{"status":"ok","message-type":"work","message-version":"1.0.0","message":{"indexed":{"date-parts":[[2025,8,27]],"date-time":"2025-08-27T16:04:06Z","timestamp":1756310646293,"version":"3.43.0"},"publisher-location":"New York, NY, USA","reference-count":100,"publisher":"ACM","license":[{"start":{"date-parts":[[2025,8,24]],"date-time":"2025-08-24T00:00:00Z","timestamp":1755993600000},"content-version":"vor","delay-in-days":0,"URL":"http:\/\/www.acm.org\/publications\/policies\/copyright_policy#Background"}],"funder":[{"DOI":"10.13039\/100000001","name":"NSF (National Science Foundation)","doi-asserted-by":"publisher","award":["2402941"],"award-info":[{"award-number":["2402941"]}],"id":[{"id":"10.13039\/100000001","id-type":"DOI","asserted-by":"publisher"}]}],"content-domain":{"domain":["dl.acm.org"],"crossmark-restriction":true},"short-container-title":[],"published-print":{"date-parts":[[2025,8,25]]},"DOI":"10.1145\/3708821.3710832","type":"proceedings-article","created":{"date-parts":[[2025,8,13]],"date-time":"2025-08-13T06:30:56Z","timestamp":1755066656000},"page":"1065-1082","update-policy":"https:\/\/doi.org\/10.1145\/crossmark-policy","source":"Crossref","is-referenced-by-count":1,"title":["Runtime Stealthy Perception Attacks against DNN-based Adaptive Cruise Control Systems"],"prefix":"10.1145","author":[{"ORCID":"https:\/\/orcid.org\/0000-0002-3663-7447","authenticated-orcid":false,"given":"Xugui","family":"Zhou","sequence":"first","affiliation":[{"name":"Louisiana State University, Baton Rouge, USA"}],"role":[{"role":"author","vocabulary":"crossref"}]},{"ORCID":"https:\/\/orcid.org\/0009-0006-5439-3075","authenticated-orcid":false,"given":"Anqi","family":"Chen","sequence":"additional","affiliation":[{"name":"Northeastern University, Boston, USA"}],"role":[{"role":"author","vocabulary":"crossref"}]},{"ORCID":"https:\/\/orcid.org\/0000-0002-4727-379X","authenticated-orcid":false,"given":"Maxfield","family":"Kouzel","sequence":"additional","affiliation":[{"name":"University of Virginia, Charlottesville, USA"}],"role":[{"role":"author","vocabulary":"crossref"}]},{"ORCID":"https:\/\/orcid.org\/0000-0002-7333-3207","authenticated-orcid":false,"given":"Haotian","family":"Ren","sequence":"additional","affiliation":[{"name":"University of Virginia, Charlottesville, USA"}],"role":[{"role":"author","vocabulary":"crossref"}]},{"ORCID":"https:\/\/orcid.org\/0009-0002-1413-853X","authenticated-orcid":false,"given":"Morgan","family":"McCarty","sequence":"additional","affiliation":[{"name":"Northeastern University, Boston, USA"}],"role":[{"role":"author","vocabulary":"crossref"}]},{"ORCID":"https:\/\/orcid.org\/0000-0002-9649-6789","authenticated-orcid":false,"given":"Cristina","family":"Nita-Rotaru","sequence":"additional","affiliation":[{"name":"Northeastern University, Boston, USA"}],"role":[{"role":"author","vocabulary":"crossref"}]},{"ORCID":"https:\/\/orcid.org\/0000-0001-5279-842X","authenticated-orcid":false,"given":"Homa","family":"Alemzadeh","sequence":"additional","affiliation":[{"name":"University of Virginia, Charlottesville, USA"}],"role":[{"role":"author","vocabulary":"crossref"}]}],"member":"320","published-online":{"date-parts":[[2025,8,24]]},"reference":[{"key":"e_1_3_3_1_2_2","unstructured":"[n. d.]. ADAS Cameras: How They Work and Why They Need Calibration. https:\/\/caradas.com\/adas-cameras\/."},{"key":"e_1_3_3_1_3_2","unstructured":"[n. d.]. ADAS User Study. https:\/\/drive.google.com\/file\/d\/1GtMQpmgIzu4ZcjRbYKQfdE1q8WEEYPue\/view?usp=sharing."},{"key":"e_1_3_3_1_4_2","unstructured":"[n. d.]. comma connect. https:\/\/www.comma.ai\/connect."},{"key":"e_1_3_3_1_5_2","unstructured":"[n. d.]. Cybersecurity Risks for Hi-Tech Autonomous and Electric Vehicles Industry. https:\/\/www.linkedin.com\/pulse\/cybersecurity-risks-hi-tech-autonomous-electric-vehicles-samrat-seal\/."},{"key":"e_1_3_3_1_6_2","unstructured":"[n. d.]. GRVA-12-50r1e.pdf. https:\/\/unece.org\/sites\/default\/files\/2022-01\/GRVA-12-50r1e.pdf."},{"key":"e_1_3_3_1_7_2","unstructured":"[n. d.]. Installing a Fork of Openpilot with Workbench. https:\/\/medium.com\/@jfrux\/installing-a-fork-of-openpilot-with-workbench-de35e9388021."},{"key":"e_1_3_3_1_8_2","unstructured":"[n. d.]. Panda. https:\/\/github.com\/commaai\/panda."},{"key":"e_1_3_3_1_9_2","unstructured":"[n. d.]. Qualtrics. https:\/\/www.qualtrics.com\/."},{"key":"e_1_3_3_1_10_2","unstructured":"[n. d.]. Supported Cars by OpenPilot. https:\/\/github.com\/commaai\/openpilot\/blob\/master\/docs\/CARS.md."},{"key":"e_1_3_3_1_11_2","unstructured":"[n. d.]. Tesla Autopilot. https:\/\/www.tesla.com\/autopilot."},{"key":"e_1_3_3_1_12_2","unstructured":"2018. Safety Architecture. https:\/\/blog.comma.ai\/how-to-write-a-car-port-for-openpilot."},{"key":"e_1_3_3_1_13_2","unstructured":"2018. Taxonomy and definitions for terms related to driving automation systems for on-road motor vehicles. SAE international 4970 724 (2018) 1\u20135."},{"key":"e_1_3_3_1_14_2","unstructured":"2020. OpenPilot: An Overview and the Port to the Honda Clarity: Hardware. https:\/\/wirelessnet2.medium.com\/openpilot-an-overview-and-the-port-to-the-honda-clarity-16341d53c9aa."},{"key":"e_1_3_3_1_15_2","unstructured":"2020. UN Regulation No 152 \u2013 Uniform provisions concerning the approval of motor vehicles with regard to the Advanced Emergency Braking System (AEBS) for M1 and N1 vehicles [2020\/1597]. http:\/\/data.europa.eu\/eli\/reg\/2020\/1597\/oj. 66-89\u00a0pages."},{"key":"e_1_3_3_1_16_2","unstructured":"2021. Adaptive Cruise Control (ACC) Operating Characteristics and User Interface: Standard J2399. Society of Automotive Engineers (2021)."},{"key":"e_1_3_3_1_17_2","unstructured":"2021. BMW 3 Series Dimensions. https:\/\/www.carsguide.com.au\/bmw\/3-series\/car-dimensions\/2021."},{"key":"e_1_3_3_1_18_2","unstructured":"2021. Openpilot SSH Key security bypass. https:\/\/www.redpacketsecurity.com\/openpilot-ssh-key-security-bypass\/."},{"key":"e_1_3_3_1_19_2","unstructured":"2021. SAE Levels of Driving Automation\u2122 Refined for Clarity and International Audience. https:\/\/www.sae.org\/blog\/sae-j3016-update."},{"key":"e_1_3_3_1_20_2","unstructured":"2022. Number of autonomous vehicles globally in 2022. https:\/\/www.statista.com\/statistics\/1230664\/projected-number-autonomous-cars-worldwide\/"},{"key":"e_1_3_3_1_21_2","doi-asserted-by":"publisher","unstructured":"Turki Alsuwian Rana\u00a0Basharat Saeed and Arslan\u00a0Ahmed Amin. 2022. Autonomous Vehicle with Emergency Braking Algorithm Based on Multi-Sensor Fusion and Super Twisting Speed Controller. Applied Sciences 12 17 (Aug. 2022) 8458. 10.3390\/app12178458","DOI":"10.3390\/app12178458"},{"key":"e_1_3_3_1_22_2","unstructured":"Baidu. [n. d.]. Apollo. https:\/\/developer.apollo.auto\/."},{"key":"e_1_3_3_1_23_2","unstructured":"Gary Bishop Greg Welch et\u00a0al. 2001. An introduction to the kalman filter. Proc of SIGGRAPH Course 8 27599-23175 (2001) 41."},{"key":"e_1_3_3_1_24_2","volume-title":"Modern control systems","author":"Bishop Richard C Dorf Robert\u00a0H","year":"2011","unstructured":"Richard C Dorf Robert\u00a0H Bishop. 2011. Modern control systems."},{"key":"e_1_3_3_1_25_2","volume-title":"Model predictive control","author":"Camacho Eduardo\u00a0F","year":"2013","unstructured":"Eduardo\u00a0F Camacho and Carlos\u00a0Bordons Alba. 2013. Model predictive control. Springer science & business media."},{"key":"e_1_3_3_1_26_2","doi-asserted-by":"crossref","unstructured":"Amirhosein Chahe Chenan Wang Abhishek Jeyapratap Kaidi Xu and Lifeng Zhou. 2023. Dynamic Adversarial Attacks on Autonomous Driving Systems. arXiv preprint arXiv:https:\/\/arXiv.org\/abs\/2312.06701 (2023).","DOI":"10.15607\/RSS.2024.XX.076"},{"key":"e_1_3_3_1_27_2","unstructured":"Li Chen Tutian Tang Zhitian Cai Yang Li Penghao Wu Hongyang Li Jianping Shi Junchi Yan and Yu Qiao. 2022. Level 2 autonomous driving on a single device: Diving into the devils of openpilot. arXiv:https:\/\/arXiv.org\/abs\/2206.08176 (2022)."},{"key":"e_1_3_3_1_28_2","doi-asserted-by":"publisher","DOI":"10.1145\/3579856.3582816"},{"key":"e_1_3_3_1_29_2","first-page":"349","volume-title":"23rd International Symposium on Research in Attacks, Intrusions and Defenses (RAID)","author":"Choi Hongjun","year":"2020","unstructured":"Hongjun Choi, Sayali Kate, Yousra Aafer, Xiangyu Zhang, and Dongyan Xu. 2020. Software-based Realtime Recovery from Sensor Attacks on Robotic Vehicles. In 23rd International Symposium on Research in Attacks, Intrusions and Defenses (RAID). 349\u2013364."},{"key":"e_1_3_3_1_30_2","unstructured":"Comma.ai. [n. d.]. Openpilot. https:\/\/comma.ai\/openpilot."},{"key":"e_1_3_3_1_31_2","unstructured":"Comma.ai. [n. d.]. Supercombo. https:\/\/github.com\/commaai\/openpilot\/tree\/90af436a121164a51da9fa48d093c29f738adf6a\/selfdrive\/modeld\/models."},{"key":"e_1_3_3_1_32_2","unstructured":"Consumer Reports. [n. d.]. CR Active Driving Assistance Systems: Test Results & Design Recommendations. https:\/\/data.consumerreports.org\/reports\/cr-active-driving-assistance-systems\/."},{"key":"e_1_3_3_1_33_2","first-page":"2206","volume-title":"International conference on machine learning","author":"Croce Francesco","year":"2020","unstructured":"Francesco Croce and Matthias Hein. 2020. Reliable evaluation of adversarial robustness with an ensemble of diverse parameter-free attacks. In International conference on machine learning. PMLR, 2206\u20132216."},{"key":"e_1_3_3_1_34_2","doi-asserted-by":"publisher","DOI":"10.1145\/3471621.3471869"},{"key":"e_1_3_3_1_35_2","first-page":"1","volume-title":"Proceedings of the 1st Annual Conference on Robot Learning","author":"Dosovitskiy Alexey","year":"2017","unstructured":"Alexey Dosovitskiy, German Ros, Felipe Codevilla, Antonio Lopez, and Vladlen Koltun. 2017. CARLA: An Open Urban Driving Simulator. In Proceedings of the 1st Annual Conference on Robot Learning. 1\u201316."},{"key":"e_1_3_3_1_36_2","unstructured":"Gintare\u00a0Karolina Dziugaite Zoubin Ghahramani and Daniel\u00a0M Roy. 2016. A study of the effect of jpg compression on adversarial images. arXiv:https:\/\/arXiv.org\/abs\/1608.00853 (2016)."},{"key":"e_1_3_3_1_37_2","doi-asserted-by":"crossref","unstructured":"Mahmoud\u00a0Hashem Eiza and Qiang Ni. 2017. Driving with sharks: Rethinking connected vehicles with vehicle cybersecurity. IEEE Vehicular Technology Magazine 12 2 (2017) 45\u201351.","DOI":"10.1109\/MVT.2017.2669348"},{"key":"e_1_3_3_1_38_2","doi-asserted-by":"crossref","unstructured":"Abdulrahman\u00a0Abu Elkhail Rafi Ud\u00a0Daula Refat Ricardo Habre Azeem Hafeez Anys Bacha and Hafiz Malik. 2021. Vehicle security: A survey of security issues and vulnerabilities malware attacks and defenses. IEEE Access 9 (2021) 162401\u2013162437.","DOI":"10.1109\/ACCESS.2021.3130495"},{"key":"e_1_3_3_1_39_2","doi-asserted-by":"publisher","DOI":"10.1109\/CVPR.2018.00175"},{"key":"e_1_3_3_1_40_2","unstructured":"Ian\u00a0J Goodfellow Jonathon Shlens and Christian Szegedy. 2014. Explaining and harnessing adversarial examples. arXiv:https:\/\/arXiv.org\/abs\/1412.6572 (2014)."},{"key":"e_1_3_3_1_41_2","unstructured":"Andy Greenberg. 2015. Hackers Remotely Kill a Jeep on the Highway\u2014With Me in It. https:\/\/www.wired.com\/2015\/07\/hackers-remotely-kill-jeep-highway\/. Wired (2015)."},{"key":"e_1_3_3_1_42_2","doi-asserted-by":"publisher","DOI":"10.1145\/3576914.3587493"},{"key":"e_1_3_3_1_43_2","first-page":"1903","volume-title":"31st USENIX Security Symposium (USENIX Security 22)","author":"Hallyburton R\u00a0Spencer","year":"2022","unstructured":"R\u00a0Spencer Hallyburton, Yupei Liu, Yulong Cao, Z\u00a0Morley Mao, and Miroslav Pajic. 2022. Security analysis of Camera-LiDAR fusion against Black-Box attacks on autonomous vehicles. In 31st USENIX Security Symposium (USENIX Security 22). 1903\u20131920."},{"key":"e_1_3_3_1_44_2","unstructured":"Shahar Hoory Tzvika Shapira Asaf Shabtai and Yuval Elovici. 2020. Dynamic adversarial patch for evading object detection models. arXiv:https:\/\/arXiv.org\/abs\/2010.13070 (2020)."},{"key":"e_1_3_3_1_45_2","doi-asserted-by":"crossref","unstructured":"John Hunt and John Hunt. 2019. Monkey Patching and Attribute Lookup. A Beginners Guide to Python 3 Programming (2019) 325\u2013336.","DOI":"10.1007\/978-3-030-20290-3_28"},{"key":"e_1_3_3_1_46_2","doi-asserted-by":"publisher","DOI":"10.1109\/DSN.2019.00025"},{"key":"e_1_3_3_1_47_2","doi-asserted-by":"publisher","DOI":"10.1109\/DSN48063.2020.00030"},{"key":"e_1_3_3_1_48_2","unstructured":"Yunhan Jia Yantao Lu Junjie Shen Qi\u00a0Alfred Chen Zhenyu Zhong and Tao Wei. 2019. Fooling detection alone is not enough: First adversarial attack against multiple object tracking. arXiv:https:\/\/arXiv.org\/abs\/1905.11026 (2019)."},{"key":"e_1_3_3_1_49_2","doi-asserted-by":"publisher","unstructured":"Kyounggon Kim Jun\u00a0Seok Kim Seonghoon Jeong Jo-Hee Park and Huy\u00a0Kang Kim. 2021. Cybersecurity for autonomous vehicles: Review of attacks and defense. Computers \\(\\&\\) Security 103 (2021) 102150. 10.1016\/j.cose.2020.102150","DOI":"10.1016\/j.cose.2020.102150"},{"key":"e_1_3_3_1_50_2","doi-asserted-by":"publisher","DOI":"10.1145\/3474376.3487283"},{"key":"e_1_3_3_1_51_2","doi-asserted-by":"publisher","DOI":"10.1109\/SP.2010.34"},{"key":"e_1_3_3_1_52_2","doi-asserted-by":"publisher","DOI":"10.1201\/9781351251389-8"},{"key":"e_1_3_3_1_53_2","doi-asserted-by":"publisher","DOI":"10.1109\/IRC.2019.00023"},{"key":"e_1_3_3_1_54_2","unstructured":"Mark Lee and Zico Kolter. 2019. On physical adversarial patches for object detection. arXiv:https:\/\/arXiv.org\/abs\/1906.11897 (2019)."},{"key":"e_1_3_3_1_55_2","unstructured":"Nancy Leveson and John Thomas. 2013. An STPA Primer. Cambridge MA (2013)."},{"key":"e_1_3_3_1_56_2","first-page":"3896","volume-title":"International Conference on Machine Learning","author":"Li Juncheng","year":"2019","unstructured":"Juncheng Li, Frank Schmidt, and Zico Kolter. 2019. Adversarial camera stickers: A physical camera-based attack on deep learning systems. In International Conference on Machine Learning. 3896\u20133904."},{"key":"e_1_3_3_1_57_2","doi-asserted-by":"publisher","DOI":"10.1109\/CVPR52688.2022.01455"},{"key":"e_1_3_3_1_58_2","unstructured":"Xin Liu Huanrui Yang Ziwei Liu Linghao Song Hai Li and Yiran Chen. 2018. Dpatch: An adversarial patch attack on object detectors. arXiv:https:\/\/arXiv.org\/abs\/1806.02299 (2018)."},{"key":"e_1_3_3_1_59_2","first-page":"1865","volume-title":"30th USENIX Security Symposium (USENIX Security 21)","author":"Lovisotto Giulio","year":"2021","unstructured":"Giulio Lovisotto, Henry Turner, Ivo Sluganovic, Martin Strohmeier, and Ivan Martinovic. 2021. SLAP: Improving physical adversarial examples with Short-Lived adversarial perturbations. In 30th USENIX Security Symposium (USENIX Security 21). 1865\u20131882."},{"key":"e_1_3_3_1_60_2","doi-asserted-by":"publisher","DOI":"10.1007\/978-3-031-02067-4"},{"key":"e_1_3_3_1_61_2","doi-asserted-by":"publisher","DOI":"10.14722\/vehiclesec.2023.23063"},{"key":"e_1_3_3_1_62_2","doi-asserted-by":"publisher","DOI":"10.14722\/vehiclesec.2023.23063"},{"key":"e_1_3_3_1_63_2","doi-asserted-by":"publisher","DOI":"10.14722\/autosec.2021.23015"},{"key":"e_1_3_3_1_64_2","unstructured":"Aleksander Madry Aleksandar Makelov Ludwig Schmidt Dimitris Tsipras and Adrian Vladu. 2017. Towards deep learning models resistant to adversarial attacks. arXiv:https:\/\/arXiv.org\/abs\/1706.06083 (2017)."},{"key":"e_1_3_3_1_65_2","first-page":"6929","volume-title":"32nd USENIX Security Symposium (USENIX Security 23)","author":"Man Yanmao","year":"2023","unstructured":"Yanmao Man, Raymond Muller, Ming Li, Z\u00a0Berkay Celik, and Ryan Gerdes. 2023. That person moves like a car: Misclassification attack detection for autonomous systems using spatiotemporal consistency. In 32nd USENIX Security Symposium (USENIX Security 23). 6929\u20136946."},{"key":"e_1_3_3_1_66_2","unstructured":"Charlie Miller and Chris Valasek. 2015. Remote exploitation of an unaltered passenger vehicle. Black Hat USA 2015 S 91 (2015) 1\u201391."},{"key":"e_1_3_3_1_67_2","volume-title":"Cenex-LCV and Cenex-CAM 2023","author":"Mocnik Rudi","unstructured":"Rudi Mocnik, Daniel\u00a0S Fowler, and Carsten Maple. [n. d.]. Vehicular Over-the-Air Software Upgrade Threat Modelling. In Cenex-LCV and Cenex-CAM 2023. https:\/\/wrap.warwick.ac.uk\/179188\/1\/WRAP-vehicular-over-the-air-software-upgrade-threat-modelling-2023.pdf"},{"key":"e_1_3_3_1_68_2","doi-asserted-by":"publisher","DOI":"10.1109\/CVPR.2016.282"},{"key":"e_1_3_3_1_69_2","doi-asserted-by":"publisher","DOI":"10.1109\/DSN-W50199.2020.00028"},{"key":"e_1_3_3_1_70_2","volume-title":"Pre-crash scenario typology for crash avoidance research","author":"Najm Wassim\u00a0G","year":"2007","unstructured":"Wassim\u00a0G Najm, John\u00a0D. Smith, Mikio Yanagisawa, and John A. Volpe National Transportation Systems Center (U.S.). 2007. Pre-crash scenario typology for crash avoidance research. Technical Report DOT-VNTSC-NHTSA-06-02."},{"key":"e_1_3_3_1_71_2","unstructured":"Sen Nie Ling Liu and Yuefeng Du. 2017. Free-fall: Hacking tesla from wireless to can bus. Briefing Black Hat USA 25 (2017) 1\u201316."},{"key":"e_1_3_3_1_72_2","unstructured":"Nicolas Papernot Patrick McDaniel Arunesh Sinha and Michael Wellman. 2016. Towards the science of security and privacy in machine learning. arXiv:https:\/\/arXiv.org\/abs\/1611.03814 (2016)."},{"key":"e_1_3_3_1_73_2","doi-asserted-by":"crossref","unstructured":"Ratheesh Ravindran Michael\u00a0J Santora and Mohsin\u00a0M Jamali. 2020. Multi-object detection and tracking based on DNN for autonomous vehicles: A review. IEEE Sensors Journal 21 5 (2020) 5668\u20135677.","DOI":"10.1109\/JSEN.2020.3041615"},{"key":"e_1_3_3_1_74_2","doi-asserted-by":"publisher","DOI":"10.1109\/CVPR.2016.91"},{"key":"e_1_3_3_1_75_2","volume-title":"Hacking Automotive Ethernet Cameras","author":"Rezvani Daniel","unstructured":"Daniel Rezvani. [n. d.]. Hacking Automotive Ethernet Cameras. Retrieved November 12, 2018 from https:\/\/argus-sec.com\/hacking-automotive-ethernet-cameras\/"},{"key":"e_1_3_3_1_76_2","doi-asserted-by":"publisher","DOI":"10.1109\/PRDC.2018.00016"},{"key":"e_1_3_3_1_77_2","doi-asserted-by":"publisher","DOI":"10.14722\/vehiclesec.2023.23055"},{"key":"e_1_3_3_1_78_2","doi-asserted-by":"publisher","DOI":"10.14722\/vehiclesec.2023.23036"},{"key":"e_1_3_3_1_79_2","first-page":"3309","volume-title":"30th USENIX Security Symposium","author":"Sato Takami","year":"2021","unstructured":"Takami Sato, Junjie Shen, Ningfei Wang, Yunhan Jia, Xue Lin, and Qi\u00a0Alfred Chen. 2021. Dirty Road Can Attack: Security of Deep Learning based Automated Lane Centering under Physical-World Attack. In 30th USENIX Security Symposium. 3309\u20133326."},{"key":"e_1_3_3_1_80_2","unstructured":"Harald Schafer Eder Santana Andrew Haden and Riccardo Biasini. 2018. A commute in data: The comma2k19 dataset. arXiv:https:\/\/arXiv.org\/abs\/1812.05752 (2018)."},{"key":"e_1_3_3_1_81_2","doi-asserted-by":"publisher","DOI":"10.1007\/978-3-031-68606-1_3"},{"key":"e_1_3_3_1_82_2","unstructured":"Richard Schram Aled Williams and Michiel van Ratingen. 2013. Implementation of Autonomous Emergency Braking (AEB) the next step in Euro NCAP\u2019S safety assessment. ESV Seoul (2013)."},{"key":"e_1_3_3_1_83_2","doi-asserted-by":"crossref","unstructured":"Erich Schubert J\u00f6rg Sander Martin Ester Hans\u00a0Peter Kriegel and Xiaowei Xu. 2017. DBSCAN revisited revisited: why and how you should (still) use DBSCAN. ACM Transactions on Database Systems (TODS) 42 3 (2017) 1\u201321.","DOI":"10.1145\/3068335"},{"key":"e_1_3_3_1_84_2","doi-asserted-by":"publisher","DOI":"10.1109\/ICRA.2018.8461018"},{"key":"e_1_3_3_1_85_2","first-page":"931","volume-title":"Proceedings of the 29th USENIX Conference on Security Symposium","author":"Shen Junjie","year":"2020","unstructured":"Junjie Shen, Jun\u00a0Yeon Won, Zeyuan Chen, and Qi\u00a0Alfred Chen. 2020. Drift with devil: Security of multi-sensor fusion based localization in high-level autonomous driving under GPS spoofing. In Proceedings of the 29th USENIX Conference on Security Symposium. 931\u2013948."},{"key":"e_1_3_3_1_86_2","unstructured":"Eric Shi. [n. d.]. OpenPilot: An Overview and the Port to the Honda Clarity: Hardware. https:\/\/wirelessnet2.medium.com\/openpilot-an-overview-and-the-port-to-the-honda-clarity-16341d53c9aa."},{"key":"e_1_3_3_1_87_2","first-page":"3319","volume-title":"International conference on machine learning","author":"Sundararajan Mukund","year":"2017","unstructured":"Mukund Sundararajan, Ankur Taly, and Qiqi Yan. 2017. Axiomatic attribution for deep networks. In International conference on machine learning. 3319\u20133328."},{"key":"e_1_3_3_1_88_2","unstructured":"Tencent. 2019. Experimental security research of Tesla autopilot. Tencent Keen Security Lab (2019)."},{"key":"e_1_3_3_1_89_2","doi-asserted-by":"crossref","unstructured":"Ildar Urazghildiiev Rolf Ragnarsson Pierre Ridderstrom Anders Rydberg Eric Ojefors Kjell Wallin Per Enochsson Magnus Ericson and Gran Lofqvist. 2007. Vehicle classification based on the radar measurement of height profiles. IEEE Transactions on intelligent transportation systems 8 2 (2007) 245\u2013253.","DOI":"10.1109\/TITS.2006.890071"},{"key":"e_1_3_3_1_90_2","doi-asserted-by":"crossref","unstructured":"Zhou Wang and Alan\u00a0C Bovik. 2002. A universal image quality index. IEEE signal processing letters 9 3 (2002) 81\u201384.","DOI":"10.1109\/97.995823"},{"key":"e_1_3_3_1_91_2","first-page":"949","volume-title":"29th USENIX security symposium (USENIX Security 20)","author":"Wen Haohuang","year":"2020","unstructured":"Haohuang Wen, Qi\u00a0Alfred Chen, and Zhiqiang Lin. 2020. Plug-N-Pwned: Comprehensive vulnerability analysis of OBD-II dongles as a new Over-the-Air attack surface in automotive IoT. In 29th USENIX security symposium (USENIX Security 20). 949\u2013965."},{"key":"e_1_3_3_1_92_2","doi-asserted-by":"crossref","unstructured":"Bowen Weng Minghao Zhu and Keith Redmill. 2022. A formal safety characterization of advanced driver assist systems in the car-following regime with scenario-sampling. IFAC-PapersOnLine 55 no.24 (2022) 266\u2013272.","DOI":"10.1016\/j.ifacol.2022.10.295"},{"key":"e_1_3_3_1_93_2","unstructured":"Wikipedia. [n. d.]. Norm. https:\/\/en.wikipedia.org\/wiki\/Norm_(mathematics)."},{"key":"e_1_3_3_1_94_2","doi-asserted-by":"publisher","DOI":"10.1007\/978-3-030-58548-8_1"},{"key":"e_1_3_3_1_95_2","first-page":"2237","volume-title":"30th USENIX Security Symposium","author":"Xiang Chong","year":"2021","unstructured":"Chong Xiang, Arjun\u00a0Nitin Bhagoji, Vikash Sehwag, and Prateek Mittal. 2021. PatchGuard: A provably robust defense against adversarial patches via small receptive fields and masking. In 30th USENIX Security Symposium. 2237\u20132254."},{"key":"e_1_3_3_1_96_2","doi-asserted-by":"publisher","DOI":"10.1109\/WACV56688.2023.00461"},{"key":"e_1_3_3_1_97_2","unstructured":"Weilin Xu David Evans and Yanjun Qi. 2017. Feature squeezing: Detecting adversarial examples in deep neural networks. arXiv:https:\/\/arXiv.org\/abs\/1704.01155 (2017)."},{"key":"e_1_3_3_1_98_2","first-page":"684","volume-title":"The 22nd International Conference on Artificial Intelligence and Statistics","author":"Zhang Yuchen","year":"2019","unstructured":"Yuchen Zhang and Percy Liang. 2019. Defending against whitebox adversarial attacks via randomized discretization. In The 22nd International Conference on Artificial Intelligence and Statistics. 684\u2013693."},{"key":"e_1_3_3_1_99_2","doi-asserted-by":"crossref","unstructured":"Shuai Zhou Chi Liu Dayong Ye Tianqing Zhu Wanlei Zhou and Philip\u00a0S Yu. 2022. Adversarial attacks and defenses in deep learning: From a perspective of cybersecurity. Comput. Surveys 55 8 (2022) 1\u201339.","DOI":"10.1145\/3547330"},{"key":"e_1_3_3_1_100_2","doi-asserted-by":"crossref","unstructured":"Xugui Zhou Bulbul Ahmed James\u00a0H Aylor Philip Asare and Homa Alemzadeh. 2023. Hybrid Knowledge and Data Driven Synthesis of Runtime Monitors for Cyber-Physical Systems. IEEE Transactions on Dependable and Secure Computing (2023).","DOI":"10.1109\/TDSC.2023.3242653"},{"key":"e_1_3_3_1_101_2","doi-asserted-by":"publisher","DOI":"10.1109\/DSN53405.2022.00020"}],"event":{"name":"ASIA CCS '25: 20th ACM Asia Conference on Computer and Communications Security","location":"Hanoi Vietnam","acronym":"ASIA CCS '25","sponsor":["SIGSAC ACM Special Interest Group on Security, Audit, and Control"]},"container-title":["Proceedings of the 20th ACM Asia Conference on Computer and Communications Security"],"original-title":[],"link":[{"URL":"https:\/\/dl.acm.org\/doi\/abs\/10.1145\/3708821.3710832","content-type":"text\/html","content-version":"vor","intended-application":"syndication"},{"URL":"https:\/\/dl.acm.org\/doi\/pdf\/10.1145\/3708821.3710832","content-type":"unspecified","content-version":"vor","intended-application":"similarity-checking"}],"deposited":{"date-parts":[[2025,8,13]],"date-time":"2025-08-13T07:28:36Z","timestamp":1755070116000},"score":1,"resource":{"primary":{"URL":"https:\/\/dl.acm.org\/doi\/10.1145\/3708821.3710832"}},"subtitle":[],"short-title":[],"issued":{"date-parts":[[2025,8,24]]},"references-count":100,"alternative-id":["10.1145\/3708821.3710832","10.1145\/3708821"],"URL":"https:\/\/doi.org\/10.1145\/3708821.3710832","relation":{},"subject":[],"published":{"date-parts":[[2025,8,24]]},"assertion":[{"value":"2025-08-24","order":3,"name":"published","label":"Published","group":{"name":"publication_history","label":"Publication History"}}]}}