Running Head: CYBER RISKS IN ADVERSARIAL AI ATTACKS ON AUTONOMOUS VEHICLES
1
Cyber Risks in Adversarial AI Attacks on Autonomous Vehicles
Student Name
Institution
Course
Professor
Date
CYBER RISKS IN ADVERSARIAL AI ATTACKS ON AUTONOMOUS VEHICLES 2
Cyber Risks in Adversarial AI Attacks on Autonomous Vehicles
Self-driving cars are a combination of software, hardware, and connectivity; therefore,
they are vulnerable to several cyber threats. As noted by Giannaros et al. (2023), AVs comprise a
network of systems that control essential functionalities, and therefore, they have many possible
weak links. These weaknesses include weaknesses in software and hardware and other
weaknesses in interfaces. For example, Limbasiya et al. (2022) showed the potential of how
attackers can control the AVs, including the brakes and steering wheel, either physically or via
commands on a network without physical access. This capability is highly risky; the car might
crash, or someone not authorized might be in control of the car's movements.
Moreover, Wang et al. (2022) explain the outcomes that may occur if an attacker gains
access to an AV's internal network. It can create an opportunity for the attackers to jam/interfere
with the vehicle's operational functions in totality. In the experiments carried out by Giannaros
and colleagues (2023), the authors showed that once the attacker is in the network, they can
easily change the architecture of the software of the AV and gain control, thus bypassing the
security measures that have been put in place to prevent such an attack. Thus, such studies
highlight the need for high levels of cybersecurity to counterbalance various external threats and
risks to AVs, their passengers, and pedestrians.
Furthermore, applying multiple technologies in AVs introduces other problems that
enlarge the AV surface of attack. Sheik et al. (2023) have indicated that the components in an AV
are integrated, and a weakness in one of the components can compromise the whole car. This
connectivity is not only for the vehicle but also for the external network for V2V and V2I for
connected cars, which are mandatory for properly working connected cars. Hence, these
CYBER RISKS IN ADVERSARIAL AI ATTACKS ON AUTONOMOUS VEHICLES 3
networks should be safeguarded from cyber threats that may target the weaknesses in AVs'
working structures, as Seetharaman et al. (2021) discussed.
Other perception systems required in AVs are LiDAR, radar, and cameras to ensure that
the vehicles have accurate information about the environment around them. These sensors assist
the AVs in making decisions because they provide information on the environment in which the
sensors are located, as explained by Girdhar et al. (2023). However, these sensors are easily
vulnerable to adversarial attacks that can cause a lot of harm to the safety and efficiency of the
vehicle. According to Giannaros et al. (2023), the authors described that LiDAR sensors are
vulnerable to spoofing attacks in which the attacker transmits signals that look like the actual
object or change the distance. Such attacks are effective because they can deceive AVs into
giving wrong directions that are fatal to passengers and pedestrians.
Moreover, radar sensors, which AVs use to identify objects and obstacles near a vehicle,
can also be susceptible to adversarial attacks. In their study, Li et al. (2024) agreed that radar
signals can interfere; therefore, they do not detect objects or measure the wrong distance and
velocity. This weakness can be a danger of some types of accidents if AVs use radar data for non-
collisions and traffic conditions. The fact that the radar signals can be jammed demonstrates the
main weakness through which the adversaries can endanger the safety and dependability of the
AVs on the roads.
Moreover, the other sensors in AVs, such as cameras, including image recognition and
traffic sign detection, can also be attacked by adversarial attacks. Girdhar et al. (2023)
established in their study that manipulation of the slight change in the camera feeds or changing
pixel values or patterns misleads the image understanding of AVs. This could result in a wrong
CYBER RISKS IN ADVERSARIAL AI ATTACKS ON AUTONOMOUS VEHICLES 4
identification of traffic signals, pedestrians, or other vehicles; hence, dangerous decisions could
be made on the road. Zhang et al. (2023) postulated that there is a need to improve the robustness
of camera-based sensor systems to avoid compromising the perception systems of AV systems in
various environments.
The connections created by the AVs and those within the AVs and between them and the
environment are important for their correct operation. These networks have been found by Zheng
et al. (2022) to be central but, at the same time, very vulnerable to a host of cyber threats. Some
threats are real, like the man-in-the-middle attacks through which the attacker can alter
information shared between AVs or other systems. It can distort the reliability and privacy of the
information that is being transmitted and hence cause unauthorized control or manipulation of
AV operations.
In addition to interception threats, another threat posed in vehicular communication
networks is eavesdropping, as Lu et al. (2021) pointed out. Overt interception of such
information over these networks can endanger adversaries with information on the movements of
AVs, operational patterns, or even passengers' identities; therefore, privacy and security threats
are inevitable. Also, Han et al. (2024) noted that susceptibility to data injection attacks calls for
cybersecurity improvement. It could misinform the AVs with wrong data, thus causing them to
make wrong decisions concerning the occupants and other users of the roads.
Sheik et al. (2023) observe that it is necessary to practice sufficient precautions within the
communication process to eliminate such risks. Encryption ensures messages passed between
AVs and structures are originals and have not been interfered with. Encrypted means of passing
information safeguard data by putting it in a form that can only be deciphered by the target,
CYBER RISKS IN ADVERSARIAL AI ATTACKS ON AUTONOMOUS VEHICLES 5
which excludes other people from overhearing. Shafik et al. (2023) point out that through
authentication processes, the identity of the communicating parties is ensured, and thus, spoofing
cannot occur, making vehicular communication networks reliable.
Furthermore, there is a need to ensure that encryption and authentication methods are
carried out to the highest level in terms of the reliability of AV communications. Ying et al.
(2024) also pointed out in the same work that integrating cryptographic solutions such as public-
key infrastructure (PKI) would improve the security of vehicular networks since it provides a
secure means of creating communication and authentication channels. Furthermore, according to
the study by Khan et al. (2020), it is crucial to periodically update the security measures as
threats to AV networks occur occasionally.
Among the risks that are associated with the ML models that are used in AVs include
adversarial examples. Adversarial examples are defined as inputs deliberately crafted to deceive
the AI algorithms, leading to the wrong decisions by the AVs, as stated by Kloukiniotis et al.
(2022). The research conducted by Zhang (2024) clearly illustrated that even slight variations in
input data that are almost invisible to human perception can cause significant misclassifications
in AVs' decision matrices. These are do-or-die risks because they can lead to an accident or a
failure of the autonomous driving scenario.
Moreover, Ingle & Pawale (2024) noted that adversarial attacks are simple to execute;
these manipulations can be done with low capital intensity and expertise. This enhances the risk
of adversarial examples because the attack can be conducted by anyone with basic knowledge of
the ML algorithms to jeopardize AV operations. Addressing these threats requires enhancing the
model's immune system and the model's resistance to adversarial alterations. In the study by
CYBER RISKS IN ADVERSARIAL AI ATTACKS ON AUTONOMOUS VEHICLES 6
Qayyum et al. (2024), the authors recommend that more studies be conducted to establish ways
to develop improved AI to detect adversarial attacks in real-time to enhance self-driving car
systems.
Again, protecting AVs from cyber threats and adversarial attacks can only be done by
applying defensive measures. Giannaros et al. (2023) call for preventive interventions to enhance
the security of AVs. Serban et al. (2020) describe one of the most valuable strategies: the
adversarial training of AI models in which adversarial examples are included in the training
process. This procedure helps the models adapt to recognizing manipulations and performing the
right actions as a result of manipulations, which overall improves the models' ability to defend
against adversarial attacks in real-life scenarios. Therefore, one of the basic approaches is
adversarial training, which is used to increase the stability of AI systems in AVs and should work
correctly even in the case of an attack.
Another defense measure Aldahdooh et al. (2022) identified is the use of secondary
networks designed to detect adversarial inputs. These networks act as the additional layers of
defense where the incoming data flows are checked for deviations or shifts that might signal the
adversary's attempts to tamper with the AV decision processes. Miller et al. (2020) recommend
gradient masking techniques since they obscure gradients that the adversaries employ to
formulate the adversarial noise. Since these gradients are rather harmful to the AV systems,
access to them can be limited to reduce the possibility of the adversaries' exploitation, thus
enhancing the security and reliability of the systems.
The application of self-driving cars is one of the most controversial problems that should
be solved with the proper consideration of ethical and legal aspects to guarantee the safety and
CYBER RISKS IN ADVERSARIAL AI ATTACKS ON AUTONOMOUS VEHICLES 7
trust of the population. Martinho et al. (2021) note that ethical discourses regarding AV systems
are not static. These include legal liability for AV crashes, ethical concerns about AVs, and
privacy, all of which need to be established as policies for the development and deployment of
AVs. Khan (2024) has noted that there is a requirement to have clear and sufficient rules that
could assist in responding to the issues associated with cyber threats of AVs. Sound regulation is
needed to ensure that the AV technologies perform as required and are safe to use on public roads
and to sustain the public's trust in the technologies.
In addition, there are ethical concerns that define the development of AV technologies in
the future. In their work, Liu et al. (2024) highlight that there is a need for organizations to be
more open as well as be held accountable for their actions in terms of handling cyber threats and
risks related to AV operations. Ethical standards are essential to help design and deploy AV
systems in a manner that respects human life and the common good. Tange et al. (2020) have
called on the AV industry to develop standards and guidelines for a secure and robust ecosystem.
This reduces cybersecurity threats because standardization establishes guidelines for
manufacturing companies and operators and makes the various AV systems compatible with each
other despite coming from different manufacturers.
CYBER RISKS IN ADVERSARIAL AI ATTACKS ON AUTONOMOUS VEHICLES 8
References
Aldahdooh, A., Hamidouche, W., Fezza, S. A., & Déforges, O. (2022). Adversarial example
detection for DNN models: A review and experimental comparison.DArtificial Intelligence
Review,D55(6), 4403-4462.
Girdhar, M., Hong, J., & Moore, J. (2023). Cybersecurity of autonomous vehicles: A systematic
literature review of adversarial attacks and defense models.DIEEE Open Journal of
Vehicular Technology,D4, 417-437.
Giannaros, A., Karras, A., Theodorakopoulos, L., Karras, C., Kranias, P., Schizas, N., ... & Tsolis,
D. (2023). Autonomous vehicles: Sophisticated attacks, safety issues, challenges, open
topics, blockchain, and future directions.DJournal of Cybersecurity and Privacy,D3(3),
493-543.
Ingle, G., & Pawale, S. (2024). Enhancing Model Robustness and Accuracy Against Adversarial
Attacks via Adversarial Input Training.DInternational Journal of Advanced Computer
Science & Applications,D15(3).
Han, D., Babaei, R., Zhao, S., & Cheng, S. (2024). Exploring the Efficacy of Learning
Techniques in Model Extraction Attacks on Image Classifiers: A Comparative
Study.DApplied Sciences,D14(9), 3785.
Khan, S. K., Shiwakoti, N., Stasinopoulos, P., & Chen, Y. (2020). Cyber-attacks in the next-
generation cars, mitigation techniques, anticipated readiness, and future
directions.DAccident Analysis & Prevention,D148, 105837.
CYBER RISKS IN ADVERSARIAL AI ATTACKS ON AUTONOMOUS VEHICLES 9
Khan, S. K., Shiwakoti, N., Stasinopoulos, P., Chen, Y., & Warren, M. (2024). The impact of
perceived cyber-risks on automated vehicle acceptance: insights from a survey of
participants from the United States, the United Kingdom, New Zealand, and
Australia.DTransport policy,D152, 87-101.
Kloukiniotis, A., Papandreou, A., Lalos, A., Kapsalas, P., Nguyen, D. V., & Moustakas, K.
(2022). Countering adversarial attacks on autonomous vehicles using denoising
techniques: A review.DIEEE Open Journal of Intelligent Transportation Systems,D3, 61-80.
Liu, N., Nikitas, A., & Parkinson, S. (2020). Exploring expert perceptions about Connected and
Autonomous Vehicles' cyber security and privacy: A thematic analysis approach.
Transportation research part F: traffic psychology and behavior,D75, 66-86.
Lu, X., Luong, N. C., Hoang, D. T., Niyato, D., Xiao, Y., & Wang, P. (2021). Secure wirelessly
powered networks at the physical layer: Challenges, countermeasures, and the road
ahead.DProceedings of the IEEE,D110(1), 193-209.
Li, Z., Li, S., Zhang, H., Zhou, Y., Xie, S., & Zhang, Y. (2024). Overview of Sensing Attacks on
Autonomous Vehicle Technologies and Impact on Traffic Flow.DarXiv preprint
arXiv:2401.15193.
Limbasiya, T., Teng, K. Z., Chattopadhyay, S., & Zhou, J. (2022). A systematic survey of attack
detection and prevention in connected and autonomous vehicles.DVehicular
Communications,D37, 100515.
Martinho, A., Herber, N., Kroesen, M., & Chorus, C. (2021). The autonomous vehicles industry
focuses on ethical issues. Transport Reviews,D41(5), 556-577.
CYBER RISKS IN ADVERSARIAL AI ATTACKS ON AUTONOMOUS VEHICLES 10
Miller, D. J., Xiang, Z., & Kesidis, G. (2020). Adversarial learning targeting deep neural network
classification: A comprehensive review of defenses against attacks.DProceedings of the
IEEE,D108(3), 402-433.
Qayyum, A., Usama, M., Qadir, J., & Al-Fuqaha, A. (2020). Securing connected & autonomous
vehicles: Challenges posed by adversarial machine learning and the way forward.DIEEE
Communications Surveys & Tutorials,D22(2), 998-1026.
Serban, A., Poll, E., & Visser, J. (2020). Adversarial examples on object recognition: A
comprehensive survey.DACM Computing Surveys (CSUR),D53(3), 1-38.
Sheik, A. T., Maple, C., Epiphaniou, G., & Dianati, M. (2023). Securing Cloud-Assisted
Connected and Autonomous Vehicles: An In-Depth Threat Analysis and Risk
Assessment.DSensors,D24(1), 241.
Seetharaman, A., Patwa, N., Jadhav, V., Saravanan, A. S., & Sangeeth, D. (2021). Impact of
factors influencing cyber threats on autonomous vehicles.DApplied Artificial
Intelligence,D35(2), 105-132.
Shafik, W., Matinkhah, S. M., & Shokoor, F. (2023). Cybersecurity in uncrewed aerial vehicles:
A review. International Journal on Smart Sensing and Intelligent Systems,D16(1).
Tange, K., De Donno, M., Fafoutis, X., & Dragoni, N. (2020). A systematic survey of industrial
Internet of Things security: Requirements and fog computing opportunities.DIEEE
Communications Surveys & Tutorials,D22(4), 2489-2520.
CYBER RISKS IN ADVERSARIAL AI ATTACKS ON AUTONOMOUS VEHICLES 11
Wang, Z., Wei, H., Wang, J., Zeng, X., & Chang, Y. (2022). Security issues and solutions for
connected and autonomous vehicles in a sustainable city: A survey.DSustainability,D14(19),
12409.
Ying, Z., Wang, K., Xiong, J., & Ma, M. (2024). A literature review on V2X communications
security: Foundation, solutions, status, and future.DIET Communications.
Zhang, D. (2024).DAdversarial Machine Learning and Defenses for Automated and Connected
VehiclesD(Master's thesis, University of Waterloo).
Zhang, Y., Carballo, A., Yang, H., & Takeda, K. (2023). Perception and sensing for autonomous
vehicles under adverse weather conditions: A survey.DISPRS Journal of Photogrammetry
and Remote Sensing,D196, 146-177.
Zheng, Y., Li, Z., Xu, X., & Zhao, Q. (2022). Dynamic defenses in cyber security: Techniques,
methods, and challenges.DDigital Communications and Networks,D8(4), 422-435.