Posted in

Self-Driving Cars & Cybersecurity: Will They Be Safe Enough?

Consumers and politicians alike have been watching advancements in autonomous vehicles with bated breath. With cutting-edge technology like blockchain advancements and AI finding its way into vehicles at a rapid pace, safety concerns are at the forefront of public discourse.

This is exacerbated by news coverage. Back in 2015, Wired correspondent Andy Greenberg got into a Jeep Cherokee, ready to go on a drive as part of an experiment to see how cybersecurity risks could put drivers in physical danger. In the few minutes that followed, the vehicle was hacked and remotely controlled by the hackers. As stated in an article on CPO Magazine, the hackers used the car’s infotainment system to gain access to its controls. The experiment went viral and resulted in a recall of 1.4 million vehicles due to the exposure of this flaw.

Hacking into a car to gain remote access isn’t a new threat. After all, this phenomenon has been the plot of countless crime and legal television shows. With the advent of self-driving cars, this technological threat is compounded even further. The CPO Magazine article states, If a vehicle can be overridden through its infotainment system, the same scenario is equally “or even more “possible for autonomous vehicles. They are reliant on more software and require constant connectivity, which in turn opens up more windows that can potentially provide remote access.   

Are self-driving cars a smart idea in regards to security and health? We’ve become increasingly reliant on technology in the best few decades ” but are we ready to put the wheel in the hands of internet-connected AI that could be compromised? Undoubtedly, this reliance on technology has many benefits, but it can also increase the risk.

Challenges and Solutions

A study found that 56% of people would not ride in a driverless car if they had the chance. The most common reasons cited were lack of trust and fear of giving up control to a machine. Safety is the primary concern for drivers on the road, and for autonomous vehicles to actually take off, passengers need to feel safe.

With statistics like these, there’s no doubt that autonomous vehicles need to up their cybersecurity measures. Current autonomous tech being tested now is showing promise, but when you’re dealing with such a crucial need for safety, the allowable margin of error is extremely thin. For the technology to be worth the risk, it needs to be foolproof.

The problem in guaranteeing safety, however, lies in timing. Self-driving car manufacturers always have to be one step ahead of cybercriminals, ensuring that their systems can adequately adapt and respond to ever-evolving cyber threats. Cybersecurity risk mitigation plans need to be implemented in the design phase of the vehicle to work. An article on Techopedia states:

Experts already warned against the current carmakers’ propensity to retrofit non-autonomous vehicles with a few additional sensor pods. This may be okay now when engineers are still stuck with prototypes and need to test out the various functionalities of these vehicles, but later this approach is doomed to be largely insufficient to guarantee any degree of safety.

Other cybersecurity measures include adversarial machine learning, where the car will know when it is being attacked and respond appropriately. However, since this sort of machine learning needs real foes to be trained, it may take a while to be implemented. Many industries have been facing cyberattacks for years now and are more equipped to take preventative measures. Cybersecurity staples include keeping systems up to date and consulting cybersecurity professionals to safeguard data.

With autonomous vehicles, however, things aren’t so black and white. Since self-driving cars have not been widely targeted by hostile hackers yet, there has been no way to run cybersecurity tests in a realistic setting. The Techopedia article quotes Craig Smith, Research Director at cyber analytics group Rapid7: Google has been a target of cyber attacks for years, whereas the auto industry hasn’t, so they have some catching up to do ¦ (C)armakers seem particularly weaker than other companies, as they’re not so used to preventing problems (especially those which are completely out of their field).

Other solutions that have been brainstormed include constant penetration to look for vulnerabilities in-car systems. This could help minimize the risk that results from multiple coding languages being utilized in self-driving technology.

Secondly, companies could collaborate to develop more resilient technology. Because they could bring together workforces with diverse skill sets, this could improve processes for cybersecurity testing. Collaboration across companies would improve security measures far more than focusing on competition.


Liability Issues

In 2017, a self-driving Uber in Tempe, Arizona, was involved in an accident. The accident caused the SUV to flip over, killing one pedestrian. While this accident was not the result of hacking, it does expose some of the concerning flaws of autonomous vehicles.

The incident also raised the valid point of liability. Whose fault was it? As stated by Dolman Law, The possibility remains in the Tempe case that the automobile manufacturer, any companies that supplied the self-driving technology, and the safety driver behind the wheel that did not take over operation before the crash occurred, could potentially be sued.

This equation becomes even more complicated when the possibility of hacking self-driving ride-shares is considered. In this case, the software in question seems to have malfunctioned on its own ” but what if a hacker was in control?

This was the opening question at a panel discussion on cyberthreats to motor vehicles at the World Congress conference in Detroit. Could hackers weaponize vehicles? If so, then what? An article on E&E News quotes Jeffrey Massimilla, head of global vehicle security for General Motors Co.: I believe a more plausible attack on a connected ecosystem in a vehicle would be something on the line of ransomware. A motorist gets in the car and is greeted by a hacker’s message on the dashboard screen: ‘You want to start your car, call a number. Pay a bitcoin and you’re in.'”

Potential situations like these shed light on the need to figure out liability and insurance issues when it comes to autonomous vehicles. Especially in cases where hacking results in human injury or even death, who is ultimately responsible? The liability issues surrounding autonomous vehicles are extremely complex.

While stakeholders continue to consider various solutions to make autonomous vehicles safer and insurance policies more clear cut, one thing is for certain: There’s still a long way to go. As technology develops, so does the ability to infiltrate it. While self-driving cars are poised to solve many of today’s transport-related problems, there is still much to be done before these cars are fit to take over the roads.

Dan Matthews is a writer and content consultant from Boise, ID with a passion for tech, innovation, and thinking differently about the world. You can find him on Twitter and LinkedIn. 

Privacy Overview

This website uses cookies so that we can provide you with the best user experience possible. Cookie information is stored in your browser and performs functions such as recognising you when you return to our website and helping our team to understand which sections of the website you find most interesting and useful.