REVIEW 3 major objections 6 minor 68 references
Safety Interventions against Adversarial Patches in an Open-Source Driver Assistance System
T0 review · 3 major / 6 minor · reviewed 2026-08-16 · deepseek-v4-flash
Pith's one-line read Auto-braking and drivers can beat ML fixes for camera patches.
desk verdict A useful, honestly scoped simulation study of safety interventions against perception faults in OpenPilot, but the title overstates the attack model—the paper injects fixed DNN-output errors from prior work rather than evaluating real adversarial patches. read the letter →
The pith
A machine-rendered reading of the paper's core claim, the machinery that carries it, and where it could break.
The reading
What carries the argument
The load-bearing mechanism is a time-to-collision-based emergency-braking controller, with $ttc = RD/RS$ (relative distance divided by relative speed), that issues a forward-collision warning and then applies staged braking (90%, 95%, then full force) as TTC falls below speed-dependent thresholds. The paper varies one property of that mechanism: whether AEB receives the same corrupted perception predictions that drive the controller, no sensor input at all, or an independent secure sensor stream. Around this controller sit a command-range safety checker that blocks gas and brake commands outside 2 to -3.5 m/s², and a driver-reaction simulator with fixed reaction times that brakes or steers back toward lane center when warnings trigger. The fault-injection engine that emulates adversarial patches by directly perturbing relative distance (10–38 m) and desired curvature (3%) is what connects this safety stack to physical attacks. The argument works by comparing accident-prevention rates across configurations of this stack.
What would settle it
Place a real printed or projected adversarial patch on a lead vehicle and on the road ahead of a car running the same assisted-driving software, instrument the perception module to record the relative-distance and curvature errors actually produced, and check whether those errors fall in the injected ranges at the assumed trigger distances; if they do not, the reported prevention rates and mechanism rankings need to be recomputed.
Extended reading notes
Core claim
On the paper's own terms, the central discovery is that a real Level-2 ADAS is not defenseless against perception attacks: the defense is already in the car. OpenPilot alone collides or leaves the lane in every simulated attack configuration, but adding a time-to-collision-based AEB that reads an independent, uncompromised data stream prevents 100% of forward-collision accidents from relative-distance attacks, whereas the same AEB fed by the same corrupted perception stream prevents only 19.17%. Human drivers reacting after 2.5 seconds prevent 40–69.17% of accidents depending on attack type, and an LSTM (long short-term memory) machine-learning mitigation model prevents 23.08–40%. Lateral lane-centering attacks remain only partially mitigated—AEB's indirect prevention of lateral accidents tops out near 40.83%—and in mixed attacks the fixed priority order that lets AEB override the driver lowers the combined prevention rate from 69.17% to about 51.67%. These numbers are the paper's claim, not a field-wide result.
Load-bearing premise
The paper's prevention rates all stand on the assumption that injecting fixed errors into the perception output—10–38 m in relative distance and a 3% curvature deviation—faithfully reproduces what a physical adversarial patch does to a camera-based assisted-driving system in this simulator; if that mapping is off, every comparison in the paper measures a different attack than the one claimed.
Editorial extensions
If this is right
- If AEB reads an independent sensor, forward-collision prevention reaches 100% in the simulated relative-distance attacks; the same AEB on compromised data prevents only 19.17%, so redundant sensing is the single highest-leverage safety feature tested.
- Driver reaction time matters measurably: shortening it from 2.5 s to 1.0 s raises accident prevention on relative-distance attacks from 40% to 53.33%, and on curvature attacks from 48.33% to 77.50%.
- Lateral attacks are the hard case: no tested mechanism exceeds 53.33% prevention for curvature attacks, and AEB only helps because aggressive acceleration toward the lead vehicle triggers braking before the ego vehicle leaves the lane.
- Priority conflicts degrade safety: when AEB overrides the driver in mixed attacks, the combined prevention rate falls from 69.17% (driver alone) to 50–51.67%, so intervention coordination is itself a safety parameter.
- An ML recovery model trained on fault-free commands is not a substitute for these mechanisms: it prevents 23.08–40% of accidents and even introduces new lateral accidents in relative-distance attacks.
Reading between the lines
- Editorial inference: the 100% figure for independent-sensor AEB suggests that adding a redundant perception channel—radar or a second camera with different failure modes—is likely to buy more real-world safety than retraining the control model, but only if the redundant channel actually covers the same failure modes as the attacked camera.
- Editorial inference: because the fault-injection magnitudes come from prior work on different perception models, the exact percentages should be read as ordering evidence rather than predictive field rates; a real patch that induces a different error distribution, or errors that vary over time, could reorder the mechanisms.
- Editorial inference: a testable extension would run the same scenario suite with adaptive or temporally varying fault magnitudes to see whether the rank ordering survives; the fixed 10–38 m and 3% magnitudes are the point where the simulation is most likely to diverge from physics.
- Editorial inference: the finding that AEB prevents some lateral accidents implies that longitudinal emergency braking doubles as a coarse lateral safety net; designers could exploit this deliberately by coupling AEB activation to lane-departure risk rather than treating the two directions as independent.
Signed reviews
Editorial analysis
A structured set of objections, weighed in public.
Referee Report
Summary. The paper evaluates the resilience of OpenPilot v0.9.7, an open-source Level-2 ADAS, against adversarial perception attacks by emulating attack effects through source-level fault injection into DNN outputs (relative-distance errors and curvature deviations borrowed from prior work [9], [10]). It integrates OpenPilot with the MetaDrive simulator and implements safety mechanisms—AEBS in three configurations, firmware-style safety checks, a rule-based driver reaction simulator, and an LSTM-based ML mitigation baseline—then measures accident prevention rates across six driving scenarios. The authors report that OpenPilot is vulnerable to the emulated attacks, that AEB with independent sensor data and timely human intervention prevent a large fraction of accidents (up to 100% for relative-distance attacks), that lateral-direction attacks remain difficult to mitigate, and that the ML baseline underperforms basic safety mechanisms. They also identify conflicts among safety interventions, particularly the priority of AEB overriding driver inputs, as an important design issue.
Significance. If the results are accepted, the paper makes a useful contribution by building an open-source, closed-loop simulation platform that couples real ADAS control software (OpenPilot) with a physical-world simulator and multiple safety mechanisms; the artifact is available at a DOI, which aids reproducibility. The comparison of AEBS configurations, human interventions, and an ML-based mitigation method is a valuable empirical evaluation for the dependable-systems and automotive-security communities. The observation that independent-sensor AEB outperforms both ML mitigation and delayed driver reactions is plausible and practically relevant. However, the significance is limited by the unvalidated assumption that the fixed fault-injection magnitudes faithfully represent physical adversarial-patch effects, and by the small number of repetitions per configuration. The paper's main value is as a fault-injection-based sensitivity study of safety interventions, not as a direct evaluation of physical adversarial patches as the title suggests.
major comments (3)
- [§III-B / Table VI] The central empirical claim rests on an unvalidated transfer assumption. The paper emulates adversarial patches by injecting fixed perception errors (10–38 m relative-distance errors and a 3% curvature deviation) taken from prior work [9], [10], but it does not demonstrate that these magnitudes, trigger conditions, and error shapes reproduce what an actual adversarial patch does to OpenPilot v0.9.7's DNN inside MetaDrive. Different model versions, camera parameters, or driving environments could produce different error profiles, so every prevention rate in Table VI, and hence Observation 3, may quantify a different phenomenon than 'adversarial patch attack.' I recommend either validating the mapping with at least one real-patch evaluation on this platform or reframing the claims as an evaluation of safety interventions under fault-injection-emulated perception errors, and adjusting the title and abstract accordingly.
- [§IV-E (Table VI, Table VII)] Each fault-injection configuration is repeated only 10 times, but results are presented as point percentages with no variance or confidence intervals. With 10 trials, a single accident shifts a prevention rate by 10 percentage points, which makes the main comparative claims (e.g., 40% driver braking vs. 100% AEB for relative-distance attacks, and the non-monotonic reaction-time results in Table VII) statistically fragile. Please report per-run outcomes, confidence intervals, or at least state the exact number of trials for every cell and discuss the resulting uncertainty when making comparative statements.
- [§IV-D / Algorithm 1] The ML baseline's behavior depends on the threshold τ and the bias parameter b0, but the paper never reports their values or the procedure used to set them. Without this information, the comparison in Table VI that supports Observation 6 is not reproducible and could be sensitive to hyperparameter choices. Please report the exact settings or provide a sensitivity analysis over τ and b0 to demonstrate that the comparison with AEB and driver intervention is fair and robust.
minor comments (6)
- [Title, Abstract, §III-B] The title and abstract repeatedly say 'adversarial patches,' but Section III-B states that the work 'directly emulates' patch effects by injecting attacks into DNN outputs; please use terminology that consistently distinguishes emulated perception errors from physically realized adversarial patches.
- [§IV / Table IV] The text says each configuration is repeated 10 times, yet Table IV reports benign-condition outcomes with denominators of 20 (e.g., '1/20', '10/20'); please clarify how many runs were performed for the no-attack baseline and whether the 360-simulation count refers only to fault-injection runs.
- [§V] The Threats to Validity section mentions simulation-only scope and driver-model simplification, but it does not list the fault-injection-to-patch mapping as a limitation; this is a significant validity threat and should be acknowledged explicitly.
- [Table VI] Table VI is dense and the header abbreviations ('Comp.', 'Indep.', and the multiple 'Trigger Rate' columns) are hard to parse; consider splitting the table into sub-tables by fault type or adding a legend that explains each row's intervention configuration.
- [§III-C, Eq. (4)] The speed-dependent TTC thresholds (3.8, 5.8, 9.8) are introduced without explaining their units or provenance beyond a citation to prior work; a brief sentence clarifying their basis would improve reproducibility.
- [§IV-E6] The claim that the ML model 'prevented nearly all A1 accidents caused by relative distance attacks' is supported by the table, but it would benefit from a per-scenario breakdown given the small number of trials and the wide spread in the other rows.
Circularity Check
No significant circularity; the paper's conclusions are empirical outcomes of a closed-loop simulation, with attack magnitudes, safety thresholds, and driver reaction times taken as external inputs rather than derived from the target results.
full rationale
The paper's derivation chain is empirical rather than definitional. Attack magnitudes are external inputs: Section III-B states the authors 'directly emulate the effect of the patches by injecting attacks into the DNN output and getting the range of attack values of mispredictions corresponding to adversarial patches from previous work [9], [10],' and Table III fixes relative-distance errors (10/15/38 m) and a 3% curvature deviation before any safety-intervention experiment is run. The AEBS behavior is defined by independent standards-style formulas (TTC = RD/RS; braking cascade thresholds t_pb1, t_pb2, t_fb), not by fitting Table VI. Driver reaction times (2.5 s nominal, 1.0-3.5 s sweep) come from external transportation guidelines and prior studies. The ML baseline is trained on fault-free OpenPilot data and then evaluated under injected faults; its 23.08%-40% prevention rates are measured outcomes, not fitted parameters. The central claims (e.g., independent-sensor AEB prevents up to 100% of relative-distance attacks, driver intervention prevents 40%-69.17%) are computed accident-prevention rates from simulation runs, and none of these target quantities appears as an input to the fault injection, AEBS, driver, or ML models. One cited source for attack magnitudes, [9], shares authors with this paper, but it is prior empirical work on attack ranges rather than an unverified theorem, and the current paper's conclusions do not reduce to that citation by construction. The reviewer's concern that injected magnitudes may not faithfully represent physical adversarial patches is a threat-to-validity issue about the mapping between simulation and reality, not a circularity in the derivation chain. Accordingly, no circular step is present.
Assumptions & free parameters
free parameters (6)
- Grid of relative-distance fault injection magnitudes =
10 m, 15 m, 38 m for RD bins below 80 m, 25 m, and 20 m
- Curvature fault injection magnitude =
3% deviation in desired curvature
- Driver reaction time =
2.5 s default, varied 1.0-3.5 s
- AEBS braking TTC coefficients =
t_pb1 = V/3.8, t_pb2 = V/5.8, t_fb = V/9.8
- AEBS driver deceleration a_driver =
not specified
- ML baseline activation threshold tau and bias b0 =
not specified
assumptions (5)
- domain assumption Fault injection from [9,10] is a faithful substitute for physical adversarial patches
- domain assumption OpenPilot v0.9.7 in MetaDrive 0.4.2.3 captures real vehicle control behavior
- domain assumption The rule-based driver reaction simulator approximates human emergency responses
- domain assumption The AEBS model per UN R152 and prior work is representative of production AEB
- domain assumption MetaDrive physics on a dry highway map supports the hazard and accident definitions
Cite this review
Pith. "Pith review of Safety Interventions against Adversarial Patches in an Open-Source Driver Assistance System." pith.science (2026). https://pith.science/paper/HEVVT6BX
@misc{pith2026250418990,
author = {Pith},
title = {Pith review of: Safety Interventions against Adversarial Patches in an Open-Source Driver Assistance System},
year = {2026},
howpublished = {\url{https://pith.science/paper/HEVVT6BX}},
note = {Machine review of arXiv:2504.18990}
}
read the original abstract
Drivers are becoming increasingly reliant on advanced driver assistance systems (ADAS) as autonomous driving technology becomes more popular and developed with advanced safety features to enhance road safety. However, the increasing complexity of the ADAS makes autonomous vehicles (AVs) more exposed to attacks and accidental faults. In this paper, we evaluate the resilience of a widely used ADAS against safety-critical attacks that target perception inputs. Various safety mechanisms are simulated to assess their impact on mitigating attacks and enhancing ADAS resilience. Experimental results highlight the importance of timely intervention by human drivers and automated safety mechanisms in preventing accidents in both driving and lateral directions and the need to resolve conflicts among safety interventions to enhance system resilience and reliability.
Figures
Reference graph
Works this paper leans on
-
[9]
Runtime Stealthy Perception Attacks against DNN- Based Adaptive Cruise Control Systems,
X. Zhou, A. Chen, M. Kouzel, H. Ren, M. McCarty, C. Nita-Rotaru, and H. Alemzadeh, “Runtime Stealthy Perception Attacks against DNN- Based Adaptive Cruise Control Systems,” inACM Asia Conference on Computer and Communications Security (ASIA CCS), 2025
work page 2025
-
[10]
T. Sato, J. Shen, N. Wang, Y . Jia, X. Lin, and Q. A. Chen, “Dirty Road Can Attack: Security of Deep Learning Based Automated Lane Centering under{Physical-World}Attack,” in30th USENIX Security Symposium (USENIX Security 21), 2021, pp. 3309–3326
work page 2021
-
[1]
SAE Levels of Driving Automation™ Refined for Clarity and Interna- tional Audience,
“SAE Levels of Driving Automation™ Refined for Clarity and Interna- tional Audience,” https://www.sae.org/blog/sae-j3016-update, 2021
work page 2021
-
[2]
“ADAS Market Report 2030.” [Online]. Avail- able: https://www.marketsandmarkets.com/Market-Reports/driver- assistance-systems-market-1201.html
-
[3]
Global Advanced Driver Assistance Systems (ADAS) Market Size and Forecast
“Global Advanced Driver Assistance Systems (ADAS) Market Size and Forecast.” [Online]. Available: https://www.verifiedmarketresearch.com/product/global-advanced- driver-assistance-systems-adas-market-size-and-forecast/
-
[4]
The 23 Most Dangerous Cars on the Road
“The 23 Most Dangerous Cars on the Road.” [Online]. Available: https://www.iseecars.com/most-dangerous-cars-study
-
[5]
U.S. Department of Transportation National Highway Traffic Safety Administration, “Summary Report: Standing General Order on Crash Reporting for Level 2 Advanced Driver Assistance Systems,” Tech. Rep., 2022. [Online]. Available: https://www.nhtsa.gov/sites/nhtsa.gov/ files/2022-06/ADAS-L2-SGO-Report-June-2022.pdf
work page 2022
-
[6]
ML-Based Fault Injection for Autonomous Vehicles: A Case for Bayesian Fault Injection,
S. Jha, S. Banerjee, T. Tsai, S. K. Hari, M. B. Sullivan, Z. T. Kalbar- czyk, S. W. Keckler, and R. K. Iyer, “ML-Based Fault Injection for Autonomous Vehicles: A Case for Bayesian Fault Injection,” in2019 49th annual IEEE/IFIP international conference on dependable systems and networks (DSN). IEEE, 2019, pp. 112–124
work page 2019
Show all 68 references
-
[7]
ML-Driven Malware that Targets A V Safety,
S. Jha, S. Cui, S. Banerjee, J. Cyriac, T. Tsai, Z. Kalbarczyk, and R. K. Iyer, “ML-Driven Malware that Targets A V Safety,” in2020 50th Annual IEEE/IFIP International Conference on Dependable Systems and Networks (DSN). IEEE, 2020, pp. 113–124
2020
-
[8]
Robustness testing of data and knowledge driven anomaly detection in cyber-physical systems,
X. Zhou, M. Kouzel, and H. Alemzadeh, “Robustness testing of data and knowledge driven anomaly detection in cyber-physical systems,” in 2022 52nd Annual IEEE/IFIP International Conference on Dependable Systems and Networks Workshops (DSN-W). IEEE, 2022, pp. 44–51
2022
-
[11]
Tesla Autopilot,
“Tesla Autopilot,” https://www.tesla.com/autopilot
-
[12]
Subaru EyeSight,
“Subaru EyeSight,” https://www.subaru.com/eyesight.html
-
[13]
Fooling Detection Alone is not Enough: First Adversarial Attack against Multiple Object Tracking,
Y . Jia, Y . Lu, J. Shen, Q. A. Chen, Z. Zhong, and T. Wei, “Fooling Detection Alone is not Enough: First Adversarial Attack against Multiple Object Tracking,”arXiv:1905.11026, 2019
1905 arXiv
-
[14]
Robust Physical-World Attacks on Deep Learning Visual Classification,
K. Eykholt, I. Evtimov, E. Fernandes, B. Li, A. Rahmati, C. Xiao, A. Prakash, T. Kohno, and D. Song, “Robust Physical-World Attacks on Deep Learning Visual Classification,” inProceedings of the IEEE conference on computer vision and pattern recognition, 2018, pp. 1625– 1634
2018
-
[15]
Experimental Security Research of Tesla Autopilot,
Tencent, “Experimental Security Research of Tesla Autopilot,”Tencent Keen Security Lab, 2019
2019
-
[16]
Adversarial Camera Stickers: A Phys- ical Camera-Based Attack on Deep Learning Systems,
J. Li, F. Schmidt, and Z. Kolter, “Adversarial Camera Stickers: A Phys- ical Camera-Based Attack on Deep Learning Systems,” inInternational Conference on Machine Learning, 2019, pp. 3896–3904
2019
-
[17]
WIP: Towards the Practicality of the Adversarial Attack on Object Tracking in Autonomous Driving,
C. Ma, N. Wang, Q. A. Chen, and C. Shen, “WIP: Towards the Practicality of the Adversarial Attack on Object Tracking in Autonomous Driving,” inInaugural International Symposium on Vehicle Security & Privacy, 2023
2023
-
[18]
Sequential Attacks on Kalman Filter-Based forward Collision Warning Systems,
Y . Ma, J. A. Sharp, R. Wang, E. Fernandes, and X. Zhu, “Sequential Attacks on Kalman Filter-Based forward Collision Warning Systems,” in Proceedings of the AAAI Conference on Artificial Intelligence, vol. 35, no. 10, 2021, pp. 8865–8873
2021
-
[19]
Software-Based Realtime Recovery from Sensor Attacks on Robotic Vehicles,
H. Choi, S. Kate, Y . Aafer, X. Zhang, and D. Xu, “Software-Based Realtime Recovery from Sensor Attacks on Robotic Vehicles,” in 23rd International Symposium on Research in Attacks, Intrusions and Defenses (RAID), 2020, pp. 349–364
2020
-
[20]
PID- Piper: Recovering Robotic Vehicles from Physical Attacks,
P. Dash, G. Li, Z. Chen, M. Karimibiuki, and K. Pattabiraman, “PID- Piper: Recovering Robotic Vehicles from Physical Attacks,” in2021 51st Annual IEEE/IFIP International Conference on Dependable Systems and Networks (DSN). IEEE, 2021, pp. 26–38
2021
-
[21]
Specguard: Specification Aware Recovery for Robotic Autonomous Vehicles from Physical Attacks,
P. Dash, E. Chan, and K. Pattabiraman, “Specguard: Specification Aware Recovery for Robotic Autonomous Vehicles from Physical Attacks,” in Proceedings of the 2024 on ACM SIGSAC Conference on Computer and Communications Security, 2024, pp. 1849–1863
2024
-
[22]
OpenPilot
Comma.ai, “OpenPilot.” [Online]. Available: https://github.com/ commaai/openpilot
-
[23]
Supported Cars by OpenPilot,
“Supported Cars by OpenPilot,” https://github.com/commaai/openpilot/ blob/master/docs/CARS.md
-
[24]
MetaDrive: Composing Diverse Driving Scenarios for Generalizable Reinforcement Learning,
Q. Li, Z. Peng, Z. Xue, Q. Zhang, and B. Zhou, “MetaDrive: Composing Diverse Driving Scenarios for Generalizable Reinforcement Learning,” arXiv preprint arXiv:2109.12674, 2021
2021 arXiv
-
[25]
CARLA: An Open Urban Driving Simulator,
A. Dosovitskiy, G. Ros, F. Codevilla, A. Lopez, and V . Koltun, “CARLA: An Open Urban Driving Simulator,” inProceedings of the 1st Annual Conference on Robot Learning, 2017, pp. 1–16
2017
-
[26]
Dynamic Adver- sarial Patch for Evading Object Detection Models,
S. Hoory, T. Shapira, A. Shabtai, and Y . Elovici, “Dynamic Adver- sarial Patch for Evading Object Detection Models,”arXiv preprint arXiv:2010.13070, 2020
2010 arXiv
-
[27]
Dynamic Adversarial Attacks on Autonomous Driving Systems,
A. Chahe, C. Wang, A. Jeyapratap, K. Xu, and L. Zhou, “Dynamic Adversarial Attacks on Autonomous Driving Systems,”arXiv preprint arXiv:2312.06701, 2023
2023 arXiv
-
[28]
That Person Moves Like a Car: Misclassification Attack Detection for Autonomous Systems Using Spatiotemporal Consistency,
Y . Man, R. Muller, M. Li, Z. B. Celik, and R. Gerdes, “That Person Moves Like a Car: Misclassification Attack Detection for Autonomous Systems Using Spatiotemporal Consistency,” in32nd USENIX Security Symposium (USENIX Security 23), 2023, pp. 6929–6946
2023
-
[29]
A First Physical-World Trajectory Prediction Attack via LiDAR-Induced Deceptions in Autonomous Driving,
Y . Lou, Y . Zhu, Q. Song, R. Tan, C. Qiao, W.-B. Lee, and J. Wang, “A First Physical-World Trajectory Prediction Attack via LiDAR-Induced Deceptions in Autonomous Driving,”arXiv preprint arXiv:2406.11707, 2024
2024 arXiv
-
[30]
Adversarial Attacks on Adaptive Cruise Control Systems,
Y . Guo, T. Sato, Y . Cao, Q. A. Chen, and Y . Cheng, “Adversarial Attacks on Adaptive Cruise Control Systems,” inProceedings of Cyber-Physical Systems and IoT Week 2023, 2023, pp. 49–54
2023
-
[31]
Implementation of Autonomous Emergency Braking (AEB), the Next Step in Euro NCAP’S Safety Assessment,
R. Schram, A. Williams, and M. van Ratingen, “Implementation of Autonomous Emergency Braking (AEB), the Next Step in Euro NCAP’S Safety Assessment,”ESV , Seoul, 2013
2013
-
[32]
66–89, 2020
“UN Regulation No 152 – Uniform Provisions Concerning the Ap- proval of Motor Vehicles with Regard to the Advanced Emergency Braking System (AEBS) for M1 and N1 Vehicles [2020/1597],” http: //data.europa.eu/eli/reg/2020/1597/oj, pp. 66–89, 2020
2020
-
[33]
GRV A-12-50r1e.pdf,
“GRV A-12-50r1e.pdf,” https://unece.org/sites/default/files/2022-01/ GRV A-12-50r1e.pdf
2022
-
[34]
Autonomous Vehicle with Emergency Braking Algorithm Based on Multi-Sensor Fusion and Super Twisting Speed Controller,
T. Alsuwian, R. B. Saeed, and A. A. Amin, “Autonomous Vehicle with Emergency Braking Algorithm Based on Multi-Sensor Fusion and Super Twisting Speed Controller,”Applied Sciences, vol. 12, no. 17, p. 8458, Aug. 2022
2022
-
[35]
Strategic Safety-Critical Attacks against an Advanced Driver Assistance System,
X. Zhou, A. Schmedding, H. Ren, L. Yang, P. Schowitz, E. Smirni, and H. Alemzadeh, “Strategic Safety-Critical Attacks against an Advanced Driver Assistance System,” in2022 52nd Annual IEEE/IFIP Interna- tional Conference on Dependable Systems and Networks (DSN). IEEE, 2022, pp. 79–87
2022
-
[36]
Available: https://github.com/commaai/ panda
Comma.ai, “Panda.” [Online]. Available: https://github.com/commaai/ panda
-
[37]
OpenPilot - Safety Architecture,
“OpenPilot - Safety Architecture,” 2018. [Online]. Available: https://blog.comma.ai/how-to-write-a-car-port-for-openpilot/ #background--safety-architecture [38]Intelligent transport systems – Full speed range adaptive cruise con- trol (FSRA) systems – Performance requirements ...
2018
-
[39]
Safe Driving,
Virginia DMV, “Safe Driving,” https://www.dmv.virginia.gov/webdoc/ pdf/dmv39d.pdf
-
[40]
Driver Brake Response to Sudden Unintended Acceleration while Parking,
J. G. Gaspar and D. V . McGehee, “Driver Brake Response to Sudden Unintended Acceleration while Parking,”Transportation research inter- disciplinary pertives, vol. 2, p. 100039, 2019
2019
-
[41]
California Commercial Driver Handbook,
“California Commercial Driver Handbook,” https://www.dmv.ca.gov/ portal/uploads/2020/06/comlhdbk.pdf, 2019
2020
-
[42]
Reference Guide for NSC DDC Instructor-led Training,
N. S. Council, “Reference Guide for NSC DDC Instructor-led Training,” https://www.nsc.org/getmedia/ a46d07cb-faf1-4572-8317-661e7f77ef7a/instructor-admin- reference-guide.pdf?srsltid=AfmBOop5BGVGMZl63t_31waS- 4mgVvsUl4of_64EOIWQELG30mgonCkW, 2014
2014
-
[43]
Automotive Technology: What to Know About Automatic Emergency Braking,
M. International, “Automotive Technology: What to Know About Automatic Emergency Braking,” April 2024, [Online; accessed 5-December-2024]. [Online]. Avail- able: https://maycointernational.com/blog/automotive-technology-what- to-know-about-automatic-emergency-braking/
2024
-
[44]
New Automatic Emergency Braking Safety Standard will Save Lives, Expert Explains,
V . T. News, “New Automatic Emergency Braking Safety Standard will Save Lives, Expert Explains,” April 2024, [Online; accessed 5- December-2024]. [Online]. Available: https://news.vt.edu/articles/2024/ 04/Automatic-emergency-braking-safety-expert.html
2024
-
[45]
Pre-Crash Scenario Typology for Crash Avoidance Research,
W. G. Najm, J. D. Smith, M. Yanagisawa, and John A. V olpe National Transportation Systems Center (U.S.), “Pre-Crash Scenario Typology for Crash Avoidance Research,” Tech. Rep. DOT-VNTSC-NHTSA-06- 02, Apr. 2007
2007
-
[46]
Use of Risk-Adjusted CUSUM and RSPRT Charts for Monitoring in Medical Contexts,
O. A. Grigg, V . Farewell, and D. Spiegelhalter, “Use of Risk-Adjusted CUSUM and RSPRT Charts for Monitoring in Medical Contexts,” Statistical methods in medical research, vol. 12, no. 2, pp. 147–170, 2003
2003
-
[47]
Brake reaction time,
University of Idaho, “Brake reaction time,” https:// www.webpages.uidaho.edu/niatt_labmanual/chapters/geometricdesign/ theoryandconcepts/BrakeReactionTime.htm, n.d., [Online; accessed 27-February-2025]
2025
-
[48]
Differences of Drivers’ Reaction Times According to Age and Mental Workload,
H. Makishita and K. Matsunaga, “Differences of Drivers’ Reaction Times According to Age and Mental Workload,”Accident Analysis & Prevention, vol. 40, no. 2, pp. 567–575, 2008. [Online]. Available: https://www.sciencedirect.com/science/article/pii/S0001457507001418
2008
-
[49]
How Much Does Rain Reduce Your Traction?
Supercars.net, “How Much Does Rain Reduce Your Traction?” https: //www.supercars.net/blog/how-much-does-rain-reduce-your-traction/, n.d., [Online; accessed 27-February-2025]
2025
-
[50]
Weather condition effect on the road surface friction: A Preliminary assessment based on sensor data,
M. Rasol, F. Schmidt, and S. Ientile, “Weather condition effect on the road surface friction: A Preliminary assessment based on sensor data,” inLife-Cycle of Structures and Infrastructure Systems. CRC Press, 2023, pp. 2187–2194
2023
-
[51]
Phantom of the ADAS: Securing Advanced Driver-Assistance Systems from Split-Second Phantom Attacks,
B. Nassi, Y . Mirsky, D. Nassi, R. Ben-Netanel, O. Drokin, and Y . Elovici, “Phantom of the ADAS: Securing Advanced Driver-Assistance Systems from Split-Second Phantom Attacks,” in Proceedings of the 2020 ACM SIGSAC Conference on Computer and Communications Security, ser. CCS ...
2020
-
[52]
WIP: Practical Removal Attacks on LiDAR-Based Object De- tection in Autonomous Driving,
T. Sato, Y . Hayakawa, R. Suzuki, Y . Shiiki, K. Yoshioka, and Q. A. Chen, “WIP: Practical Removal Attacks on LiDAR-Based Object De- tection in Autonomous Driving,” inInaugural International Symposium on Vehicle Security & Privacy, 2023
2023
-
[53]
Drift with Devil: Security of Multi-Sensor Fusion Based Localization in High-Level Autonomous Driving under GPS Spoofing,
J. Shen, J. Y . Won, Z. Chen, and Q. A. Chen, “Drift with Devil: Security of Multi-Sensor Fusion Based Localization in High-Level Autonomous Driving under GPS Spoofing,” inProceedings of the 29th USENIX Conference on Security Symposium, 2020, pp. 931–948
2020
-
[54]
Spoofing Attacks against Vehicular FMCW Radar,
R. Komissarov and A. Wool, “Spoofing Attacks against Vehicular FMCW Radar,” inProceedings of the 5th Workshop on Attacks and Solutions in Hardware Security, 2021, pp. 91–97
2021
-
[55]
MobilBye: Attacking ADAS with Camera Spoofing,
D. Nassi, R. Ben-Netanel, Y . Elovici, and B. Nassi, “MobilBye: Attacking ADAS with Camera Spoofing,” 2019. [Online]. Available: https://arxiv.org/abs/1906.09765
2019 arXiv
-
[56]
Strategic resilience evaluation of neural networks within autonomous vehicle software,
A. Schmedding, P. Schowitz, X. Zhou, Y . Lu, L. Yang, H. Alemzadeh, and E. Smirni, “Strategic resilience evaluation of neural networks within autonomous vehicle software,” inInternational Conference on Computer Safety, Reliability, and Security. Springer, 2024, pp. 33–48
2024
-
[57]
Aspis: Lightweight neural network protection against soft errors,
A. Schmedding, L. Yang, A. Jog, and E. Smirni, “Aspis: Lightweight neural network protection against soft errors,” in35th IEEE International Symposium on Software Reliability Engineering, ISSRE 2024, Tsukuba, Japan, October 28-31, 2024. IEEE, 2024, pp. 248–259
2024
-
[58]
Practical resilience analysis of GPGPU applications in the presence of single- and multi-bit faults,
L. Yang, B. Nie, A. Jog, and E. Smirni, “Practical resilience analysis of GPGPU applications in the presence of single- and multi-bit faults,” IEEE Trans. Computers, vol. 70, no. 1, pp. 30–44, 2021
2021
-
[59]
Malicious Attacks against Multi-Sensor Fusion in Autonomous Driving,
Y . Zhu, C. Miao, H. Xue, Y . Yu, L. Su, and C. Qiao, “Malicious Attacks against Multi-Sensor Fusion in Autonomous Driving,” in Proceedings of the 30th Annual International Conference on Mobile Computing and Networking, ser. ACM MobiCom ’24. New York, NY , USA: Association for...
2024
-
[60]
Hybrid knowledge and data driven synthesis of runtime monitors for cyber- physical systems,
X. Zhou, B. Ahmed, J. H. Aylor, P. Asare, and H. Alemzadeh, “Hybrid knowledge and data driven synthesis of runtime monitors for cyber- physical systems,”IEEE Transactions on Dependable and Secure Com- puting, vol. 21, no. 1, pp. 12–30, 2023
2023
-
[61]
Simulation-Based Adversarial Test Generation for Autonomous Vehicles with Machine Learning Components,
C. E. Tuncali, G. Fainekos, H. Ito, and J. Kapinski, “Simulation-Based Adversarial Test Generation for Autonomous Vehicles with Machine Learning Components,” in2018 IEEE Intelligent Vehicles Symposium (IV). IEEE, 2018, pp. 1555–1562
2018
-
[62]
Deeptest: Automated Testing of Deep-Neural-Network-Driven Autonomous Cars,
Y . Tian, K. Pei, S. Jana, and B. Ray, “Deeptest: Automated Testing of Deep-Neural-Network-Driven Autonomous Cars,” inProceedings of the 40th international conference on software engineering, 2018, pp. 303–314
2018
-
[63]
Testing Advanced Driver Assistance Systems using Multi-Objective Search and Neural Networks,
R. Ben Abdessalem, S. Nejati, L. C. Briand, and T. Stifter, “Testing Advanced Driver Assistance Systems using Multi-Objective Search and Neural Networks,” inProceedings of the 31st IEEE/ACM International Conference on Automated Software Engineering, 2016, pp. 63–74
2016
-
[64]
Testing Vision-Based Control Systems using Learnable Evolutionary Algo- rithms,
R. B. Abdessalem, S. Nejati, L. C. Briand, and T. Stifter, “Testing Vision-Based Control Systems using Learnable Evolutionary Algo- rithms,” in2018 IEEE/ACM 40th International Conference on Software Engineering (ICSE). IEEE, 2018, pp. 1016–1026
2018
-
[65]
Automatically Testing Self- Driving Cars with Search-Based Procedural Content Generation,
A. Gambi, M. Mueller, and G. Fraser, “Automatically Testing Self- Driving Cars with Search-Based Procedural Content Generation,” in Proceedings of the 28th ACM SIGSOFT International Symposium on Software Testing and Analysis, 2019, pp. 318–328
2019
-
[66]
ADAS Reliability against Weather Conditions: Quantification of Performance Robustness
T. Rahman, A. Liu, D. S. Cheema, V . Chirila, D. C. Transport, and C. Canada, “ADAS Reliability against Weather Conditions: Quantification of Performance Robustness.” [Online]. Available: https://api.semanticscholar.org/CorpusID:268237053
-
[67]
Analyzing and Improving Resilience and Robustness of Autonomous Systems,
Z. Wan, K. Swaminathan, P.-Y . Chen, N. Chandramoorthy, and A. Raychowdhury, “Analyzing and Improving Resilience and Robustness of Autonomous Systems,” inProceedings of the 41st IEEE/ACM International Conference on Computer-Aided Design, ser. ICCAD ’22. New York, NY , USA: Ass...
2022
-
[68]
Automated Vehicle Lane Centering System Requirements Informed by Resilience Engineering and a Solution Using Infrastructure- Based Sensors,
J. F. Rojas, P. Patil, A. M. Masterson, T. H. Bradley, A. R. Ekti, and Z. D. Asher, “Automated Vehicle Lane Centering System Requirements Informed by Resilience Engineering and a Solution Using Infrastructure- Based Sensors,”IEEE Access, vol. 12, pp. 97 605–97 620, 2024
2024
-
[69]
Cyberattacks on Adaptive Cruise Controls and Emergency Braking Systems: Adversary Models, Impact Assess- ment, and Countermeasures,
A. Berdich and B. Groza, “Cyberattacks on Adaptive Cruise Controls and Emergency Braking Systems: Adversary Models, Impact Assess- ment, and Countermeasures,”IEEE Transactions on Reliability, vol. 73, no. 2, pp. 1216–1230, 2024
2024
Reviewed August 16, 2026 · model on record in the stance chip above.
Discussion (0). Continue with ORCID to comment.