{"status":"ok","message-type":"work","message-version":"1.0.0","message":{"indexed":{"date-parts":[[2026,6,1]],"date-time":"2026-06-01T18:26:23Z","timestamp":1780338383827,"version":"3.54.1"},"publisher-location":"New York, NY, USA","reference-count":67,"publisher":"ACM","license":[{"start":{"date-parts":[[2020,10,30]],"date-time":"2020-10-30T00:00:00Z","timestamp":1604016000000},"content-version":"vor","delay-in-days":0,"URL":"https:\/\/www.acm.org\/publications\/policies\/copyright_policy#Background"}],"content-domain":{"domain":["dl.acm.org"],"crossmark-restriction":true},"short-container-title":[],"published-print":{"date-parts":[[2020,10,30]]},"DOI":"10.1145\/3372297.3423359","type":"proceedings-article","created":{"date-parts":[[2021,3,4]],"date-time":"2021-03-04T16:20:06Z","timestamp":1614874806000},"page":"293-308","update-policy":"https:\/\/doi.org\/10.1145\/crossmark-policy","source":"Crossref","is-referenced-by-count":76,"title":["Phantom of the ADAS: Securing Advanced Driver-Assistance Systems from Split-Second Phantom Attacks"],"prefix":"10.1145","author":[{"given":"Ben","family":"Nassi","sequence":"first","affiliation":[{"name":"Ben-Gurion University of the Negev, Be'er-Sheva, Israel"}],"role":[{"vocabulary":"crossref","role":"author"}]},{"given":"Yisroel","family":"Mirsky","sequence":"additional","affiliation":[{"name":"Ben-Gurion University of the Negev &amp; Georgia Institute of Technology, Atlanta, GA, USA"}],"role":[{"vocabulary":"crossref","role":"author"}]},{"given":"Dudi","family":"Nassi","sequence":"additional","affiliation":[{"name":"Ben-Gurion University of the Negev, Be'er-Sheva, Israel"}],"role":[{"vocabulary":"crossref","role":"author"}]},{"given":"Raz","family":"Ben-Netanel","sequence":"additional","affiliation":[{"name":"Ben-Gurion University of the Negev, Be'er-Sheva, Israel"}],"role":[{"vocabulary":"crossref","role":"author"}]},{"given":"Oleg","family":"Drokin","sequence":"additional","affiliation":[{"name":"Independent Researcher, Knoxville, TN, USA"}],"role":[{"vocabulary":"crossref","role":"author"}]},{"given":"Yuval","family":"Elovici","sequence":"additional","affiliation":[{"name":"Ben Gurion University of the Negev, Be'er-Sheva, Israel"}],"role":[{"vocabulary":"crossref","role":"author"}]}],"member":"320","published-online":{"date-parts":[[2020,11,2]]},"reference":[{"key":"e_1_3_2_2_1_1","unstructured":"Simon Alvarez. [n.d.]. Tesla's approach for Full Self-Driving gets validated by Cornell researchers LiDAR pioneer. https:\/\/www.teslarati.com\/tesla-elon-musk-full-self-driving-lidar-waymo-cornell-study\/.  Simon Alvarez. [n.d.]. Tesla's approach for Full Self-Driving gets validated by Cornell researchers LiDAR pioneer. https:\/\/www.teslarati.com\/tesla-elon-musk-full-self-driving-lidar-waymo-cornell-study\/."},{"key":"e_1_3_2_2_2_1","unstructured":"Anker. 2019. Nebula Capsule. https:\/\/www.amazon.com\/Projector-Anker-Portable-High-Contrast-Playtime\/dp\/B076Q3GBJK.  Anker. 2019. Nebula Capsule. https:\/\/www.amazon.com\/Projector-Anker-Portable-High-Contrast-Playtime\/dp\/B076Q3GBJK."},{"key":"e_1_3_2_2_3_1","doi-asserted-by":"publisher","DOI":"10.1016\/j.neucom.2018.08.009"},{"key":"e_1_3_2_2_4_1","doi-asserted-by":"publisher","DOI":"10.1007\/11744023_32"},{"key":"e_1_3_2_2_5_1","volume-title":"Adversarial patch. arXiv preprint arXiv:1712.09665","author":"Brown Tom B","year":"2017"},{"key":"e_1_3_2_2_6_1","doi-asserted-by":"publisher","DOI":"10.1109\/CVPR42600.2020.01164"},{"key":"e_1_3_2_2_7_1","doi-asserted-by":"publisher","DOI":"10.1145\/3319535.3339815"},{"key":"e_1_3_2_2_8_1","volume-title":"Towards evaluating the robustness of neural networks. In 2017 ieee symposium on security and privacy (sp)","author":"Carlini Nicholas"},{"key":"e_1_3_2_2_9_1","volume-title":"Ead: elastic-net attacks to deep neural networks via adversarial examples. arXiv preprint arXiv:1709.04114","author":"Chen Pin-Yu","year":"2017"},{"key":"e_1_3_2_2_10_1","volume-title":"Joint European Conference on Machine Learning and Knowledge Discovery in Databases. Springer, 52--68","author":"Chen Shang-Tse","year":"2018"},{"key":"e_1_3_2_2_11_1","unstructured":"European Comission. 2016. Advanced driver assistance systems. https:\/\/ec.europa.eu\/transport\/road_safety\/sites\/roadsafety\/files\/ersosynthesis2016-adas15_en.pdf.  European Comission. 2016. Advanced driver assistance systems. https:\/\/ec.europa.eu\/transport\/road_safety\/sites\/roadsafety\/files\/ersosynthesis2016-adas15_en.pdf."},{"key":"e_1_3_2_2_12_1","unstructured":"NEDA CVIJETIC. 2019. DRIVE Labs: Detecting the Distance -- NVIDIA Blog. https:\/\/blogs.nvidia.com\/blog\/2019\/06\/19\/drive-labs-distance-to-object-detection\/. (Accessed on 08\/24\/2020).  NEDA CVIJETIC. 2019. DRIVE Labs: Detecting the Distance -- NVIDIA Blog. https:\/\/blogs.nvidia.com\/blog\/2019\/06\/19\/drive-labs-distance-to-object-detection\/. (Accessed on 08\/24\/2020)."},{"key":"e_1_3_2_2_13_1","volume-title":"R-fcn: Object detection via region-based fully convolutional networks. In Advances in neural information processing systems. 379--387.","author":"Dai Jifeng","year":"2016"},{"key":"e_1_3_2_2_14_1","doi-asserted-by":"publisher","DOI":"10.1145\/3219819.3219910"},{"key":"e_1_3_2_2_15_1","volume-title":"Levels of driving automation are defined in new SAE international standard J3016","author":"Driving Automated","year":"2014"},{"key":"e_1_3_2_2_16_1","unstructured":"Gamaleldin Elsayed Dilip Krishnan Hossein Mobahi Kevin Regan and Samy Bengio. 2018. Large margin deep networks for classification. In Advances in neural information processing systems. 842--852.  Gamaleldin Elsayed Dilip Krishnan Hossein Mobahi Kevin Regan and Samy Bengio. 2018. Large margin deep networks for classification. In Advances in neural information processing systems. 842--852."},{"key":"e_1_3_2_2_17_1","volume-title":"Robust physical-world attacks on deep learning models. arXiv preprint arXiv:1707.08945","author":"Eykholt Kevin","year":"2017"},{"key":"e_1_3_2_2_18_1","volume-title":"Scandinavian conference on Image analysis. Springer, 363--370","author":"Gunnar","year":"2003"},{"key":"e_1_3_2_2_19_1","volume-title":"Survey of pedestrian detection for advanced driver assistance systems","author":"Geronimo David","year":"2009"},{"key":"e_1_3_2_2_20_1","volume-title":"Maximilian M\u00fchlegg, Sebastian Dorn, et al.","author":"Geyer Jakob","year":"2020"},{"key":"e_1_3_2_2_21_1","volume-title":"Explaining and harnessing adversarial examples. arXiv preprint arXiv:1412.6572","author":"Goodfellow Ian J","year":"2014"},{"key":"e_1_3_2_2_22_1","doi-asserted-by":"publisher","DOI":"10.1016\/j.cose.2018.11.004"},{"key":"e_1_3_2_2_23_1","volume-title":"Deep Residual Learning for Image Recognition. In 2016 IEEE Conference on Computer Vision and Pattern Recognition (CVPR). 770--778","author":"He K."},{"key":"e_1_3_2_2_24_1","volume-title":"Mobilenets: Efficient convolutional neural networks for mobile vision applications. arXiv preprint arXiv:1704.04861","author":"Howard Andrew G","year":"2017"},{"key":"e_1_3_2_2_25_1","doi-asserted-by":"publisher","DOI":"10.1109\/CVPR.2017.351"},{"key":"e_1_3_2_2_26_1","volume-title":"Handbook of neural network signal processing","author":"Hwang Jenq-Neng"},{"key":"e_1_3_2_2_27_1","unstructured":"Car Industry. 2019. Safety First For Automated Driving. https:\/\/www.daimler.com\/documents\/innovation\/other\/safety-first-for-automated-driving.pdf\".  Car Industry. 2019. Safety First For Automated Driving. https:\/\/www.daimler.com\/documents\/innovation\/other\/safety-first-for-automated-driving.pdf\"."},{"key":"e_1_3_2_2_28_1","volume-title":"Batch normalization: Accelerating deep network training by reducing internal covariate shift. arXiv preprint arXiv:1502.03167","author":"Ioffe Sergey","year":"2015"},{"key":"e_1_3_2_2_29_1","doi-asserted-by":"publisher","DOI":"10.1145\/3134600.3134635"},{"key":"e_1_3_2_2_30_1","volume-title":"Multi-Scale Defense of Adversarial Images. In 2019 IEEE International Conference on Image Processing (ICIP). IEEE, 4070--4074","author":"Ji Jiahuan","year":"2019"},{"key":"e_1_3_2_2_31_1","unstructured":"keen labs. 2019. Tencent Keen Security Lab: Experimental Security Research of Tesla Autopilot. https:\/\/keenlab.tencent.com\/en\/2019\/03\/29\/Tencent-Keen-Security-Lab-Experimental-Security-Research-of-Tesla-Autopilot\/.  keen labs. 2019. Tencent Keen Security Lab: Experimental Security Research of Tesla Autopilot. https:\/\/keenlab.tencent.com\/en\/2019\/03\/29\/Tencent-Keen-Security-Lab-Experimental-Security-Research-of-Tesla-Autopilot\/."},{"key":"e_1_3_2_2_32_1","volume-title":"Adversarial examples in the physical world. arXiv preprint arXiv:1607.02533","author":"Kurakin Alexey","year":"2016"},{"key":"e_1_3_2_2_33_1","unstructured":"Timothy Lee. [n.d.]. Intel's Mobileye has a plan to dominate self-driving?and it might work. https:\/\/arstechnica.com\/cars\/2020\/01\/intels-mobileye-has-a-plan-to-dominate-self-driving-and-it-might-work\/.  Timothy Lee. [n.d.]. Intel's Mobileye has a plan to dominate self-driving?and it might work. https:\/\/arstechnica.com\/cars\/2020\/01\/intels-mobileye-has-a-plan-to-dominate-self-driving-and-it-might-work\/."},{"key":"e_1_3_2_2_34_1","unstructured":"Timothy Lee. 2019 a. Men hack electronic billboard play porn on it. https:\/\/arstechnica.com\/tech-policy\/2019\/10\/men-hack-electronic-billboard-play-porn-on-it\/.  Timothy Lee. 2019 a. Men hack electronic billboard play porn on it. https:\/\/arstechnica.com\/tech-policy\/2019\/10\/men-hack-electronic-billboard-play-porn-on-it\/."},{"key":"e_1_3_2_2_35_1","unstructured":"Timothy Lee. 2019 b. Waymo tells riders to get ready for fully driverless rides. https:\/\/arstechnica.com\/cars\/2019\/10\/waymo-starts-offering-driverless-rides-to-ordinary-riders-in-phoenix\/.  Timothy Lee. 2019 b. Waymo tells riders to get ready for fully driverless rides. https:\/\/arstechnica.com\/cars\/2019\/10\/waymo-starts-offering-driverless-rides-to-ordinary-riders-in-phoenix\/."},{"key":"e_1_3_2_2_36_1","doi-asserted-by":"publisher","DOI":"10.1007\/978-3-319-46448-0_2"},{"key":"e_1_3_2_2_37_1","volume-title":"On Configurable Defense against Adversarial Example Attacks. arXiv preprint arXiv:1812.02737","author":"Luo Bo","year":"2018"},{"key":"e_1_3_2_2_38_1","doi-asserted-by":"publisher","DOI":"10.14722\/ndss.2019.23415"},{"key":"e_1_3_2_2_39_1","unstructured":"Mobileye. [n.d.]. Mobileye 6-Series - User Manual. http:\/\/www.c2sec.com.sg\/Files\/UserManualMobileye6.pdf.  Mobileye. [n.d.]. Mobileye 6-Series - User Manual. http:\/\/www.c2sec.com.sg\/Files\/UserManualMobileye6.pdf."},{"key":"e_1_3_2_2_40_1","doi-asserted-by":"publisher","DOI":"10.1109\/CVPR.2016.282"},{"key":"e_1_3_2_2_41_1","volume-title":"denoise, and defend against adversarial attacks. arXiv preprint arXiv:1802.06806","author":"Moosavi-Dezfooli Seyed-Mohsen","year":"2018"},{"key":"e_1_3_2_2_42_1","volume-title":"Fooling a Real Car with Adversarial Traffic Signs. arXiv preprint arXiv:1907.00374","author":"Morgulis Nir","year":"2019"},{"key":"e_1_3_2_2_43_1","doi-asserted-by":"publisher","DOI":"10.1109\/ICCCE.2012.6271270"},{"key":"e_1_3_2_2_44_1","doi-asserted-by":"publisher","DOI":"10.1109\/SP.2019.00051"},{"key":"e_1_3_2_2_45_1","doi-asserted-by":"publisher","DOI":"10.1109\/TIFS.2018.2854708"},{"key":"e_1_3_2_2_46_1","volume-title":"Beat Buesser, Ambrish Rawat, Martin Wistuba, Valentina Zantedeschi, Nathalie Baracaldo, Bryant Chen, Heiko Ludwig, Ian Molloy, and Ben Edwards.","author":"Nicolae Maria-Irina","year":"2018"},{"key":"e_1_3_2_2_47_1","unstructured":"NTSB. 2020. Collision Between a Sport Utility Vehicle Operating With Partial Driving Automation and a Crash Attenuator Mountain View California. https:\/\/www.ntsb.gov\/investigations\/AccidentReports\/Reports\/HAR2001.pdf.  NTSB. 2020. Collision Between a Sport Utility Vehicle Operating With Partial Driving Automation and a Crash Attenuator Mountain View California. https:\/\/www.ntsb.gov\/investigations\/AccidentReports\/Reports\/HAR2001.pdf."},{"key":"e_1_3_2_2_48_1","doi-asserted-by":"publisher","DOI":"10.1109\/EuroSP.2016.36"},{"key":"e_1_3_2_2_49_1","first-page":"2015","article-title":"Remote attacks on automated vehicles sensors: Experiments on camera and lidar","volume":"11","author":"Petit Jonathan","year":"2015","journal-title":"Black Hat Europe"},{"key":"e_1_3_2_2_50_1","volume-title":"Stronger. In 2017 IEEE Conference on Computer Vision and Pattern Recognition (CVPR). 6517--6525","author":"Redmon J."},{"key":"e_1_3_2_2_51_1","unstructured":"Regulus. [n.d.]. Tesla Model 3 Spoofed off the highway - Regulus Navigation System Hack Causes Car to Turn On Its Own. https:\/\/www.regulus.com\/blog\/tesla-model-3-spoofed-off-the-highway-regulus-researches-hack-navigation-system-causing-car-to-steer-off-road\/.  Regulus. [n.d.]. Tesla Model 3 Spoofed off the highway - Regulus Navigation System Hack Causes Car to Turn On Its Own. https:\/\/www.regulus.com\/blog\/tesla-model-3-spoofed-off-the-highway-regulus-researches-hack-navigation-system-causing-car-to-steer-off-road\/."},{"key":"e_1_3_2_2_52_1","unstructured":"Shaoqing Ren Kaiming He Ross Girshick and Jian Sun. 2015. Faster r-cnn: Towards real-time object detection with region proposal networks. In Advances in neural information processing systems. 91--99.  Shaoqing Ren Kaiming He Ross Girshick and Jian Sun. 2015. Faster r-cnn: Towards real-time object detection with region proposal networks. In Advances in neural information processing systems. 91--99."},{"key":"e_1_3_2_2_53_1","unstructured":"Anjali Berdia Simona Shemer. 2019. Self-Driving Spin: Riding In An Autonomous Vehicle Around Tel Aviv. https:\/\/nocamels.com\/2019\/06\/autonomous-vehicle-yandex-tech\/.  Anjali Berdia Simona Shemer. 2019. Self-Driving Spin: Riding In An Autonomous Vehicle Around Tel Aviv. https:\/\/nocamels.com\/2019\/06\/autonomous-vehicle-yandex-tech\/."},{"key":"e_1_3_2_2_54_1","volume-title":"Arsalan Mosenia, Mung Chiang, and Prateek Mittal.","author":"Sitawarin Chawin","year":"2018"},{"key":"e_1_3_2_2_55_1","volume-title":"USENIX Workshop on Offensive Technologies (WOOT 18)","author":"Song Dawn","year":"2018"},{"key":"e_1_3_2_2_56_1","unstructured":"Jack Stewart. 2018. Why Tesla's Autopilot Can't See a Stopped Firetruck. https:\/\/www.wired.com\/story\/tesla-autopilot-why-crash-radar\/.  Jack Stewart. 2018. Why Tesla's Autopilot Can't See a Stopped Firetruck. https:\/\/www.wired.com\/story\/tesla-autopilot-why-crash-radar\/."},{"key":"e_1_3_2_2_57_1","volume-title":"Towards Robust LiDAR-based Perception in Autonomous Driving: General Black-box Adversarial Sensor Attack and Countermeasures. In 29th USENIX Security Symposium (USENIX Security 20)","author":"Sun Jiachen"},{"key":"e_1_3_2_2_58_1","doi-asserted-by":"publisher","DOI":"10.1109\/CVPR42600.2020.00252"},{"key":"e_1_3_2_2_59_1","unstructured":"Tesla. [n.d.]. Tesla Vehicle Safety Report. https:\/\/www.tesla.com\/VehicleSafetyReport.  Tesla. [n.d.]. Tesla Vehicle Safety Report. https:\/\/www.tesla.com\/VehicleSafetyReport."},{"key":"e_1_3_2_2_60_1","unstructured":"Tesla. 2020. Model S - Owner's Manual. https:\/\/www.tesla.com\/sites\/default\/files\/model_s_owners_manual_north_america_en_us.pdf.  Tesla. 2020. Model S - Owner's Manual. https:\/\/www.tesla.com\/sites\/default\/files\/model_s_owners_manual_north_america_en_us.pdf."},{"key":"e_1_3_2_2_61_1","unstructured":"Security Tutorials. [n.d.]. Hacking Digital Billboards. https:\/\/securitytutorials.co.uk\/hacking-digital-billboards\/.  Security Tutorials. [n.d.]. Hacking Digital Billboards. https:\/\/securitytutorials.co.uk\/hacking-digital-billboards\/."},{"key":"e_1_3_2_2_62_1","doi-asserted-by":"publisher","DOI":"10.1109\/TPAMI.2019.2926463"},{"key":"e_1_3_2_2_63_1","volume-title":"arXiv preprint arXiv:1811.09831","author":"Wu Shangxi","year":"2018"},{"key":"e_1_3_2_2_64_1","doi-asserted-by":"publisher","DOI":"10.1007\/978-3-642-40779-6_13"},{"key":"e_1_3_2_2_65_1","volume-title":"DEF CON","volume":"24","author":"Yan Chen","year":"2016"},{"key":"e_1_3_2_2_66_1","doi-asserted-by":"publisher","DOI":"10.1145\/3319535.3354259"},{"key":"e_1_3_2_2_67_1","volume-title":"Invisible mask: Practical attacks on face recognition with infrared. arXiv preprint arXiv:1803.04683","author":"Zhou Zhe","year":"2018"}],"event":{"name":"CCS '20: 2020 ACM SIGSAC Conference on Computer and Communications Security","location":"Virtual Event USA","acronym":"CCS '20","sponsor":["SIGSAC ACM Special Interest Group on Security, Audit, and Control"]},"container-title":["Proceedings of the 2020 ACM SIGSAC Conference on Computer and Communications Security"],"original-title":[],"link":[{"URL":"https:\/\/dl.acm.org\/doi\/10.1145\/3372297.3423359","content-type":"unspecified","content-version":"vor","intended-application":"text-mining"},{"URL":"https:\/\/dl.acm.org\/doi\/pdf\/10.1145\/3372297.3423359","content-type":"unspecified","content-version":"vor","intended-application":"similarity-checking"}],"deposited":{"date-parts":[[2025,6,17]],"date-time":"2025-06-17T22:02:20Z","timestamp":1750197740000},"score":1,"resource":{"primary":{"URL":"https:\/\/dl.acm.org\/doi\/10.1145\/3372297.3423359"}},"subtitle":[],"short-title":[],"issued":{"date-parts":[[2020,10,30]]},"references-count":67,"alternative-id":["10.1145\/3372297.3423359","10.1145\/3372297"],"URL":"https:\/\/doi.org\/10.1145\/3372297.3423359","relation":{},"subject":[],"published":{"date-parts":[[2020,10,30]]},"assertion":[{"value":"2020-11-02","order":2,"name":"published","label":"Published","group":{"name":"publication_history","label":"Publication History"}}]}}