gas and brake commands outside 2 to -3.5 m/s², and a driver-reaction simulator with fixed reaction times that brakes or steers back toward lane center when warnings trigger. The fault-injection engine that emulates adversarial patches by directly perturbing relative distance (10–38 m) and desired curvature (3%) is what connects this safety stack to physical attacks. The argument works by comparing accident-prevention rates across configurations of this stack.

What would settle it

Place a real printed or projected adversarial patch on a lead vehicle and on the road ahead of a car running the same assisted-driving software, instrument the perception module to record the relative-distance and curvature errors actually produced, and check whether those errors fall in the injected ranges at the assumed trigger distances; if they do not, the reported prevention rates and mechanism rankings need to be recomputed.

Watch

Extended reading notes

Core claim

On the paper's own terms, the central discovery is that a real Level-2 ADAS is not defenseless against perception attacks: the defense is already in the car. OpenPilot alone collides or leaves the lane in every simulated attack configuration, but adding a time-to-collision-based AEB that reads an independent, uncompromised data stream prevents 100% of forward-collision accidents from relative-distance attacks, whereas the same AEB fed by the same corrupted perception stream prevents only 19.17%. Human drivers reacting after 2.5 seconds prevent 40–69.17% of accidents depending on attack type, and an LSTM (long short-term memory) machine-learning mitigation model prevents 23.08–40%. Lateral lane-centering attacks remain only partially mitigated—AEB's indirect prevention of lateral accidents tops out near 40.83%—and in mixed attacks the fixed priority order that lets AEB override the driver lowers the combined prevention rate from 69.17% to about 51.67%. These numbers are the paper's claim, not a field-wide result.

Load-bearing premise

The paper's prevention rates all stand on the assumption that injecting fixed errors into the perception output—10–38 m in relative distance and a 3% curvature deviation—faithfully reproduces what a physical adversarial patch does to a camera-based assisted-driving system in this simulator; if that mapping is off, every comparison in the paper measures a different attack than the one claimed.

Editorial extensions

If this is right

  • If AEB reads an independent sensor, forward-collision prevention reaches 100% in the simulated relative-distance attacks; the same AEB on compromised data prevents only 19.17%, so redundant sensing is the single highest-leverage safety feature tested.
  • Driver reaction time matters measurably: shortening it from 2.5 s to 1.0 s raises accident prevention on relative-distance attacks from 40% to 53.33%, and on curvature attacks from 48.33% to 77.50%.
  • Lateral attacks are the hard case: no tested mechanism exceeds 53.33% prevention for curvature attacks, and AEB only helps because aggressive acceleration toward the lead vehicle triggers braking before the ego vehicle leaves the lane.
  • Priority conflicts degrade safety: when AEB overrides the driver in mixed attacks, the combined prevention rate falls from 69.17% (driver alone) to 50–51.67%, so intervention coordination is itself a safety parameter.
  • An ML recovery model trained on fault-free commands is not a substitute for these mechanisms: it prevents 23.08–40% of accidents and even introduces new lateral accidents in relative-distance attacks.

Reading between the lines

Editorial extensions of the paper, not claims the author makes directly.

  • Editorial inference: the 100% figure for independent-sensor AEB suggests that adding a redundant perception channel—radar or a second camera with different failure modes—is likely to buy more real-world safety than retraining the control model, but only if the redundant channel actually covers the same failure modes as the attacked camera.
  • Editorial inference: because the fault-injection magnitudes come from prior work on different perception models, the exact percentages should be read as ordering evidence rather than predictive field rates; a real patch that induces a different error distribution, or errors that vary over time, could reorder the mechanisms.
  • Editorial inference: a testable extension would run the same scenario suite with adaptive or temporally varying fault magnitudes to see whether the rank ordering survives; the fixed 10–38 m and 3% magnitudes are the point where the simulation is most likely to diverge from physics.
  • Editorial inference: the finding that AEB prevents some lateral accidents implies that longitudinal emergency braking doubles as a coarse lateral safety net; designers could exploit this deliberately by coupling AEB activation to lane-departure risk rather than treating the two directions as independent.
Share X Bluesky LinkedIn Reddit HN

Signed reviews

No signed human review yet.

Editorial analysis

A structured set of objections, weighed in public.

Desk editor's note, referee report, and a circularity audit.

Referee Report

3 major / 6 minor

Summary. The paper evaluates the resilience of OpenPilot v0.9.7, an open-source Level-2 ADAS, against adversarial perception attacks by emulating attack effects through source-level fault injection into DNN outputs (relative-distance errors and curvature deviations borrowed from prior work [9], [10]). It integrates OpenPilot with the MetaDrive simulator and implements safety mechanisms—AEBS in three configurations, firmware-style safety checks, a rule-based driver reaction simulator, and an LSTM-based ML mitigation baseline—then measures accident prevention rates across six driving scenarios. The authors report that OpenPilot is vulnerable to the emulated attacks, that AEB with independent sensor data and timely human intervention prevent a large fraction of accidents (up to 100% for relative-distance attacks), that lateral-direction attacks remain difficult to mitigate, and that the ML baseline underperforms basic safety mechanisms. They also identify conflicts among safety interventions, particularly the priority of AEB overriding driver inputs, as an important design issue.

Significance. If the results are accepted, the paper makes a useful contribution by building an open-source, closed-loop simulation platform that couples real ADAS control software (OpenPilot) with a physical-world simulator and multiple safety mechanisms; the artifact is available at a DOI, which aids reproducibility. The comparison of AEBS configurations, human interventions, and an ML-based mitigation method is a valuable empirical evaluation for the dependable-systems and automotive-security communities. The observation that independent-sensor AEB outperforms both ML mitigation and delayed driver reactions is plausible and practically relevant. However, the significance is limited by the unvalidated assumption that the fixed fault-injection magnitudes faithfully represent physical adversarial-patch effects, and by the small number of repetitions per configuration. The paper's main value is as a fault-injection-based sensitivity study of safety interventions, not as a direct evaluation of physical adversarial patches as the title suggests.

major comments (3)
  1. [§III-B / Table VI] The central empirical claim rests on an unvalidated transfer assumption. The paper emulates adversarial patches by injecting fixed perception errors (10–38 m relative-distance errors and a 3% curvature deviation) taken from prior work [9], [10], but it does not demonstrate that these magnitudes, trigger conditions, and error shapes reproduce what an actual adversarial patch does to OpenPilot v0.9.7's DNN inside MetaDrive. Different model versions, camera parameters, or driving environments could produce different error profiles, so every prevention rate in Table VI, and hence Observation 3, may quantify a different phenomenon than 'adversarial patch attack.' I recommend either validating the mapping with at least one real-patch evaluation on this platform or reframing the claims as an evaluation of safety interventions under fault-injection-emulated perception errors, and adjusting the title and abstract accordingly.
  2. [§IV-E (Table VI, Table VII)] Each fault-injection configuration is repeated only 10 times, but results are presented as point percentages with no variance or confidence intervals. With 10 trials, a single accident shifts a prevention rate by 10 percentage points, which makes the main comparative claims (e.g., 40% driver braking vs. 100% AEB for relative-distance attacks, and the non-monotonic reaction-time results in Table VII) statistically fragile. Please report per-run outcomes, confidence intervals, or at least state the exact number of trials for every cell and discuss the resulting uncertainty when making comparative statements.
  3. [§IV-D / Algorithm 1] The ML baseline's behavior depends on the threshold τ and the bias parameter b0, but the paper never reports their values or the procedure used to set them. Without this information, the comparison in Table VI that supports Observation 6 is not reproducible and could be sensitive to hyperparameter choices. Please report the exact settings or provide a sensitivity analysis over τ and b0 to demonstrate that the comparison with AEB and driver intervention is fair and robust.
minor comments (6)
  1. [Title, Abstract, §III-B] The title and abstract repeatedly say 'adversarial patches,' but Section III-B states that the work 'directly emulates' patch effects by injecting attacks into DNN outputs; please use terminology that consistently distinguishes emulated perception errors from physically realized adversarial patches.
  2. [§IV / Table IV] The text says each configuration is repeated 10 times, yet Table IV reports benign-condition outcomes with denominators of 20 (e.g., '1/20', '10/20'); please clarify how many runs were performed for the no-attack baseline and whether the 360-simulation count refers only to fault-injection runs.
  3. [§V] The Threats to Validity section mentions simulation-only scope and driver-model simplification, but it does not list the fault-injection-to-patch mapping as a limitation; this is a significant validity threat and should be acknowledged explicitly.
  4. [Table VI] Table VI is dense and the header abbreviations ('Comp.', 'Indep.', and the multiple 'Trigger Rate' columns) are hard to parse; consider splitting the table into sub-tables by fault type or adding a legend that explains each row's intervention configuration.
  5. [§III-C, Eq. (4)] The speed-dependent TTC thresholds (3.8, 5.8, 9.8) are introduced without explaining their units or provenance beyond a citation to prior work; a brief sentence clarifying their basis would improve reproducibility.
  6. [§IV-E6] The claim that the ML model 'prevented nearly all A1 accidents caused by relative distance attacks' is supported by the table, but it would benefit from a per-scenario breakdown given the small number of trials and the wide spread in the other rows.

Circularity Check

0 steps flagged · score 0.0 of 10

No significant circularity; the paper's conclusions are empirical outcomes of a closed-loop simulation, with attack magnitudes, safety thresholds, and driver reaction times taken as external inputs rather than derived from the target results.

full rationale

The paper's derivation chain is empirical rather than definitional. Attack magnitudes are external inputs: Section III-B states the authors 'directly emulate the effect of the patches by injecting attacks into the DNN output and getting the range of attack values of mispredictions corresponding to adversarial patches from previous work [9], [10],' and Table III fixes relative-distance errors (10/15/38 m) and a 3% curvature deviation before any safety-intervention experiment is run. The AEBS behavior is defined by independent standards-style formulas (TTC = RD/RS; braking cascade thresholds t_pb1, t_pb2, t_fb), not by fitting Table VI. Driver reaction times (2.5 s nominal, 1.0-3.5 s sweep) come from external transportation guidelines and prior studies. The ML baseline is trained on fault-free OpenPilot data and then evaluated under injected faults; its 23.08%-40% prevention rates are measured outcomes, not fitted parameters. The central claims (e.g., independent-sensor AEB prevents up to 100% of relative-distance attacks, driver intervention prevents 40%-69.17%) are computed accident-prevention rates from simulation runs, and none of these target quantities appears as an input to the fault injection, AEBS, driver, or ML models. One cited source for attack magnitudes, [9], shares authors with this paper, but it is prior empirical work on attack ranges rather than an unverified theorem, and the current paper's conclusions do not reduce to that citation by construction. The reviewer's concern that injected magnitudes may not faithfully represent physical adversarial patches is a threat-to-validity issue about the mapping between simulation and reality, not a circularity in the derivation chain. Accordingly, no circular step is present.

Assumptions & free parameters 6 free parameters · 5 assumptions · 0 invented entities

The simulation uses several externally supplied attack magnitudes and human behavior parameters; none are derived from first principles. The most load-bearing is the equivalence between fixed fault-injection values and real adversarial patch effects, which is assumed from prior work. The remaining items are standard domain simplifications for simulation-based ADAS safety studies.

free parameters (6)
  • Grid of relative-distance fault injection magnitudes = 10 m, 15 m, 38 m for RD bins below 80 m, 25 m, and 20 m
    Taken from prior work [9] to imitate an adversarial patch on the lead vehicle; not measured in this system, so it is a free input that determines ACC attack severity.
  • Curvature fault injection magnitude = 3% deviation in desired curvature
    Taken from [10] for a dirty-road patch; used for all ALC attacks with no distribution or system-specific calibration.
  • Driver reaction time = 2.5 s default, varied 1.0-3.5 s
    Assumed average reaction time from literature, applied uniformly to all driver interventions; a central sensitivity parameter of the safety results.
  • AEBS braking TTC coefficients = t_pb1 = V/3.8, t_pb2 = V/5.8, t_fb = V/9.8
    Chosen following [9,34]; the 90%, 95%, and 100% braking levels are modeling choices, not measured from a specific vehicle.
  • AEBS driver deceleration a_driver = not specified
    Equation (2) uses a_driver to compute stopping time, but no value is given, leaving a hidden free parameter in FCW timing.
  • ML baseline activation threshold tau and bias b0 = not specified
    Algorithm 1 relies on accumulated-error threshold tau and bias b(t), but the actual values are not reported, making the ML mitigation comparison underdetermined.
assumptions (5)
  • domain assumption Fault injection from [9,10] is a faithful substitute for physical adversarial patches
    Section III-B explicitly emulates patch effects by injecting fixed perception errors from prior work; the entire attack evaluation depends on this mapping.
  • domain assumption OpenPilot v0.9.7 in MetaDrive 0.4.2.3 captures real vehicle control behavior
    Section IV uses the simulator as the testbed; no real-vehicle experiments are run, and the paper acknowledges this in Section V.
  • domain assumption The rule-based driver reaction simulator approximates human emergency responses
    Section III-C and Table II use fixed activation conditions and a single reaction time; the paper itself flags this as a limitation in Section V.
  • domain assumption The AEBS model per UN R152 and prior work is representative of production AEB
    Section III-C implements a simplified TTC-threshold AEBS without sensor fusion or detailed vehicle dynamics, which may differ from real production systems.
  • domain assumption MetaDrive physics on a dry highway map supports the hazard and accident definitions
    Section IV-A defines A1, A2, H1, and H2 at the simulator level; these are not physical crash measurements and depend on simulator fidelity.

how reviews work

0 comments
Cite this review

Pith. "Pith review of Safety Interventions against Adversarial Patches in an Open-Source Driver Assistance System." pith.science (2026). https://pith.science/paper/HEVVT6BX

@misc{pith2026250418990,
  author       = {Pith},
  title        = {Pith review of: Safety Interventions against Adversarial Patches in an Open-Source Driver Assistance System},
  year         = {2026},
  howpublished = {\url{https://pith.science/paper/HEVVT6BX}},
  note         = {Machine review of arXiv:2504.18990}
}
read the original abstract

Drivers are becoming increasingly reliant on advanced driver assistance systems (ADAS) as autonomous driving technology becomes more popular and developed with advanced safety features to enhance road safety. However, the increasing complexity of the ADAS makes autonomous vehicles (AVs) more exposed to attacks and accidental faults. In this paper, we evaluate the resilience of a widely used ADAS against safety-critical attacks that target perception inputs. Various safety mechanisms are simulated to assess their impact on mitigating attacks and enhancing ADAS resilience. Experimental results highlight the importance of timely intervention by human drivers and automated safety mechanisms in preventing accidents in both driving and lateral directions and the need to resolve conflicts among safety interventions to enhance system resilience and reliability.

Figures

Figures reproduced from arXiv: 2504.18990 by the authors.

Figure 1
Figure 1. Overview of the Control Structure of an ADAS. [PITH_FULL_IMAGE:figures/full_fig_p002_1.png] view at source ↗
Figure 2
Figure 2. Example physical attacks against ACC and ALC by adding [PITH_FULL_IMAGE:figures/full_fig_p003_2.png] view at source ↗
Figure 3
Figure 3. Overview of closed-loop simulation platform. [PITH_FULL_IMAGE:figures/full_fig_p005_3.png] view at source ↗
Figures from the paper (2 more)
Figure 5
Figure 5. Figure 5: Speed and Distance to Lane Lines when Approaching LV. [PITH_FULL_IMAGE:figures/full_fig_p006_5.png]
Figure 6
Figure 6. Figure 6: Speed and Relative Distance under Fault Injection. [PITH_FULL_IMAGE:figures/full_fig_p007_6.png]

Discussion (0). Continue with ORCID to comment.

Reference graph

Works this paper leans on

68 extracted references · 61 canonical work pages

  1. [9]

    Runtime Stealthy Perception Attacks against DNN- Based Adaptive Cruise Control Systems,

    X. Zhou, A. Chen, M. Kouzel, H. Ren, M. McCarty, C. Nita-Rotaru, and H. Alemzadeh, “Runtime Stealthy Perception Attacks against DNN- Based Adaptive Cruise Control Systems,” inACM Asia Conference on Computer and Communications Security (ASIA CCS), 2025

  2. [10]

    Dirty Road Can Attack: Security of Deep Learning Based Automated Lane Centering under{Physical-World}Attack,

    T. Sato, J. Shen, N. Wang, Y . Jia, X. Lin, and Q. A. Chen, “Dirty Road Can Attack: Security of Deep Learning Based Automated Lane Centering under{Physical-World}Attack,” in30th USENIX Security Symposium (USENIX Security 21), 2021, pp. 3309–3326

  3. [1]

    SAE Levels of Driving Automation™ Refined for Clarity and Interna- tional Audience,

    “SAE Levels of Driving Automation™ Refined for Clarity and Interna- tional Audience,” https://www.sae.org/blog/sae-j3016-update, 2021

  4. [2]

    ADAS Market Report 2030

    “ADAS Market Report 2030.” [Online]. Avail- able: https://www.marketsandmarkets.com/Market-Reports/driver- assistance-systems-market-1201.html

  5. [3]

    Global Advanced Driver Assistance Systems (ADAS) Market Size and Forecast

    “Global Advanced Driver Assistance Systems (ADAS) Market Size and Forecast.” [Online]. Available: https://www.verifiedmarketresearch.com/product/global-advanced- driver-assistance-systems-adas-market-size-and-forecast/

  6. [4]

    The 23 Most Dangerous Cars on the Road

    “The 23 Most Dangerous Cars on the Road.” [Online]. Available: https://www.iseecars.com/most-dangerous-cars-study

  7. [5]

    Summary Report: Standing General Order on Crash Reporting for Level 2 Advanced Driver Assistance Systems,

    U.S. Department of Transportation National Highway Traffic Safety Administration, “Summary Report: Standing General Order on Crash Reporting for Level 2 Advanced Driver Assistance Systems,” Tech. Rep., 2022. [Online]. Available: https://www.nhtsa.gov/sites/nhtsa.gov/ files/2022-06/ADAS-L2-SGO-Report-June-2022.pdf

  8. [6]

    ML-Based Fault Injection for Autonomous Vehicles: A Case for Bayesian Fault Injection,

    S. Jha, S. Banerjee, T. Tsai, S. K. Hari, M. B. Sullivan, Z. T. Kalbar- czyk, S. W. Keckler, and R. K. Iyer, “ML-Based Fault Injection for Autonomous Vehicles: A Case for Bayesian Fault Injection,” in2019 49th annual IEEE/IFIP international conference on dependable systems and networks (DSN). IEEE, 2019, pp. 112–124

Show all 68 references
  1. [7]

    ML-Driven Malware that Targets A V Safety,

    S. Jha, S. Cui, S. Banerjee, J. Cyriac, T. Tsai, Z. Kalbarczyk, and R. K. Iyer, “ML-Driven Malware that Targets A V Safety,” in2020 50th Annual IEEE/IFIP International Conference on Dependable Systems and Networks (DSN). IEEE, 2020, pp. 113–124

  2. [8]

    Robustness testing of data and knowledge driven anomaly detection in cyber-physical systems,

    X. Zhou, M. Kouzel, and H. Alemzadeh, “Robustness testing of data and knowledge driven anomaly detection in cyber-physical systems,” in 2022 52nd Annual IEEE/IFIP International Conference on Dependable Systems and Networks Workshops (DSN-W). IEEE, 2022, pp. 44–51

  3. [11]

    Tesla Autopilot,

    “Tesla Autopilot,” https://www.tesla.com/autopilot

  4. [12]

    Subaru EyeSight,

    “Subaru EyeSight,” https://www.subaru.com/eyesight.html

  5. [13]

    Fooling Detection Alone is not Enough: First Adversarial Attack against Multiple Object Tracking,

    Y . Jia, Y . Lu, J. Shen, Q. A. Chen, Z. Zhong, and T. Wei, “Fooling Detection Alone is not Enough: First Adversarial Attack against Multiple Object Tracking,”arXiv:1905.11026, 2019

  6. [14]

    Robust Physical-World Attacks on Deep Learning Visual Classification,

    K. Eykholt, I. Evtimov, E. Fernandes, B. Li, A. Rahmati, C. Xiao, A. Prakash, T. Kohno, and D. Song, “Robust Physical-World Attacks on Deep Learning Visual Classification,” inProceedings of the IEEE conference on computer vision and pattern recognition, 2018, pp. 1625– 1634

  7. [15]

    Experimental Security Research of Tesla Autopilot,

    Tencent, “Experimental Security Research of Tesla Autopilot,”Tencent Keen Security Lab, 2019

  8. [16]

    Adversarial Camera Stickers: A Phys- ical Camera-Based Attack on Deep Learning Systems,

    J. Li, F. Schmidt, and Z. Kolter, “Adversarial Camera Stickers: A Phys- ical Camera-Based Attack on Deep Learning Systems,” inInternational Conference on Machine Learning, 2019, pp. 3896–3904

  9. [17]

    WIP: Towards the Practicality of the Adversarial Attack on Object Tracking in Autonomous Driving,

    C. Ma, N. Wang, Q. A. Chen, and C. Shen, “WIP: Towards the Practicality of the Adversarial Attack on Object Tracking in Autonomous Driving,” inInaugural International Symposium on Vehicle Security & Privacy, 2023

  10. [18]

    Sequential Attacks on Kalman Filter-Based forward Collision Warning Systems,

    Y . Ma, J. A. Sharp, R. Wang, E. Fernandes, and X. Zhu, “Sequential Attacks on Kalman Filter-Based forward Collision Warning Systems,” in Proceedings of the AAAI Conference on Artificial Intelligence, vol. 35, no. 10, 2021, pp. 8865–8873

  11. [19]

    Software-Based Realtime Recovery from Sensor Attacks on Robotic Vehicles,

    H. Choi, S. Kate, Y . Aafer, X. Zhang, and D. Xu, “Software-Based Realtime Recovery from Sensor Attacks on Robotic Vehicles,” in 23rd International Symposium on Research in Attacks, Intrusions and Defenses (RAID), 2020, pp. 349–364

  12. [20]

    PID- Piper: Recovering Robotic Vehicles from Physical Attacks,

    P. Dash, G. Li, Z. Chen, M. Karimibiuki, and K. Pattabiraman, “PID- Piper: Recovering Robotic Vehicles from Physical Attacks,” in2021 51st Annual IEEE/IFIP International Conference on Dependable Systems and Networks (DSN). IEEE, 2021, pp. 26–38

  13. [21]

    Specguard: Specification Aware Recovery for Robotic Autonomous Vehicles from Physical Attacks,

    P. Dash, E. Chan, and K. Pattabiraman, “Specguard: Specification Aware Recovery for Robotic Autonomous Vehicles from Physical Attacks,” in Proceedings of the 2024 on ACM SIGSAC Conference on Computer and Communications Security, 2024, pp. 1849–1863

  14. [22]

    OpenPilot

    Comma.ai, “OpenPilot.” [Online]. Available: https://github.com/ commaai/openpilot

  15. [23]

    Supported Cars by OpenPilot,

    “Supported Cars by OpenPilot,” https://github.com/commaai/openpilot/ blob/master/docs/CARS.md

  16. [24]

    MetaDrive: Composing Diverse Driving Scenarios for Generalizable Reinforcement Learning,

    Q. Li, Z. Peng, Z. Xue, Q. Zhang, and B. Zhou, “MetaDrive: Composing Diverse Driving Scenarios for Generalizable Reinforcement Learning,” arXiv preprint arXiv:2109.12674, 2021

  17. [25]

    CARLA: An Open Urban Driving Simulator,

    A. Dosovitskiy, G. Ros, F. Codevilla, A. Lopez, and V . Koltun, “CARLA: An Open Urban Driving Simulator,” inProceedings of the 1st Annual Conference on Robot Learning, 2017, pp. 1–16

  18. [26]

    Dynamic Adver- sarial Patch for Evading Object Detection Models,

    S. Hoory, T. Shapira, A. Shabtai, and Y . Elovici, “Dynamic Adver- sarial Patch for Evading Object Detection Models,”arXiv preprint arXiv:2010.13070, 2020

  19. [27]

    Dynamic Adversarial Attacks on Autonomous Driving Systems,

    A. Chahe, C. Wang, A. Jeyapratap, K. Xu, and L. Zhou, “Dynamic Adversarial Attacks on Autonomous Driving Systems,”arXiv preprint arXiv:2312.06701, 2023

  20. [28]

    That Person Moves Like a Car: Misclassification Attack Detection for Autonomous Systems Using Spatiotemporal Consistency,

    Y . Man, R. Muller, M. Li, Z. B. Celik, and R. Gerdes, “That Person Moves Like a Car: Misclassification Attack Detection for Autonomous Systems Using Spatiotemporal Consistency,” in32nd USENIX Security Symposium (USENIX Security 23), 2023, pp. 6929–6946

  21. [29]

    A First Physical-World Trajectory Prediction Attack via LiDAR-Induced Deceptions in Autonomous Driving,

    Y . Lou, Y . Zhu, Q. Song, R. Tan, C. Qiao, W.-B. Lee, and J. Wang, “A First Physical-World Trajectory Prediction Attack via LiDAR-Induced Deceptions in Autonomous Driving,”arXiv preprint arXiv:2406.11707, 2024

  22. [30]

    Adversarial Attacks on Adaptive Cruise Control Systems,

    Y . Guo, T. Sato, Y . Cao, Q. A. Chen, and Y . Cheng, “Adversarial Attacks on Adaptive Cruise Control Systems,” inProceedings of Cyber-Physical Systems and IoT Week 2023, 2023, pp. 49–54

  23. [31]

    Implementation of Autonomous Emergency Braking (AEB), the Next Step in Euro NCAP’S Safety Assessment,

    R. Schram, A. Williams, and M. van Ratingen, “Implementation of Autonomous Emergency Braking (AEB), the Next Step in Euro NCAP’S Safety Assessment,”ESV , Seoul, 2013

  24. [32]

    66–89, 2020

    “UN Regulation No 152 – Uniform Provisions Concerning the Ap- proval of Motor Vehicles with Regard to the Advanced Emergency Braking System (AEBS) for M1 and N1 Vehicles [2020/1597],” http: //data.europa.eu/eli/reg/2020/1597/oj, pp. 66–89, 2020

  25. [33]

    GRV A-12-50r1e.pdf,

    “GRV A-12-50r1e.pdf,” https://unece.org/sites/default/files/2022-01/ GRV A-12-50r1e.pdf

  26. [34]

    Autonomous Vehicle with Emergency Braking Algorithm Based on Multi-Sensor Fusion and Super Twisting Speed Controller,

    T. Alsuwian, R. B. Saeed, and A. A. Amin, “Autonomous Vehicle with Emergency Braking Algorithm Based on Multi-Sensor Fusion and Super Twisting Speed Controller,”Applied Sciences, vol. 12, no. 17, p. 8458, Aug. 2022

  27. [35]

    Strategic Safety-Critical Attacks against an Advanced Driver Assistance System,

    X. Zhou, A. Schmedding, H. Ren, L. Yang, P. Schowitz, E. Smirni, and H. Alemzadeh, “Strategic Safety-Critical Attacks against an Advanced Driver Assistance System,” in2022 52nd Annual IEEE/IFIP Interna- tional Conference on Dependable Systems and Networks (DSN). IEEE, 2022, pp. 79–87

  28. [36]

    Available: https://github.com/commaai/ panda

    Comma.ai, “Panda.” [Online]. Available: https://github.com/commaai/ panda

  29. [37]

    OpenPilot - Safety Architecture,

    “OpenPilot - Safety Architecture,” 2018. [Online]. Available: https://blog.comma.ai/how-to-write-a-car-port-for-openpilot/ #background--safety-architecture [38]Intelligent transport systems – Full speed range adaptive cruise con- trol (FSRA) systems – Performance requirements ...

  30. [39]

    Safe Driving,

    Virginia DMV, “Safe Driving,” https://www.dmv.virginia.gov/webdoc/ pdf/dmv39d.pdf

  31. [40]

    Driver Brake Response to Sudden Unintended Acceleration while Parking,

    J. G. Gaspar and D. V . McGehee, “Driver Brake Response to Sudden Unintended Acceleration while Parking,”Transportation research inter- disciplinary pertives, vol. 2, p. 100039, 2019

  32. [41]

    California Commercial Driver Handbook,

    “California Commercial Driver Handbook,” https://www.dmv.ca.gov/ portal/uploads/2020/06/comlhdbk.pdf, 2019

  33. [42]

    Reference Guide for NSC DDC Instructor-led Training,

    N. S. Council, “Reference Guide for NSC DDC Instructor-led Training,” https://www.nsc.org/getmedia/ a46d07cb-faf1-4572-8317-661e7f77ef7a/instructor-admin- reference-guide.pdf?srsltid=AfmBOop5BGVGMZl63t_31waS- 4mgVvsUl4of_64EOIWQELG30mgonCkW, 2014

  34. [43]

    Automotive Technology: What to Know About Automatic Emergency Braking,

    M. International, “Automotive Technology: What to Know About Automatic Emergency Braking,” April 2024, [Online; accessed 5-December-2024]. [Online]. Avail- able: https://maycointernational.com/blog/automotive-technology-what- to-know-about-automatic-emergency-braking/

  35. [44]

    New Automatic Emergency Braking Safety Standard will Save Lives, Expert Explains,

    V . T. News, “New Automatic Emergency Braking Safety Standard will Save Lives, Expert Explains,” April 2024, [Online; accessed 5- December-2024]. [Online]. Available: https://news.vt.edu/articles/2024/ 04/Automatic-emergency-braking-safety-expert.html

  36. [45]

    Pre-Crash Scenario Typology for Crash Avoidance Research,

    W. G. Najm, J. D. Smith, M. Yanagisawa, and John A. V olpe National Transportation Systems Center (U.S.), “Pre-Crash Scenario Typology for Crash Avoidance Research,” Tech. Rep. DOT-VNTSC-NHTSA-06- 02, Apr. 2007

  37. [46]

    Use of Risk-Adjusted CUSUM and RSPRT Charts for Monitoring in Medical Contexts,

    O. A. Grigg, V . Farewell, and D. Spiegelhalter, “Use of Risk-Adjusted CUSUM and RSPRT Charts for Monitoring in Medical Contexts,” Statistical methods in medical research, vol. 12, no. 2, pp. 147–170, 2003

  38. [47]

    Brake reaction time,

    University of Idaho, “Brake reaction time,” https:// www.webpages.uidaho.edu/niatt_labmanual/chapters/geometricdesign/ theoryandconcepts/BrakeReactionTime.htm, n.d., [Online; accessed 27-February-2025]

  39. [48]

    Differences of Drivers’ Reaction Times According to Age and Mental Workload,

    H. Makishita and K. Matsunaga, “Differences of Drivers’ Reaction Times According to Age and Mental Workload,”Accident Analysis & Prevention, vol. 40, no. 2, pp. 567–575, 2008. [Online]. Available: https://www.sciencedirect.com/science/article/pii/S0001457507001418

  40. [49]

    How Much Does Rain Reduce Your Traction?

    Supercars.net, “How Much Does Rain Reduce Your Traction?” https: //www.supercars.net/blog/how-much-does-rain-reduce-your-traction/, n.d., [Online; accessed 27-February-2025]

  41. [50]

    Weather condition effect on the road surface friction: A Preliminary assessment based on sensor data,

    M. Rasol, F. Schmidt, and S. Ientile, “Weather condition effect on the road surface friction: A Preliminary assessment based on sensor data,” inLife-Cycle of Structures and Infrastructure Systems. CRC Press, 2023, pp. 2187–2194

  42. [51]

    Phantom of the ADAS: Securing Advanced Driver-Assistance Systems from Split-Second Phantom Attacks,

    B. Nassi, Y . Mirsky, D. Nassi, R. Ben-Netanel, O. Drokin, and Y . Elovici, “Phantom of the ADAS: Securing Advanced Driver-Assistance Systems from Split-Second Phantom Attacks,” in Proceedings of the 2020 ACM SIGSAC Conference on Computer and Communications Security, ser. CCS ...

  43. [52]

    WIP: Practical Removal Attacks on LiDAR-Based Object De- tection in Autonomous Driving,

    T. Sato, Y . Hayakawa, R. Suzuki, Y . Shiiki, K. Yoshioka, and Q. A. Chen, “WIP: Practical Removal Attacks on LiDAR-Based Object De- tection in Autonomous Driving,” inInaugural International Symposium on Vehicle Security & Privacy, 2023

  44. [53]

    Drift with Devil: Security of Multi-Sensor Fusion Based Localization in High-Level Autonomous Driving under GPS Spoofing,

    J. Shen, J. Y . Won, Z. Chen, and Q. A. Chen, “Drift with Devil: Security of Multi-Sensor Fusion Based Localization in High-Level Autonomous Driving under GPS Spoofing,” inProceedings of the 29th USENIX Conference on Security Symposium, 2020, pp. 931–948

  45. [54]

    Spoofing Attacks against Vehicular FMCW Radar,

    R. Komissarov and A. Wool, “Spoofing Attacks against Vehicular FMCW Radar,” inProceedings of the 5th Workshop on Attacks and Solutions in Hardware Security, 2021, pp. 91–97

  46. [55]

    MobilBye: Attacking ADAS with Camera Spoofing,

    D. Nassi, R. Ben-Netanel, Y . Elovici, and B. Nassi, “MobilBye: Attacking ADAS with Camera Spoofing,” 2019. [Online]. Available: https://arxiv.org/abs/1906.09765

  47. [56]

    Strategic resilience evaluation of neural networks within autonomous vehicle software,

    A. Schmedding, P. Schowitz, X. Zhou, Y . Lu, L. Yang, H. Alemzadeh, and E. Smirni, “Strategic resilience evaluation of neural networks within autonomous vehicle software,” inInternational Conference on Computer Safety, Reliability, and Security. Springer, 2024, pp. 33–48

  48. [57]

    Aspis: Lightweight neural network protection against soft errors,

    A. Schmedding, L. Yang, A. Jog, and E. Smirni, “Aspis: Lightweight neural network protection against soft errors,” in35th IEEE International Symposium on Software Reliability Engineering, ISSRE 2024, Tsukuba, Japan, October 28-31, 2024. IEEE, 2024, pp. 248–259

  49. [58]

    Practical resilience analysis of GPGPU applications in the presence of single- and multi-bit faults,

    L. Yang, B. Nie, A. Jog, and E. Smirni, “Practical resilience analysis of GPGPU applications in the presence of single- and multi-bit faults,” IEEE Trans. Computers, vol. 70, no. 1, pp. 30–44, 2021

  50. [59]

    Malicious Attacks against Multi-Sensor Fusion in Autonomous Driving,

    Y . Zhu, C. Miao, H. Xue, Y . Yu, L. Su, and C. Qiao, “Malicious Attacks against Multi-Sensor Fusion in Autonomous Driving,” in Proceedings of the 30th Annual International Conference on Mobile Computing and Networking, ser. ACM MobiCom ’24. New York, NY , USA: Association for...

  51. [60]

    Hybrid knowledge and data driven synthesis of runtime monitors for cyber- physical systems,

    X. Zhou, B. Ahmed, J. H. Aylor, P. Asare, and H. Alemzadeh, “Hybrid knowledge and data driven synthesis of runtime monitors for cyber- physical systems,”IEEE Transactions on Dependable and Secure Com- puting, vol. 21, no. 1, pp. 12–30, 2023

  52. [61]

    Simulation-Based Adversarial Test Generation for Autonomous Vehicles with Machine Learning Components,

    C. E. Tuncali, G. Fainekos, H. Ito, and J. Kapinski, “Simulation-Based Adversarial Test Generation for Autonomous Vehicles with Machine Learning Components,” in2018 IEEE Intelligent Vehicles Symposium (IV). IEEE, 2018, pp. 1555–1562

  53. [62]

    Deeptest: Automated Testing of Deep-Neural-Network-Driven Autonomous Cars,

    Y . Tian, K. Pei, S. Jana, and B. Ray, “Deeptest: Automated Testing of Deep-Neural-Network-Driven Autonomous Cars,” inProceedings of the 40th international conference on software engineering, 2018, pp. 303–314

  54. [63]

    Testing Advanced Driver Assistance Systems using Multi-Objective Search and Neural Networks,

    R. Ben Abdessalem, S. Nejati, L. C. Briand, and T. Stifter, “Testing Advanced Driver Assistance Systems using Multi-Objective Search and Neural Networks,” inProceedings of the 31st IEEE/ACM International Conference on Automated Software Engineering, 2016, pp. 63–74

  55. [64]

    Testing Vision-Based Control Systems using Learnable Evolutionary Algo- rithms,

    R. B. Abdessalem, S. Nejati, L. C. Briand, and T. Stifter, “Testing Vision-Based Control Systems using Learnable Evolutionary Algo- rithms,” in2018 IEEE/ACM 40th International Conference on Software Engineering (ICSE). IEEE, 2018, pp. 1016–1026

  56. [65]

    Automatically Testing Self- Driving Cars with Search-Based Procedural Content Generation,

    A. Gambi, M. Mueller, and G. Fraser, “Automatically Testing Self- Driving Cars with Search-Based Procedural Content Generation,” in Proceedings of the 28th ACM SIGSOFT International Symposium on Software Testing and Analysis, 2019, pp. 318–328

  57. [66]

    ADAS Reliability against Weather Conditions: Quantification of Performance Robustness

    T. Rahman, A. Liu, D. S. Cheema, V . Chirila, D. C. Transport, and C. Canada, “ADAS Reliability against Weather Conditions: Quantification of Performance Robustness.” [Online]. Available: https://api.semanticscholar.org/CorpusID:268237053

  58. [67]

    Analyzing and Improving Resilience and Robustness of Autonomous Systems,

    Z. Wan, K. Swaminathan, P.-Y . Chen, N. Chandramoorthy, and A. Raychowdhury, “Analyzing and Improving Resilience and Robustness of Autonomous Systems,” inProceedings of the 41st IEEE/ACM International Conference on Computer-Aided Design, ser. ICCAD ’22. New York, NY , USA: Ass...

  59. [68]

    Automated Vehicle Lane Centering System Requirements Informed by Resilience Engineering and a Solution Using Infrastructure- Based Sensors,

    J. F. Rojas, P. Patil, A. M. Masterson, T. H. Bradley, A. R. Ekti, and Z. D. Asher, “Automated Vehicle Lane Centering System Requirements Informed by Resilience Engineering and a Solution Using Infrastructure- Based Sensors,”IEEE Access, vol. 12, pp. 97 605–97 620, 2024

  60. [69]

    Cyberattacks on Adaptive Cruise Controls and Emergency Braking Systems: Adversary Models, Impact Assess- ment, and Countermeasures,

    A. Berdich and B. Groza, “Cyberattacks on Adaptive Cruise Controls and Emergency Braking Systems: Adversary Models, Impact Assess- ment, and Countermeasures,”IEEE Transactions on Reliability, vol. 73, no. 2, pp. 1216–1230, 2024

Pith tools

Reviewed August 16, 2026 · model on record in the stance chip above.