Today’s vehicles can steer, brake and change lanes on their own. But in critical moments, they still rely on a human driver to take control.
What happens if a cyberattack doesn’t target the vehicle’s software but instead exploits the driver’s behaviour?
That question sits at the heart of a newly funded research project in Western’s Faculty of Engineering, where three researchers are working to close a critical gap in the cybersecurity of semi-autonomous vehicles.
With support from the National Cybersecurity Consortium (NCC), project lead Atrisha Sarkar, professor in the department of electrical and computer engineering, Mohamed Zaki, professor in the department of civil and environmental engineering and Apurva Narayan, professor in the department of electrical and computer engineering, are examining how adversarial actors could exploit human behavioural patterns in vehicles equipped with Level-2 Advanced Driver Assistance Systems (ADAS).
Their work represents a shift in how automotive cybersecurity is understood, moving beyond code and hardware to include the human driver as part of the security system.
A new kind of vulnerability
Many vehicles currently on Canadian roads feature Level-2 automation, meaning they can assist with steering, braking and lane changes. However, they still depend on the driver to remain attentive and ready to take over when prompted. “This dependency creates a novel class of vulnerabilities,” said Sarkar. “Modern cybersecurity frameworks focus on software and hardware. But they don’t adequately address risks rooted in driver behaviour, attention and trust in automation.” For example, if an attacker understands how drivers typically respond to alerts or how long it takes them to re-engage, that information could be exploited to maximize disruption or risk during a takeover request. Instead of treating the human as an external variable, Sarkar’s project integrates human behaviour directly into cybersecurity modelling. Her team is developing models and simulations that treat driver behaviour as part of the cybersecurity system. The goal is to design new safety protocols and defensive strategies that anticipate these risks before they manifest on public roads.
(L to R) PhD students Mayar Nour and Nour ElGharably test different driving scenarios using a simulator for semi-autonomous vehicles. (Jacob Arts/Western Engineering)
