[{"data":1,"prerenderedAt":-1},["ShallowReactive",2],{"doc-detail-118023-en":3,"doc-seo-118023-105":30,"detail-sidebar-cat-0-en-105":91},{"code":4,"msg":5,"data":6},0,"success",{"doc_id":7,"user_id":8,"nickname":9,"user_avatar":10,"doc_module":4,"category_id":11,"category_name":12,"doc_title":13,"doc_description":14,"doc_content":15,"file_id":16,"file_url":17,"file_type":18,"file_size":19,"view_count":4,"is_deleted":4,"is_public":20,"is_downloadable":20,"audit_status":20,"page_count":21,"language":22,"language_code":23,"site_id":24,"html_lang":23,"table_of_contents":25,"faqs":26,"seo_title":27,"seo_description":14,"update_tm":28,"read_time":29},118023,4398048949847,"Eliana","https://ap-avatar.wpscdn.com/avatar/400002536579ef2da7f?_k=1778318612642679267",8,"Research & Report","Machine Learning Security of Connected Autonomous Vehicles - A Systems Perspective","Machine learning security is critical to safe operation of autonomous vehicles, especially when connectivity enables multiple vehicles to cooperate as a system of systems with shared objectives. Adversarial environments and malicious vehicles can trigger security challenges that extend beyond an individual platform, potentially causing cascading system-level failures. The work examines machine learning security from the perspective of many connected autonomous vehicles operating together, introduces attack scenarios to assess resilience, and discusses key research challenges such as defining indicators and metrics. Simulation-based experimentation is proposed to capture complex, dynamic interactions under attack.","Ellis, W. , Belguith, S. , & Tryfonas, T. (2024) . Machine Learning Security of Connected Autonomous Vehicles: A Systems Perspective. In 2024 IEEE International Conference on Industrial Technology (ICIT)(IEEE International Conference on Industrial Technology (ICIT)) . Institute of Electrical and Electronics Engineers (IEEE) . [https://doi.org/10.1109/ICIT58233.2024.10540922](https://doi.org/10.1109/ICIT58233.2024.10540922)  \nPeer reviewed version  \nLicense (if available): CC BY  \nLink to published version (if available):  \n10.1109/ICIT58233.2024.10540922  \nLink to publication record on the Bristol Research Portal  \nPDF-document  \nThis is the accepted author manuscript (AAM) of the article which has been made Open Access under the University of Bristol's Scholarly Works Policy. The final published version (Version of Record) can be found on the publisher's website. The copyright of any third-party content, such as images, remains with the copyright holder.  \nUniversity of Bristol – Bristol Research Portal  \nGeneral rights  \nThis document is made available in accordance with publisher policies. Please cite only the published version using the reference above. Full terms of use are available: [http://www.bristol.ac.uk/red/research-policy/pure/user-guides/brp-terms/](http://www.bristol.ac.uk/red/research-policy/pure/user-guides/brp-terms/)  \nMachine Learning Security of Connected Autonomous Vehicles: A Systems Perspective  \nWinston Ellis, Sana Belguith, Theo Tryfonas  \nUniversity of Bristol, Bristol, UK  \n{winston.ellis, sana.belguith, [theo.tryfonas](theo.tryfonas}@bristol.ac.uk)[}](theo.tryfonas}@bristol.ac.uk)[@bristol.ac.uk](theo.tryfonas}@bristol.ac.uk)  \nAbstract—Machine Learning security is vital for the safe operation of Autonomous Vehicles. When Autonomous Vehicles are connected and cooperating, they form a system of systems that have shared objectives. However, adversarial environments and adversarial vehicles in the system can cause security challenges for the whole system. Current research focuses on the Machine Learning security challenges from the perspective of a single vehicle. We argue that there is a need to consider these security challenges from the perspective of multiple interconnected vehicles, as a system. In this paper, we explore these challenges from the perspective of many Connected Autonomous Vehicles as a system with respect to Machine Learning security. We include attack scenarios that demonstrate the system interactions that can lead to cascading failures, which test the resilience of the system. We also outline some of the challenges in researching this perspective, where a key challenge is identifying indicators and metrics to describe the system resilience when under attack. To observe the system, experimentation via simulation is identified as a suitable environment that can capture the complex and dynamic system interactions in this security context.  \nIndex Terms—Machine Learning Security, Connected Autonomous Vehicles, Resilience  \nI. INTRODUCTION  \nModern vehicles are made up of various software systems controlling different aspects of the vehicle, which makes them prone to security attacks. This creates a need to implement strong security mechanisms to maintain operation in the face of adversarial conditions and attacks. One source of security issues for vehicles is human input, i.e. the driver, which makes incidents mainly occur from human decisions. This is no longer the case with the advancement of Autonomous Vehicles (AV) and their eventual adoption as the main mode of transport which mainly aim to improve safety of passengers and efficiency of transport systems [1],[2] . While this removes the human driver’s contribution to security problems, the added layers of autonomy software in the vehicle introduces different vulnerabilities including security issues related the use of Machine Learning (ML) [3] . A further advancement to AV are the Connected Autonomous Vehicles (CAV), which are d","cbCailIdSv5SQAtw","https://ap.wps.com/l/cbCailIdSv5SQAtw","pdf",272676,1,9,"English","en",105,"# Introduction\n## Machine learning risks in autonomous vehicles\n## Connected autonomous vehicles and interdependence\n## Adversarial environments and resilience needs","[{\"question\":\"Why is machine learning security vital for autonomous vehicles?\",\"answer\":\"Machine learning components influence vehicle perception, routing, and decision-making. Under adversarial conditions, ML model performance can degrade, threatening safe and efficient operation.\"},{\"question\":\"What changes when autonomous vehicles become connected and cooperative?\",\"answer\":\"Connected autonomous vehicles exchange data through communications with other vehicles, road-side units, and cloud services. This interdependence expands the security scope, since attacks can propagate across the system.\"},{\"question\":\"How does the paper propose evaluating system resilience under attack?\",\"answer\":\"It includes attack scenarios to demonstrate system interactions leading to cascading failures. It also highlights the need for indicators and metrics describing resilience, and identifies simulation-based experimentation as a suitable approach to capture complex dynamics.\"}]","Machine Learning Security of Connected Autonomous Vehicles - A Systems Perspective | PDF",1785680789,23,{"code":4,"msg":31,"data":32},"ok",{"site_id":24,"language":23,"slug":33,"title":13,"keywords":34,"description":14,"schema_data":35,"social_meta":86,"head_meta":88,"extra_data":90,"updated_unix":28},"machine-learning-security-of-connected-autonomous-vehicles-a-systems-perspective","",{"@graph":36,"@context":85},[37,54,68],{"@type":38,"itemListElement":39},"BreadcrumbList",[40,44,48,51],{"item":41,"name":42,"@type":43,"position":20},"https://docshare.wps.com","Home","ListItem",{"item":45,"name":46,"@type":43,"position":47},"https://docshare.wps.com/document/","Document",2,{"item":49,"name":12,"@type":43,"position":50},"https://docshare.wps.com/document/research-report/",3,{"item":52,"name":13,"@type":43,"position":53},"https://docshare.wps.com/document/machine-learning-security-of-connected-autonomous-vehicles-a-systems-perspective/118023/",4,{"url":52,"name":13,"@type":55,"author":56,"headline":13,"publisher":58,"fileFormat":61,"inLanguage":23,"description":14,"dateModified":62,"datePublished":62,"encodingFormat":61,"isAccessibleForFree":63,"interactionStatistic":64},"DigitalDocument",{"name":9,"@type":57},"Person",{"url":41,"name":59,"@type":60},"DocShare","Organization","application/pdf","2026-08-02",true,{"@type":65,"interactionType":66,"userInteractionCount":4},"InteractionCounter",{"@type":67},"ViewAction",{"@type":69,"mainEntity":70},"FAQPage",[71,77,81],{"name":72,"@type":73,"acceptedAnswer":74},"Why is machine learning security vital for autonomous vehicles?","Question",{"text":75,"@type":76},"Machine learning components influence vehicle perception, routing, and decision-making. Under adversarial conditions, ML model performance can degrade, threatening safe and efficient operation.","Answer",{"name":78,"@type":73,"acceptedAnswer":79},"What changes when autonomous vehicles become connected and cooperative?",{"text":80,"@type":76},"Connected autonomous vehicles exchange data through communications with other vehicles, road-side units, and cloud services. This interdependence expands the security scope, since attacks can propagate across the system.",{"name":82,"@type":73,"acceptedAnswer":83},"How does the paper propose evaluating system resilience under attack?",{"text":84,"@type":76},"It includes attack scenarios to demonstrate system interactions leading to cascading failures. It also highlights the need for indicators and metrics describing resilience, and identifies simulation-based experimentation as a suitable approach to capture complex dynamics.","https://schema.org",{"og:url":52,"og:type":87,"og:title":13,"og:site_name":59,"og:description":14},"article",{"robots":89,"canonical":52},"index,follow",{"doc_id":7,"site_id":24},{"code":4,"msg":5,"data":92},[93,97,101,105,110,115,120,123,127,130,134],{"id":20,"doc_module":4,"doc_module_name":46,"category_name":94,"show_sort_weight":95,"slug":96},"Story & Novel",90,"story-novel",{"id":47,"doc_module":4,"doc_module_name":46,"category_name":98,"show_sort_weight":99,"slug":100},"Literature",80,"literature",{"id":53,"doc_module":4,"doc_module_name":46,"category_name":102,"show_sort_weight":103,"slug":104},"Exam",70,"exam",{"id":106,"doc_module":4,"doc_module_name":46,"category_name":107,"show_sort_weight":108,"slug":109},5,"Comic",60,"comic",{"id":111,"doc_module":4,"doc_module_name":46,"category_name":112,"show_sort_weight":113,"slug":114},6,"Technology",50,"technology",{"id":116,"doc_module":4,"doc_module_name":46,"category_name":117,"show_sort_weight":118,"slug":119},7,"Healthcare",40,"healthcare",{"id":11,"doc_module":4,"doc_module_name":46,"category_name":12,"show_sort_weight":121,"slug":122},30,"research-report",{"id":21,"doc_module":4,"doc_module_name":46,"category_name":124,"show_sort_weight":125,"slug":126},"Religion & Spirituality",20,"religion-spirituality",{"id":125,"doc_module":4,"doc_module_name":46,"category_name":128,"show_sort_weight":125,"slug":129},"World Cup","world-cup",{"id":131,"doc_module":4,"doc_module_name":46,"category_name":132,"show_sort_weight":131,"slug":133},10,"Lifestyle","lifestyle",{"id":135,"doc_module":4,"doc_module_name":46,"category_name":136,"show_sort_weight":106,"slug":137},19,"General","general"]