A Deep Neural Network Attack Simulation against Data Storage of Autonomous Vehicles

Features
Authors Abstract
Content
In the pursuit of advancing autonomous vehicles (AVs), data-driven algorithms have become pivotal in replacing human perception and decision-making. While deep neural networks (DNNs) hold promise for perception tasks, the potential for catastrophic consequences due to algorithmic flaws is concerning. A well-known incident in 2016, involving a Tesla autopilot misidentifying a white truck as a cloud, underscores the risks and security vulnerabilities. In this article, we present a novel threat model and risk assessment (TARA) analysis on AV data storage, delving into potential threats and damage scenarios. Specifically, we focus on DNN parameter manipulation attacks, evaluating their impact on three distinct algorithms for traffic sign classification and lane assist. Our comprehensive tests and simulations reveal that even a single bit-flip of a DNN parameter can severely degrade classification accuracy to less than 10%, posing significant risks to the overall performance and safety of AVs. Additionally, we identify critical parameters based on bit position, layer position, and bit-flipping direction, offering essential insights for developing robust security measures in autonomous vehicle systems.
Meta TagsDetails
DOI
https://doi.org/10.4271/12-07-02-0008
Pages
17
Citation
Kim, I., Lee, G., Lee, S., and Choi , W., "A Deep Neural Network Attack Simulation against Data Storage of Autonomous Vehicles," SAE Int. J. CAV 7(2):127-143, 2024, https://doi.org/10.4271/12-07-02-0008.
Additional Details
Publisher
Published
Sep 29, 2023
Product Code
12-07-02-0008
Content Type
Journal Article
Language
English