News Release 

Cyber researchers at Ben-Gurion University fool autonomous vehicle systems with phantom images

American Associates, Ben-Gurion University of the Negev

IMAGE

IMAGE: In the Ben-Gurion University of the Negev Research Telsa considers the phantom image (left) as a real person and (right) Mobileye 630 PRO autonomous vehicle system considers the image projected... view more 

Credit: Cyber@bgu

BEER-SHEVA, ISRAEL...February 18, 2020 - Researchers from Ben-Gurion University of the Negev's (BGU) Cyber Security Research Center have found that they can cause the autopilot on an autonomous vehicle to erroneously apply its brakes in response to "phantom" images projected on a road or billboard.

In a new research paper, "Phantom of the ADAS," published on IACR.org, the researchers demonstrated that autopilots and advanced driving-assistance systems (ADASs) in semi-autonomous or fully autonomous cars register depthless projections of objects (phantoms) as real objects. They show how attackers can exploit this perceptual challenge to manipulate the vehicle and potentially harm the driver or passengers without any special expertise by using a commercial drone and inexpensive image projector.

While fully and semi-autonomous cars are already being deployed around the world, vehicular communication systems that connect the car with other cars, pedestrians and surrounding infrastructure are lagging. According to the researchers, the lack of such systems creates a "validation gap," which prevents the autonomous vehicles from validating their virtual perception with a third party, relying only on internal sensors.

In addition to causing the autopilot to apply brakes, the researchers demonstrated they can fool the ADAS into believing phantom traffic signs are real, when projected for 125 milliseconds in advertisements on digital billboards. Lastly, they showed how fake lane markers projected on a road by a projector-equipped drone will guide the autopilot into the opposite lane and potentially oncoming traffic. Click here for video

"This type of attack is currently not being taken into consideration by the automobile industry. These are not bugs or poor coding errors but fundamental flaws in object detectors that are not trained to distinguish between real and fake objects and use feature matching to detect visual objects," says Ben Nassi, lead author and a Ph.D. student of Prof. Yuval Elovici in BGU's Department of Software and Information Systems Engineering and Cyber Security Research Center.

In reality, depthless objects projected on a road are considered real even though the depth sensors can differentiate between 2D and 3D. The BGU researchers believe that this is the result of a "better safe than sorry" policy that causes the car to consider a visual 2D object real.

The researchers are developing a neural network model that analyzes a detected object's context, surface and reflected light, which is capable of detecting phantoms with high accuracy.

###

The paper is published on the website of the International Association for Cryptologic Research.

American Associates, Ben-Gurion University of the Negev

American Associates, Ben-Gurion University of the Negev (AABGU) plays a vital role in sustaining David Ben-Gurion's vision: creating a world-class institution of education and research in the Israeli desert, nurturing the Negev community and sharing the University's expertise locally and around the globe. As Ben-Gurion University of the Negev (BGU) turns 50 this year, AABGU imagines a future that goes beyond the walls of academia. It is a future where BGU invents a new world and inspires a vision for a stronger Israel and its next generation of leaders. Together with supporters, AABGU will help the University foster excellence in teaching, research and outreach to the communities of the Negev for the next 50 years and beyond. Visit vision.aabgu.org to learn more. AABGU, headquartered in Manhattan, has nine regional offices throughout the United States. For more information visit http://www.aabgu.org.

Disclaimer: AAAS and EurekAlert! are not responsible for the accuracy of news releases posted to EurekAlert! by contributing institutions or for the use of any information through the EurekAlert system.