With autonomous vehicles, security is a looming concern

Sharon Fisher//August 28, 2018

With autonomous vehicles, security is a looming concern

Sharon Fisher//August 28, 2018

image of self driving car
A conceptual image of the General Motors Cruise AV, schedule to be available in 2019, with no driver, steering wheel, pedals or manual controls. Image courtesy of GM.

After the most recent hearing of the state’s autonomous vehicles committee, which focused on security, attendees were frightened.

photo of brian ness
Brian Ness

“The consensus is, this is pretty scary stuff,” summarized Brian Ness, director of the Idaho Transportation Department (ITD), after hearing from each of the attendees. “I don’t even want to use Bluetooth in my car anymore.”

Part of the issue is the complexity of autonomous vehicles. “With higher complexity comes more vulnerabilities,” said Ken Rohde, a cybersecurity researcher at Idaho National Laboratory, noting that even a 2016 Ford F150 pickup has more lines of code than a Boeing 787 airplane.

Ness, insurance company representatives, and state officials gathered August 21 for the second of three meetings of the Autonomous and Connected Vehicle Testing and Deployment Committee. The first meeting, held May 30, covered issues such as liability and cost, while the third, scheduled for October 16, is intended to wrap up loose ends before the committee generates its report for Gov. C. L. “Butch” Otter. The committee was formed by the governor on January 2 by executive order. Autonomous vehicles are now forbidden in Idaho, even for testing. A bill to change this, S.1108, made it through the Senate in 2015, but died in the House transportation committee.

At the security-focused second meeting, the committee learned that the industry will also need to learn how to protect itself from incidents such as people carrying software-defined radios, which they could use to pretend to be ambulances to part autonomous vehicle traffic in front of them, Rohde said. Even the electrical grid itself is vulnerable, because autonomous vehicles are all-electric, he said. Sabotaging the grid could leave a region immobile, he warned.

Eight other states are also looking at autonomous vehicles via executive order, while 25 states – including all three states on Idaho’s southern border – have already implemented legislation allowing autonomous vehicles in some form.

According to the 2018 Cox Automotive Evolution of Mobility Study: Autonomous Vehicles, 84 percent of the population wants to have the option to drive themselves even in a self-driving vehicle, compared to 16 percent who would feel comfortable letting an autonomous vehicle drive them without the option of being able to take control. “The number of respondents that believe roadways would be safer if all vehicles were fully autonomous versus operated by people has decreased 18 percentage points in just two years,” the report noted.

“Malicious actors are going to be a problem, and they will attack anything that’s exposed,” said Simson Garfinkel, a Washington, D.C., computer security expert. He expects, though, that physical attacks will be more of an issue than cyberspace ones.

A similar opinion was expressed in Securing Self-Driving Cars by Charlie Miller and Chris Valasek, known for hacking a Jeep Cherokee in 2015. Now employees of Cruise, General Motors’ self-driving car division, the two wrote that vehicles are more likely to be at risk from a physical attack. In fact, autonomous vehicles offered by a service, such as Uber or Lyft, would be more likely to be safe than individually owned vehicles, because they would be more likely to be kept secure and updated regularly, they wrote.

photo of jeff weak
Jeff Weak

Another security issue is that of the streets themselves. ITD speakers showed examples of situations that flummoxed autonomous vehicles in tests, such as graffiti-covered stop signs and large white trucks, which led the autonomous vehicle to conclude it was seeing a horizon. (Autonomous vehicles in Australia have been confused by bounding kangaroos.) Attendees expressed concern that bullet holes might also render signs invisible.

But such situations might be less of an issue because the system will “learn” what a street looks like and “know” that a stop sign is there, even if it doesn’t recognize it, Miller and Valasek wrote. That functionality is required because autonomous vehicles aren’t capable of processing all data about a street in real time — only the parts that are changing or different, they wrote.

Jeff Weak, Idaho’s director of information security, said he was torn between thinking of all the benefits autonomous vehicles could provide, such as mobility for people who couldn’t drive themselves, and the security issues. But somehow the state, as well as the nation as a whole, is going to have to figure it out, he said.