VLDB 2026 Research / reviewers in the wild / expert
Mert D. Pesé
dblp:214/8289
· DBLP profile ↗
13ranked-venue papers
5as first author
11since 2021 · last 2026
0000-0001-9192-5823ORCID · verified
Domains — the database's venue-derived domains; a paper can count in several
Security and privacy · 6 · 4 first-author · 4 since 2021Artificial intelligence and machine learning · 5 · 5 since 2021Systems, architecture and hardware · 2 · 1 first-author · 2 since 2021Computer networks · 2 · 1 first-author · 2 since 2021Graphics, computer vision, multimedia, augmented reality and games · 1 · 1 since 2021
| Year | Publication | Venue | Position |
|---|---|---|---|
| 2026 | SoK: Security of the Image Processing Pipeline for Camera-based Sensing in Autonomous VehiclesabstractCameras are crucial sensors for autonomous vehicles. They capture images that are essential for many safety-critical tasks. To process these images, a complex pipeline with multiple layers is used. Security attacks on this pipeline can severely affect passenger safety and system performance. However, many attacks presented in scientific literature overlook the fact that there are different layers and, hence, the feasibility and impact of these attacks can vary. While there has been research to improve the quality and robustness of the image processing pipeline, these efforts are often orthogonal to security research without exploiting potential overlap and synergies. In this work, we aim to bridge this gap by combining security and robustness research for the image processing pipeline in autonomous vehicles. We thoroughly investigated the body of literature on the security and robustness of the image processing pipeline and selected 92 papers for deeper discussion in this SoK. For the security domain, we classify the risk of attacks using the automotive security standard ISO 21434, emphasizing the need to consider all layers for overall system security. With our online tool TARA-CAM, we propose an interactive method to perform threat analysis and risk assessment following the ISO standard. We also demonstrate how existing robustness research can help mitigate the impact of attacks, addressing the current research gap. Finally, we present PICT, an embedded open-source testbed that can influence various parameters across all layers, allowing researchers to analyze the effects of different defense strategies and attack impacts. With this SoK, we contribute a comprehensive discussion and systematic analysis of existing approaches to image processing pipeline security and robustness, together with an open-source tool and testbed that jointly facilitates hardening the image processing pipeline against existing and future security attacks. Michael Kühr, Mohammad Hamad, Pedram MohajerAnsari, Mert D. Pesé, Sebastian Steinhorst |
AsiaCCS | 4 |
| 2026 | From MIRAGE to CLEAR: Component-Level Explainable Anomaly Reasoning for Autonomous Vehicle Perception Systems
David Fernandez, Pedram MohajerAnsari, Amir Salarpour, Cigdem Kokenoz, Mert D. Pesé |
DSN | 6 |
| 2026 | Comparative Analysis of Patch Attack on VLM-Based Autonomous Driving Architectures
David Fernandez, Pedram MohajerAnsari, Amir Salarpour, Long Cheng 0005, Abolfazl Razi, Mert D. Pesé |
IV | 6 |
| 2026 | Toward Inherently Robust VLMs Against Visual Perception AttacksabstractAutonomous vehicles rely on deep neural networks (DNNs) for traffic sign recognition, lane centering, and vehicle detection, yet these models are vulnerable to attacks that induce misclassification and threaten safety. Existing defenses (e.g., adversarial training) often fail to generalize and degrade clean accuracy. We introduce Vehicle Vision-Language Models (V2LMs), fine-tuned vision-language models specialized for autonomous vehicle perception, and show that they are inherently more robust to unseen attacks without adversarial training, maintaining substantially higher adversarial accuracy than conventional DNNs. We study two deployments: Solo (task-specific V2LMs) and Tandem (a single V2LM for all three tasks). Under attacks, DNNs drop 33-74%, whereas V2LMs decline by under 8% on average. Tandem achieves comparable robustness to Solo while being more memory-efficient. We also explore integrating V2LMs in parallel with existing perception stacks to enhance resilience. Our results suggest V2LMs are a promising path toward secure, robust AV perception. Pedram MohajerAnsari, Amir Salarpour, Michael Kühr, Siyu Huang, Mohammad Hamad, Habeeb Olufowobi, Sebastian Steinhorst, Mert D. Pesé |
IV | 9 |
| 2026 | NPNet: A Non-Parametric Network with Adaptive Gaussian-Fourier Positional Encoding for 3D Classification and Segmentation
Mohammad Saeid, Amir Salarpour, Pedram MohajerAnsari, Mert D. Pesé |
IV | 4 |
| 2025 | MichiCAN: Spoofing and Denial-of-Service Protection using Integrated CAN ControllersabstractThe Controller Area Network (CAN) has been the de facto in-vehicle network protocol since the 1980s, despite lacking essential security principles like authenticity, confidentiality, integrity, and availability. CAN is especially vulnerable to Denial-of-Service (DoS) attacks, threatening the availability of safety-critical functions. Existing countermeasures have seen limited adoption due to challenges in real-time detection, prevention, and high overhead on Electronic Control Units (ECUs). To address these issues, we propose MichiCAN, a distributed, backward-compatible, real-time defense against DoS and spoofing attacks. MichiCAN leverages integrated/on-chip CAN controllers in modern MCUs, enabling bit-level access to CAN messages. This allows MichiCAN to detect DoS attacks during the arbitration phase and neutralize them by bussing off the attacker ECU swiftly. Experiments on a CAN bus prototype and a real vehicle demonstrate MichiCAN’s effectiveness in enhancing automotive network security. Mert D. Pesé, Bulut Gözübüyük, Eric Andrechek, Habeeb Olufowobi, Mohammad Hamad, Kang G. Shin |
DSN | 1 |
| 2025 | FedVLM: Scalable Personalized Vision-Language Models Through Federated LearningabstractVision-language models (VLMs) demonstrate impressive zero-shot and few-shot learning capabilities, making them essential for several downstream tasks. However, fine-tuning these models at scale remains challenging, particularly in federated environments where data is decentralized and non-iid across clients. Existing parameter-efficient tuning methods like LoRA (Low-Rank Adaptation) reduce computational overhead but struggle with heterogeneous client data, leading to suboptimal generalization. To address these challenges, we propose FedVLM, a federated LoRA fine-tuning framework that enables decentralized adaptation of VLMs while preserving model privacy and reducing reliance on centralized training. To further tackle data heterogeneity, we introduce personalized LoRA (pLoRA) which dynamically adapts LoRA parameters to each client’s unique data distribution, significantly improving local adaptation while maintaining global model aggregation. Experiments on the RLAIF-V dataset show that pLoRA improves client-specific performance by 24.5% over standard LoRA, demonstrating superior adaptation in non-iid settings. FedVLM provides a scalable and efficient solution for fine-tuning VLMs in federated settings, advancing personalized adaptation in distributed learning scenarios. Arkajyoti Mitra, Afia Anjum, Paul Agbaje, Mert D. Pesé, Habeeb Olufowobi |
ECAI | 4 |
| 2025 | Enhancing Security Through Task Migration in Software-Defined VehiclesabstractThe growing trend of software-controlled operation, control, and development of modern vehicles has led to the emergence of the software-defined vehicle (SDV) design paradigm. SDVs contain increasing software components and, like other cyber-physical systems, are more susceptible to cyber-attacks. However, patching vulnerabilities in these systems may take time, exposing them to cyber threats. To limit the effect of an attack, one solution is tomigratecritical tasks co-located on the same electronic control unit (ECU) with a compromised component to another ECU. However, existing migration solutions, often designed for fault tolerance, introduce overhead and ignore security parameters. This paper introduces ShiftGuard,a security-aware, distributed task migration mechanismfor SDVs. We explore various design decisions that may affect the performance of ShiftGuard. We implemented and demonstrated the efficacy of ShiftGuard on an automotive platform running the controller area network (CAN) protocol and found that the end-to-end latency of the task migration decision is less than 17 ms for a system with 15 tasks hosted in 3 ECUs. We also performed extensive design-space exploration using a custom-developed simulator. Our experiments with synthetic workloads show that any task migration request has a 76%-100% success rate. Additionally, we demonstrate ShiftGuard’s scalability for large networks of up to 70 ECUs, making it highly suitable for automotive systems with SDV capabilities. Mohammad Hamad, Zain Alabedin Haj Hammadeh, Davide Alessi, Monowar Hasan, Mert D. Pesé, Daniel Lüdtke, Sebastian Steinhorst |
IEEE Internet Things J. | 5 |
| 2024 | An Initial Exploration of Employing Large Multimodal Models in Defending Against Autonomous Vehicles AttacksabstractAs the advent of autonomous vehicle (AV) technology revolutionizes transportation, it simultaneously introduces new vulnerabilities to cyber-attacks, posing significant challenges to vehicle safety and security. The complexity of these systems, coupled with their increasing reliance on advanced computer vision and machine learning algorithms, makes them susceptible to sophisticated AV attacks. This paper explores the potential of Large Multimodal Models (LMMs) in identifying Natural Denoising Diffusion (NDD) attacks on traffic signs. Our comparative analysis show the superior performance of LMMs in detecting NDD samples with an average accuracy of 82.52% across the selected models compared to 37.75% for state-of-the-art deep learning models. We further discuss the integration of LMMs within the resource-constrained computational environments to mimic typical autonomous vehicles and assess their practicality through latency benchmarks. Results show substantial superiority of GPT models in achieving lower latency, down to 4.5 seconds per image for both computation time and network latency (RTT), suggesting a viable path towards real-world deployability. Lastly, we extend our analysis to LMMs’ applicability against a wider spectrum of AV attacks, particularly focusing on the Automated Lane Centering systems, emphasizing the potential of LMMs to enhance vehicular cybersecurity. Mohammed Aldeen, Pedram MohajerAnsari, Mashrur Chowdhury, Long Cheng 0005, Mert D. Pesé |
IV | 6 |
| 2022 | DETROIT: Data Collection, Translation and Sharing for Rapid Vehicular App DevelopmentabstractDETROIT is an open-source vehicle-agnostic end-to-end framework for vehicular data collection, translation and sharing that facilitates the rapid development of automotive apps. With vehicles becoming increasingly connected, unlocking sheer amounts of data from the in-vehicle network (IVN) can accelerate the development of many useful apps. Unlike existing commercial and academic solutions that can only access a restricted set of standardized emission-related sensor data and lack feasible data accessibility by third-party developers, DETROIT offers a convenient interface to develop apps which can access a broad range of powertrain-related sensors and car-body events thanks to crowd-sourcing vehicular translation tables by fully automated CAN bus reverse-engineering. DETROIT is developed with the objectives of simplicity, scalability, privacy and liability. To the best of our knowledge, this is the first end-to-end framework consisting of a frontend, backend and a developer portal to cover vehicular data collection, translation and sharing with app developers. Besides an extensive framework benchmark to show the light resource overhead and feasibility of DETROIT, we also have evaluated it by reimplementing two existing mobility apps from academia. Developers have reported that DETROIT offers high sensor fidelity, enhanced application flexibility, as well as low implementation complexity. Mert D. Pesé, Dongyao Chen, C. Andrés Campos, Alice Ying, Troy Stacer, Kang G. Shin |
SECON | 1 |
| 2021 | S2-CAN: Sufficiently Secure Controller Area NetworkabstractAs automotive security concerns are rising, the Controller Area Network (CAN) — the de facto standard of in-vehicle communication protocol — has come under scrutiny due to its lack of encryption and authentication. Several vulnerabilities, such as eavesdropping, spoofing, and replay attacks, have shown that the current implementation needs to be extended. Both academic and commercial solutions for a Secure CAN (S-CAN) have been proposed, but OEMs have not yet integrated them into their products. The main reasons for this lack of adoption are their heavy use of limited computational resources in the vehicle, increased latency that can lead to missed deadlines for safety-critical messages, as well as insufficient space available in a CAN frame to include a Message Authentication Code (MAC). Mert D. Pesé, Jay W. Schauer, Kang G. Shin |
ACSAC | 1 |
| 2020 | SPy: Car Steering Reveals Your Trip Route!abstractAbstract Vehicular data-collection platforms as part of Original Equipment Manufacturers’ (OEMs’) connected telematics services are on the rise in order to provide diverse connected services to the users. They also allow the collected data to be shared with third-parties upon users’ permission. Under the current suggested permission model, we find these platforms leaking users’ location information without explicitly obtaining users’ permission. We analyze the accuracy of inferring a vehicle’s location from seemingly benign steering wheel angle (SWA) traces, and show its impact on the driver’s location privacy. By collecting and processing real-life SWA traces, we can infer the users’ exact traveled routes with up to 71% accuracy, which is much higher than the state-of-the-art. Mert D. Pesé, Xiaoying Pu, Kang G. Shin |
Proc. Priv. Enhancing Technol. | 1 |
| 2019 | LibreCAN: Automated CAN Message TranslatorabstractModern Connected and Autonomous Vehicles (CAVs) are equipped with an increasing number of Electronic Control Units (ECUs), many of which produce large amounts of data. Data is exchanged between ECUs via an in-vehicle network, with the Controller Area Network (CAN) bus being the de facto standard in contemporary vehicles. Furthermore, CAVs have not only physical interfaces but also increased data connectivity to the Internet via their Telematic Control Units (TCUs), enabling remote access via mobile devices. It is also possible to tap into, and read/write data from/to the CAN bus, as data transmitted on the CAN bus is not encrypted. This naturally generates concerns about automotive cybersecurity. One commonality among most vehicular security attacks reported to date is that they ultimately require write access to the CAN bus. In order to cause targeted and intentional changes in vehicle behavior, malicious CAN injection attacks require knowledge of the CAN message format. However, since this format is proprietary to OEMs and can differ even among different models of a single make of vehicle, one must manually reverse-engineer the CAN message format of each vehicle they target --- a time-consuming and tedious process that does not scale. To mitigate this difficulty, we develop LibreCAN, which can translate most CAN messages with minimal effort. Our extensive evaluation on multiple vehicles demonstrates LibreCAN's efficiency in terms of accuracy, coverage, required manual effort and scalability to any vehicle. Mert D. Pesé, Troy Stacer, C. Andrés Campos, Eric Newberry, Dongyao Chen, Kang G. Shin |
CCS | 1 |