Adopting Security and Privacy Risk-Based Engineering in Designing and Handling AI/ML Based Applications for Road Vehicles
Sreenikethana Venkatachalapathy · 2023
In the recent decade, advancements and innovations in the automotive industries have mostly been driven by machine learning (ML) and artificial intelligence (AI). Vehicle software features are designed and engineered out of the data collected from various sources, such as sensors, actuators, cameras, roadside infrastructure, radar, lidar, and sometimes the supplier's or original equipment manufacturer's specific servers. But data poisoning, privacy violations, unintended behaviors, vulnerabilities, compromising cybersecurity goals, and model theft are also growing exponentially in AI and ML systems. As the automotive industry is a regulation- and quality-driven industry, can AI/ML-based features be assessed with reference to security and privacy risks? In this paper, the author would like to propose a novel approach to managing AI and ML applications by providing the preconditions, checklist, and RASIC resulting from attacking AI and ML models, technology gap analysis with a case study of ADAS algorithms, and risk assessment. Most importantly, thinking like an attacker means fooling one's own model into acting adversely.