Phantom of the ADAS: Securing Advanced Driver-Assistance Systems from Split-Second Phantom Attacks
Ben Nassi, Yisroel Mirsky, Dudi Nassi, Raz Ben-Netanel, Oleg Drokin, Yuval Elovici
Abstract
In this paper, we investigate "split-second phantom attacks," a scientific gap that causes two commercial advanced driver-assistance systems (ADASs), Telsa Model X (HW 2.5 and HW 3) and Mobileye 630, to treat a depthless object that appears for a few milliseconds as a real obstacle/object. We discuss the challenge that split-second phantom attacks create for ADASs. We demonstrate how attackers can apply split-second phantom attacks remotely by embedding phantom road signs into an advertisement presented on a digital billboard which causes Tesla's autopilot to suddenly stop the car in the middle of a road and Mobileye 630 to issue false notifications. We also demonstrate how attackers can use a projector in order to cause Tesla's autopilot to apply the brakes in response to a phantom of a pedestrian that was projected on the road and Mobileye 630 to issue false notifications in response to a projected road sign. To counter this threat, we propose a countermeasure which can determine whether a detected object is a phantom or real using just the camera sensor. The countermeasure (GhostBusters) uses a "committee of experts" approach and combines the results obtained from four lightweight deep convolutional neural networks that assess the authenticity of an object based on the object's light, context, surface, and depth. We demonstrate our countermeasure's effectiveness (it obtains a TPR of 0.994 with an FPR of zero) and test its robustness to adversarial machine learning attacks.
Ask about this paper
Your agent reads all of it.
Lune indexed this paper to the last equation, along with the top-tier papers that cite it. Ask a question and the answer quotes them.
Your agent calls
Luneget_paper_fulltext
Free to start. No credit card required.
Terminal
Install the CLIlune papers fulltext 09fadf0b-5e01-46d6-9691-0272e7c9a786Cited by top-tier papers21
- DeHiB: Deep Hidden Backdoor Attack on Semi-supervised Learning via Adversarial PerturbationZhicong Yan, Gaolei Li, Yuan Tian, Jun Wu et al.AAAI 2021 · 43 citations
- "Get in Researchers; We're Measuring Reproducibility": A Reproducibility Study of Machine Learning Papers in Tier 1 Security ConferencesDaniel Olszewski, Allison Lu, Carson Stillman, Kevin Warren et al.CCS 2023 · 19 citations
- Revisiting Automotive Attack Surfaces: a Practitioners' PerspectivePengfei Jing, Zhiqiang Cai, Yingjie Cao, Le Yu et al.S&P 2024 · 16 citations
- Safe Neurosymbolic Learning with Differentiable Symbolic ExecutionChenxi Yang, Swarat ChaudhuriICLR 2022 · 13 citations
- Physical Hijacking Attacks against Object TrackersRaymond Muller, Yanmao Man, Z. Berkay Celik, Ming Li et al.CCS 2022 · 12 citations
Builds on2
- Adversarial Sensor Attack on LiDAR-based Perception in Autonomous DrivingYulong Cao, Chaowei Xiao, Benjamin Cyr, Yimeng Zhou et al.CCS 2019 · 626 citations
- Seeing isn't Believing: Towards More Robust Adversarial Attack Against Real World Object DetectorsYue Zhao, Hong Zhu, Ruigang Liang, Qintao Shen et al.CCS 2019 · 239 citations
Related papers
- Fooling the Eyes of Autonomous Vehicles: Robust Physical Adversarial Examples Against Traffic Sign Recognition SystemsWei Jia, Zhaojun Lu, Haichun Zhang, Zhenglin Liu et al.NDSS 2022
- Towards Real-Time Defense against Object-Based LiDAR Attacks in Autonomous DrivingYan Zhang, Zihao Liu, Yi Zhu, Chenglin MiaoCCS 2025
- Exorcising "Wraith": Protecting LiDAR-based Object Detector in Automated Driving System from Appearing AttacksQifan Xiao, Xudong Pan, Yifan Lu, Mi Zhang et al.USENIX Security 2023
- Investigating Physical Latency Attacks Against Camera-Based PerceptionRaymond Muller, Ruoyu Song, Chenyi Wang, Yuxia Zhan et al.S&P 2025
- Invisible for both Camera and LiDAR: Security of Multi-Sensor Fusion based Perception in Autonomous Driving Under Physical-World AttacksYulong Cao, Ningfei Wang, Chaowei Xiao, Dawei Yang et al.S&P 2021 · 309 citations
