Explanations Help: Leveraging Human Capabilities to Detect Cyberattacks on Automated Vehicles

Explainable AI (XAI)Privacy by Design & User ControlAutonomous Driving Engineers & Test Drivers

Research Background and Issues

  • Issues and Challenges

    • Autonomous vehicles (AVs) significantly enhance driving performance through advanced sensors and machine learning technologies but are more vulnerable to cyberattacks due to their complex network components and system architectures.
    • Current defense strategies primarily focus on improving system and algorithm resilience, neglecting the potential of human monitoring in detecting cyberattacks.
    • Although previous studies indicate that humans can detect abnormal vehicle behaviors caused by cyberattacks, there has been no systematic investigation into human detection capabilities for different types of cyberattacks or how augmented displays can support these capabilities.
  • Significance

    • Commercial vehicles at SAE Level 3 or below still require human drivers to monitor driving conditions, underscoring the indispensable role of humans in cybersecurity.
    • Effectively leveraging human detection capabilities can not only identify attacks that systems fail to recognize but also enable proactive intervention to regain control of compromised vehicles, contributing to overall safety.
  • Research Motivation

    • This study focuses on three types of cyberattacks detectable by humans: attacks on traffic infrastructure, perception modules, and execution modules.
    • It also explores how two types of information displays (alerts only and alerts with explanations) enhance drivers' detection capabilities, particularly under conditions where the displays are not fully reliable (e.g., false alarms or missed alarms).

Solution

  • Proposed Solution

    • Developed two types of augmented displays: alert-only displays (Alert) and alert displays with explanations (AlertExp).
    • Evaluated human detectability of three types of cyberattacks and the efficiency of detection using different display types.
  • Innovations

    • For the first time, proposed a "proactive defense" strategy leveraging human capabilities to detect cyberattacks, surpassing traditional algorithmic or system enhancement methods.
    • Pioneered the validation that even inaccurate information, when combined with explanations, can improve detection capabilities and mitigate negative impacts.
    • Designed display conditions, including misalignment, to simulate real-world scenarios where information does not fully match actual conditions.
  • Implementation Steps and Key Techniques

    • Introduced three variables:
      1. Types of cyberattacks: attacks on traffic infrastructure, perception modules, and execution modules.
      2. Display types: no display (Baseline), alert-only displays (Alert), and alert displays with explanations (AlertExp).
      3. Alignment between alerts and attack states: alerts may align (aligned) or misalign (misaligned) with the actual attack state.
    • Designed 18 driving scenarios (9 attack scenarios and 9 non-attack scenarios) in a virtual driving environment using Unreal Engine 4 to create realistic simulation videos.
    • Conducted an online survey experiment with 260 participants randomly assigned to groups, who watched the videos and answered related questions to evaluate their detection performance, trust, and situational awareness.

Research Findings

  • Key Findings

    • Impact of Cyberattack Types:
      • Execution module attacks were the most difficult to detect and understand, but the AlertExp display significantly alleviated these challenges.
      • Perception module attacks were the easiest to detect, with display types contributing little to detection performance.
      • Detection rates for traffic infrastructure attacks were relatively low, but post-attack trust in AV systems was highest, suggesting that people tend to attribute responsibility to external factors.
    • Impact of Display Types:
      • AlertExp displays significantly improved situational awareness and detection rates for cyberattacks, while maintaining appropriate trust levels in the presence of false alarms and missed alarms.
      • Alert displays, due to the lack of explanations, caused unnecessary panic and trust degradation in non-attack scenarios, performing worse than no display (Baseline).
    • Impact of Misalignment:
      • False alarms had a significant negative impact on detection performance and trust in non-attack scenarios, while missed alarms had a smaller impact on attack scenarios.
      • Providing explanations (AlertExp) effectively mitigated the adverse effects of false alarms.
  • Experiments and Evaluation

    • Quantitative analysis revealed that situational awareness, detection capabilities, and trust were significantly influenced by the type of cyberattack and display method.
    • The advantages of alert displays with explanations (AlertExp) were evident, suggesting their prioritization in real-world deployment.
  • Limitations and Future Directions

    • The experiments were based on online simulations, lacking validation in real driving scenarios; future studies could incorporate simulation or real-world road tests.
    • The study only explored single false alarm or missed alarm conditions and did not delve into more complex dynamic trust impacts (e.g., the "cry wolf" effect).
    • Self-reported measures of cybersecurity knowledge may lack accuracy; future research could develop more precise assessment tools.

Conclusion

This study systematically investigated human capabilities in detecting cyberattacks on autonomous vehicles and the relationship between these capabilities and display types. It found that providing alert displays with explanations maximizes human potential, improves detection performance, and effectively addresses unreliable operational environments. This research offers a new paradigm for human-AV collaboration in combating cyberattacks.

Quick Actions

Share

Share this page

ios_share

https://hci.top/en/papers/chi/189420/2025

AdRecommended

Learn AI Coding at CodeNow

open_in_newOpen DOI Link
DOI: https://dl.acm.org/doi/10.1145/3706598.3714301
At a Glance

Paper Snapshot

fact_check
dataset
Source
CHI
calendar_month
Year
2025
emoji_events
Award
No award tagged
group
Authors
4 authors
sell
Subtopics
Explainable AI (XAI), Privacy by Design & User Control
work
Professions
Autonomous Driving Engineers & Test Drivers
article
Content Status
Full text indexed
hub
Related Papers
0 related papers