{"status":"ok","message-type":"work","message-version":"1.0.0","message":{"indexed":{"date-parts":[[2025,11,2]],"date-time":"2025-11-02T12:33:14Z","timestamp":1762086794691,"version":"build-2065373602"},"reference-count":26,"publisher":"Frontiers Media SA","license":[{"start":{"date-parts":[[2023,4,11]],"date-time":"2023-04-11T00:00:00Z","timestamp":1681171200000},"content-version":"vor","delay-in-days":0,"URL":"https:\/\/creativecommons.org\/licenses\/by\/4.0\/"}],"funder":[{"DOI":"10.13039\/501100003816","name":"Huawei Technologies","doi-asserted-by":"publisher","id":[{"id":"10.13039\/501100003816","id-type":"DOI","asserted-by":"publisher"}]}],"content-domain":{"domain":["frontiersin.org"],"crossmark-restriction":true},"short-container-title":["Front. Comput. Sci."],"abstract":"<jats:p>Autonomous driver assistance systems (ADAS) have been progressively pushed to extremes. Today, increasingly sophisticated algorithms, such as deep neural networks, assume responsibility for critical driving functionality, including operating the vehicle at various levels of autonomy. Elaborate obstacle detection, classification, and prediction algorithms, mostly vision-based, trajectory planning, and smooth control algorithms, take over what humans learn until they are permitted to control vehicles and beyond. And even if humans remain in the loop (e.g., to intervene in case of error, as required by autonomy levels 3 and 4), it remains questionable whether distracted human drivers will react appropriately, given the high speed at which vehicles drive and the complex traffic situations they have to cope with. A further pitfall is trusting the whole autonomous driving stack not to fail due to accidental causes and to be robust against cyberattacks of increasing sophistication. In this experience report, we share our findings in retrofitting application-agnostic resilience mechanisms into an existing hardware-\/software-stack for autonomous driving\u2014Apollo\u2014as well as where application knowledge helps improve existing resilience algorithms. Our goal is to ultimately decrease the vulnerability of autonomously driving vehicles to accidental faults and attacks, allowing them to absorb and tolerate both, as well as to come out of them at least as secure as before the attack has happened. We demonstrate replication and rejuvenation on the driving stack's Control module and indicate how this resilience can be extended both downwards to the hardware level, as well as upwards to the prediction and planning modules.<\/jats:p>","DOI":"10.3389\/fcomp.2023.1125055","type":"journal-article","created":{"date-parts":[[2023,4,11]],"date-time":"2023-04-11T05:36:36Z","timestamp":1681191396000},"update-policy":"https:\/\/doi.org\/10.3389\/crossmark-policy","source":"Crossref","is-referenced-by-count":3,"title":["Toward resilient autonomous driving\u2014An experience report on integrating resilience mechanisms into the Apollo autonomous driving software stack"],"prefix":"10.3389","volume":"5","author":[{"given":"Federico","family":"Lucchetti","sequence":"first","affiliation":[],"role":[{"role":"author","vocabulary":"crossref"}]},{"given":"Rafal","family":"Graczyk","sequence":"additional","affiliation":[],"role":[{"role":"author","vocabulary":"crossref"}]},{"given":"Marcus","family":"V\u00f6lp","sequence":"additional","affiliation":[],"role":[{"role":"author","vocabulary":"crossref"}]}],"member":"1965","published-online":{"date-parts":[[2023,4,11]]},"reference":[{"key":"B1","doi-asserted-by":"crossref","DOI":"10.1109\/ETFA.2016.7733561","article-title":"\u201cReset-based recovery for real-time cyber-physical systems with temporal safety constraints,\u201d","volume-title":"2016 IEEE 21st International Conference on Emerging Technologies and Factory Automation (ETFA)","author":"Abad","year":"2016"},{"key":"B2","doi-asserted-by":"crossref","DOI":"10.1109\/ICCPS.2018.00010","article-title":"\u201cGuaranteed physical security with restart-based design for cyber-physical systems,\u201d","volume-title":"2018 ACM\/IEEE 9th International Conference on Cyber-Physical Systems (ICCPS)","author":"Abdi","year":"2018"},{"key":"B3","doi-asserted-by":"crossref","DOI":"10.1109\/EuroSP51992.2021.00021","article-title":"\u201cBullseye polytope: A scalable clean-label poisoning attack with improved transferability,\u201d","volume-title":"2021 IEEE European Symposium on Security and Privacy (EuroS and P)","author":"Aghakhani","year":"2021"},{"key":"B4","doi-asserted-by":"publisher","first-page":"539","DOI":"10.1016\/S0893-6080(96)00089-5","article-title":"On fault tolerant training of feedforward neural networks","volume":"10","author":"Arad","year":"1997","journal-title":"Neur. Netw"},{"journal-title":"Apollo: Open source autonomous driving","year":"2017","key":"B5"},{"journal-title":"Toyota \u201cunintended acceleration\u201d has killed","year":"2010","key":"B6"},{"key":"B7","doi-asserted-by":"crossref","DOI":"10.1109\/IJCNN.1990.137773","article-title":"\u201cFault tolerant neural networks with hybrid redundancy,\u201d","volume-title":"1990 IJCNN International Joint Conference on Neural Networks","author":"Chu","year":"1990"},{"key":"B8","doi-asserted-by":"crossref","DOI":"10.1109\/IVS.2008.4621259","article-title":"\u201cClassification and tracking of dynamic objects with multiple sensors for autonomous driving in urban environments,\u201d","volume-title":"2008 IEEE Intelligent Vehicles Symposium","author":"Darms","year":"2008"},{"key":"B9","doi-asserted-by":"crossref","DOI":"10.1109\/AITEST52744.2021.00030","article-title":"\u201cEfficient and effective generation of test cases for pedestrian detection-search-based software testing of baidu apollo in svl,\u201d","volume-title":"2021 IEEE International Conference on Artificial Intelligence Testing (AITest)","author":"Ebadi","year":"2021"},{"key":"B10","article-title":"Adversarial reprogramming of neural networks.","author":"Elsayed","year":"2018","journal-title":"arXiv preprint arXiv:1806.11146."},{"key":"B11","doi-asserted-by":"publisher","DOI":"10.1109\/CVPR.2018.00175","article-title":"\u201cRobust physical-world attacks on deep learning visual classification,\u201d","author":"Eykholt","year":"2018","journal-title":"Proceedings of the IEEE Conference on Computer Vision and Pattern Recognition"},{"key":"B12","doi-asserted-by":"publisher","DOI":"10.3390\/app10186249","article-title":"Robust path tracking control for autonomous vehicle based on a novel fault tolerant adaptive model predictive control algorithm","author":"Geng","year":"2020","journal-title":"Appl. Sci"},{"key":"B13","doi-asserted-by":"publisher","DOI":"10.1016\/j.cose.2022.102920","article-title":"Behind the last line of defense: Surviving soc faults and intrusions","author":"Gouveia","year":"2022","journal-title":"Comput. Secur"},{"key":"B14","article-title":"\u201cPas 21448-road vehicles-safety of the intended functionality,\u201d","author":"Iso","year":"2019","journal-title":"International Organization for Standardization"},{"key":"B15","doi-asserted-by":"crossref","first-page":"1513","DOI":"10.1109\/ICNN.1994.374512","article-title":"\u201cRecovering faulty self-organizing neural networks: By weight shifting technique,\u201d","volume-title":"Proceedings of 1994 IEEE International Conference on Neural Networks (ICNN'94)","author":"Khunasaraphan","year":"1994"},{"key":"B16","doi-asserted-by":"crossref","DOI":"10.1109\/ICCPS.2018.00011","article-title":"\u201cCyber-physical system checkpointing and recovery,\u201d","volume-title":"2018 ACM\/IEEE 9th International Conference on Cyber-Physical Systems (ICCPS)","author":"Kong","year":"2018"},{"key":"B17","doi-asserted-by":"publisher","DOI":"10.1145\/2994487.2994489","article-title":"\u201cTowards safe and secure autonomous and cooperative vehicle ecosystems,\u201d","author":"Lima","year":"2016","journal-title":"Proceedings of the 2nd ACM Workshop on Cyber-Physical Systems Security and Privacy"},{"key":"B18","doi-asserted-by":"publisher","first-page":"1","DOI":"10.1007\/s42979-020-00423-5","article-title":"On sensor security in the era of iot and cps","volume":"2","author":"Panoff","year":"2021","journal-title":"SN Comput. Sci"},{"key":"B19","doi-asserted-by":"publisher","DOI":"10.1145\/3368089.3417063","article-title":"\u201cA first look at the integration of machine learning models in complex autonomous driving systems,\u201d","author":"Peng","year":"2020","journal-title":"Proceedings of the 28th ACM Joint Meeting on European Software Engineering Conference and Symposium on the Foundations of Software Engineering"},{"key":"B20","doi-asserted-by":"publisher","DOI":"10.1109\/ITSC45102.2020.9294422","author":"Rong","year":"2020","journal-title":"SVL simulator: a high fidelity simulator for autonomous driving. arXiv e-prints,"},{"key":"B21","doi-asserted-by":"publisher","DOI":"10.14722\/autosec.2021.23026","article-title":"\u201cDirty road can attack: Security of deep learning based automated lane centering under $Physical\u2212World$ attack,\u201d","author":"Sato","year":"2021","journal-title":"30th USENIX Security Symposium (USENIX Security 21)"},{"key":"B22","doi-asserted-by":"crossref","first-page":"111","DOI":"10.1109\/AITEST52744.2021.00031","article-title":"\u201cAn empirical testing of autonomous vehicle simulator system for urban driving,\u201d","volume-title":"2021 IEEE International Conference on Artificial Intelligence Testing (AITest)","author":"Seymour","year":"2021"},{"key":"B23","doi-asserted-by":"publisher","DOI":"10.3390\/app9010082","article-title":"Cyber-physical attack detection and recovery based on rnn in automotive brake systems","author":"Shin","year":"2018","journal-title":"Appl. Sci"},{"key":"B24","doi-asserted-by":"publisher","first-page":"452","DOI":"10.1109\/TPDS.2009.83","article-title":"Highly available intrusion-tolerant services with proactive-reactive recovery","volume":"21","author":"Sousa","year":"2009","journal-title":"IEEE Trans. Parallel Distrib. Syst"},{"key":"B25","doi-asserted-by":"publisher","first-page":"17322","DOI":"10.1109\/ACCESS.2017.2742698","article-title":"Fault and error tolerance in neural networks: A review","volume":"5","author":"Torres-Huitzil","year":"2017","journal-title":"IEEE Access"},{"journal-title":"Doublestar: Long-range attack towards depth estimation based obstacle avoidance in autonomous systems.","year":"2021","author":"Zhou","key":"B26"}],"container-title":["Frontiers in Computer Science"],"original-title":[],"link":[{"URL":"https:\/\/www.frontiersin.org\/articles\/10.3389\/fcomp.2023.1125055\/full","content-type":"unspecified","content-version":"vor","intended-application":"similarity-checking"}],"deposited":{"date-parts":[[2023,4,11]],"date-time":"2023-04-11T05:36:45Z","timestamp":1681191405000},"score":1,"resource":{"primary":{"URL":"https:\/\/www.frontiersin.org\/articles\/10.3389\/fcomp.2023.1125055\/full"}},"subtitle":[],"short-title":[],"issued":{"date-parts":[[2023,4,11]]},"references-count":26,"alternative-id":["10.3389\/fcomp.2023.1125055"],"URL":"https:\/\/doi.org\/10.3389\/fcomp.2023.1125055","relation":{},"ISSN":["2624-9898"],"issn-type":[{"type":"electronic","value":"2624-9898"}],"subject":[],"published":{"date-parts":[[2023,4,11]]},"article-number":"1125055"}}