Protecting Autonomous Vehicles Against Cyberattacks

TUM

Driver-assistance systems are now installed in nearly all modern cars. As a result, safety depends on whether computer systems can reliably process sensor data. Researchers at the Technical University of Munich (TUM) are therefore investigating how these systems can be specifically manipulated - with the goal of better protecting vehicles from such attacks in the future. Even a film discreetly placed over the sensors can cause serious accidents.

Sebastian Steinhorst, Professor of Embedded Systems and the Internet of Things Andreas Heddergott / TUM
Sebastian Steinhorst, Professor of Embedded Systems and the Internet of Things

In brief

  • Tampered cameras and sensors can dangerously mislead autonomous vehicles
  • Even simple interventions, such as placing film over sensors, can distort driving decisions
  • Researchers at TUM are testing attacks and developing protective mechanisms

Cars are equipped with an increasing number of autonomous functions. At the same time, test operations for robotaxis are planned in Munich's city traffic. These vehicles navigate their surroundings using optical sensors. Cameras detect traffic signs, road markings, and other road users; LiDAR systems measure distances and use this data to create a three-dimensional image of the surroundings. If these perception systems are manipulated, it can have safety-critical consequences.

Tampered sensors can distort driving decisions

In a recent publication, the team led by Sebastian Steinhorst, professor of Embedded Systems and Internet of Things, and Mohammad Hamad, group leader for Cybersecurity of Internet of Things and Autonomous Systems at the School of Computation, Information, and Technology , demonstrates that even an inconspicuous film on the sensor's surface can alter the perspective of cameras and LiDAR systems. The researchers use a polycarbonate film featuring a microscopically small, asymmetrical linear prism structure. The film causes light to be deflected by 20 degrees. While the vehicle continues to detect objects and lanes, it misperceives their positions. In reality, these objects and lanes are further to the left or right than assumed. If the displacement exceeds one meter, this can cause the vehicle to make erroneous decisions and, for example, accidentally drive into oncoming traffic.

The researchers are therefore analyzing the various vulnerabilities presented by vehicle cameras, LiDAR sensors, and their data processing systems. The goal is to understand new attack methods and, in particular, to develop ways for vehicles to detect and mitigate such manipulations.

Mobility

Mobility is key to combating climate change. Find out how we are developing new interdisciplinary models for digitally connected, sustainable mobility.

Mobility at TUM

People meet in a Munich street that has been greened with plant boxes MCube / Viktoriya Zayika

Testing attacks first in a digital twin

Before researchers investigate attacks on real vehicles, they test them using digital twins that virtually replicate the vehicle and its surroundings. This allows them to analyze manipulations in a controlled, safe, and cost-effective manner. Attack attempts are then tested, among other places, in a controlled environment using TUM's EDGAR research vehicle.

Vehicles should respond to attacks on their own

In addition to analyzing new attack vectors, the team is also working on ways to defend against attacks. In the long term, intelligent vehicles should be able to independently detect potential risks and respond appropriately. For example, by safely pulling over to the side of the road and indicating-even before the drive begins-that the sensors are not functioning properly. This is particularly important when a human safety control center cannot intervene in time-for example, due to a lack of connection, limited response time, or technical limitations.

Marco Calipari, Michael Kühr, Mohammad Hamad, and Sebastian Steinhorst from the Chair of Embedded Systems and Internet of Things Andreas Heddergott / TUM
Marco Calipari, Michael Kühr, Mohammad Hamad, and Sebastian Steinhorst from the Chair of Embedded Systems and Internet of Things.

Artificial Intelligence

Artificial intelligence is shaping our working lives, research, and the world around us. Learn how we are contributing to this progress by developing innovative AI methods and applications, ranging from robotics to machine learning.

AI and robotics at TUM

Image of the interior of the Leibniz Supercomputing Centre of the Bavarian Academy of Sciences and Humanities Andreas Heddergott / TUM
Publications
  • Marco Calipari, Michael Kühr, Dominik Kulmer, Maximilian Luedecke, Mohammad Hamad, Sebastian Steinhorst: „Perspective-Shift Attacks Against Optical Perception Sensors: A Novel Attack Vector on LiDAR and Camera". 4th USENIX Symposium on Vehicle Security and Privacy (VehicleSec '26), Baltimore, USA, 2026.
  • Michael Kühr, Mohammad Hamad, Pedram MohajerAnsari, Mert D. Pesé, Sebastian Steinhorst: „SoK: Security of the Image Processing Pipeline for Camera-based Sensing in Autonomous Vehicles". ACM Asia Conference on Computer and Communications Security (ASIA CCS '26), Bangalore, Indien, 2026, S. 1738-1754. DOI: 10.1145/3779208.3785267.
  • Andreas Finkenzeller, Anshu Mathur, Jan Lauinger, Mohammad Hamad, Sebastian Steinhorst: „Simutack - An Attack Simulation Framework for Connected and Autonomous Vehicles". IEEE 97th Vehicular Technology Conference: VTC2023-Spring, Florenz, Italien, 2023.

    DOI: 10.1109/VTC2023-Spring57618.2023.10200555

  • Mohammad Hamad, Andreas Finkenzeller, Michael Kühr, Andrew Roberts, Olaf Maennel, Vassilis Prevelakis, Sebastian Steinhorst: „REACT: Autonomous Intrusion Response System for Intelligent Vehicles". Computers & Security, 145, 2024. DOI: 10.1016/j.cose.2024.104008.
Further information and links
/Public Release. This material from the originating organization/author(s) might be of the point-in-time nature, and edited for clarity, style and length. Mirage.News does not take institutional positions or sides, and all views, positions, and conclusions expressed herein are solely those of the author(s).View in full here.