Thomas Rosenstatter

dblp:217/0741 · DBLP profile ↗
← Back
10ranked-venue papers
5as first author
6since 2021 · last 2026
0000-0002-9587-3423ORCID · verified

Domains — the database's venue-derived domains; a paper can count in several

Software engineering, systems software and programming languages · 3 · 1 first-author · 2 since 2021Applied, interdisciplinary, general and emerging computing · 3 · 1 first-author · 1 since 2021Artificial intelligence and machine learning · 2 · 2 first-author · 1 since 2021Security and privacy · 2 · 2 first-author · 1 since 2021Computer networks · 1 · 1 since 2021
YearPublicationVenuePosition
2026 GIIDS-AR: End-to-end generalized intelligent intrusion detection system with adversarial robustness for heterogeneous UAVs in UAM
abstract
This study presents GIIDS-AR, an enhanced version of the Generalized Intelligent Intrusion Detection System (GIIDS), developed to enhance robustness and secure diverse Unmanned Aerial Vehicles (UAVs) in Urban Air Mobility (UAM) while preserving generalization. As UAVs grow vital in logistics, emergency response, and disaster relief, their reliance on wireless communication increases exposure to cyber threats. GIIDS leverages machine learning for cross-platform detection but remains vulnerable to adversarial machine learning (AML) attacks. To assess this, GIIDS was tested under black-box, white-box, and transfer attacks. Accuracy dropped to 72% under black-box and recall to 49.9% under white-box settings. Adversarial training restored original performance improving accuracy to 99.0% and F1 to 99.8%, with AUC reaching 1.00. These evaluations were conducted using cross-dataset splits of live and simulated UAV telemetry, ensuring resilience on previously unseen data. GIIDS-AR retains layered modeling, time-aware feature encoding, and ensemble learning, while incorporating adversarial examples to improve resilience. It demonstrates strong detection performance under diverse attacks and generalizes effectively across heterogeneous UAV platforms. Our findings reveal that generalization techniques inherently contribute to adversarial robustness, positioning GIIDS-AR as one of the first unified UAV IDS frameworks capable of securing UAV networks against evolving cyber threats.
Fahmina Kabir, Nishat I. Mowla, Thomas Rosenstatter, Inshil Doh
Comput. Networks3
2023 Towards Synthetic Data Generation of VANET Attacks for Efficient Testing
abstract
Vehicle-to-Vehicle communication can improve traffic safety and efficiency. This technology, however, increases the attack surface, making new attacks possible. To cope with these threats, researchers have made a great effort to identify and explore the potential of cyberattacks and also proposed various intrusion or misbehaviour detection systems, in particular machine learning-based solutions. Simulations have become essential to design and evaluate such detection systems as there are no real publicly available Vehicular Ad-Hoc Network (VANET) datasets containing a variety of attacks. The drawback is that simulations require a significant amount of computational resources and time for configuration.In this paper, we present an attack simulation and generation framework that allows training the attack generator with either simulated or real VANET attacks. We outline the structure of our proposed framework and describe the setup of a standard-compliant attack simulator that generates valid standardised CAM and DENM messages specified by ETSI in the Cooperative Intelligent Transport Systems (C-ITS) standards. Based on the introduced framework, we demonstrate the feasibility of using deep learning for the generation of VANET attacks, which ultimately allows us to test and verify prototypes without running resource-demanding simulations.
Thomas Rosenstatter, Kateryna Melnyk
IV1
2022 RIPOSTE: A Collaborative Cyber Attack Response Framework for Automotive Systems
abstract
The automotive domain has got its own share of advancements in information and communication technology, providing more services and leading to more connectivity. However, more connectivity and openness raise cyber security and safety concerns. Indeed, services that depend on online connectivity can serve as entry points for attacks on different assets of the vehicle. This study explores collaborative ways of selecting response techniques to counter real-time cyber attacks on automotive systems. The aim is to mitigate the attacks more quickly than a single vehicle would be able to do, and increase the survivability chances of the collaborating vehicles. To achieve that, the design science research methodology is employed. As a result, we present RIPOSTE, a framework for collaborative real-time evaluation and selection of suitable response techniques when an attack is in progress. We evaluate the framework from a safety perspective by conducting a qualitative study involving domain experts. The proposed framework is deemed slightly unsafe, and insights into how to improve the overall safety of the framework are provided.
Rodi Jolak, Thomas Rosenstatter, Saif Aldaghistani, Riccardo Scandariato
SEAA2
2022 CONSERVE: A framework for the selection of techniques for monitoring containers security
abstract
Container-based virtualization is gaining popularity in different domains, as it supports continuous development and improves the efficiency and reliability of run-time environments. Different techniques are proposed for monitoring the security of containers. However, there are no guidelines supporting the selection of suitable techniques for the tasks at hand. We aim to support the selection and design of techniques for monitoring container-based virtualization environments. : First, we review the literature and identify techniques for monitoring containerized environments. Second, we classify these techniques according to a set of categories, such as technical characteristic, applicability, effectiveness, and evaluation. We further detail the pros and cons that are associated with each of the identified techniques. As a result, we present CONSERVE, a multi-dimensional decision support framework for an informed and optimal selection of a suitable set of container monitoring techniques to be implemented in different application domains. A mix of eighteen researchers and practitioners evaluated the ease of use, understandability, usefulness, efficiency, applicability, and completeness of the framework. The evaluation shows a high level of interest, and points out to potential benefits.
Rodi Jolak, Thomas Rosenstatter, Mazen Mohamad, Kim Strandberg, Behrooz Sangchoolie, Nasser Nowdehi, Riccardo Scandariato
J. Syst. Softw.2
2021 V2C: A Trust-Based Vehicle to Cloud Anomaly Detection Framework for Automotive Systems
abstract
Vehicles have become connected in many ways. They communicate with the cloud and will use Vehicle-to-Everything (V2X) communication to exchange warning messages and perform cooperative actions such as platooning. Vehicles have already been attacked and will become even more attractive targets due to their increasing connectivity, the amount of data they produce and their importance to our society. It is therefore crucial to provide cyber security measures to prevent and limit the impact of attacks.
Thomas Rosenstatter, Tomas Olovsson, Magnus Almgren
ARES1
2021 Resilient Shield: Reinforcing the Resilience of Vehicles Against Security Threats
abstract
Vehicles have become complex computer systems with multiple communication interfaces. In the future, vehicles will have even more connections to e.g., infrastructure, pedestrian smartphones, cloud, road-side-units and the Internet. External and physical interfaces, as well as internal communication buses have shown to have potential to be exploited for attack purposes. As a consequence, there is an increase in regulations which demand compliance with vehicle cyber resilience requirements. However, there is currently no clear guidance on how to comply with these regulations from a technical perspective.To address this issue, we have performed a comprehensive threat and risk analysis based on published attacks against vehicles from the past 10 years, from which we further derive necessary security and resilience techniques. The work is done using the SPMT methodology where we identify vital vehicle assets, threat actors, their motivations and objectives, and develop a comprehensive threat model. Moreover, we develop a comprehensive attack model by analyzing the identified threats and attacks. These attacks are filtered and categorized based on attack type, probability, and consequence criteria. Additionally, we perform an exhaustive mapping between asset, attack, threat actor, threat category, and required mitigation mechanism for each attack, resulting in a presentation of a secure and resilient vehicle design. Ultimately, we present the Resilient Shield a novel and imperative framework to justify and ensure security and resilience within the automotive domain.
Kim Strandberg, Thomas Rosenstatter, Rodi Jolak, Nasser Nowdehi, Tomas Olovsson
VTC Spring2
2019 Extending AUTOSAR's Counter-Based Solution for Freshness of Authenticated Messages in Vehicles
abstract
Nowadays vehicles have an internal network consisting of more than 100 microcontrollers, so-called Electronic Control Units (ECUs), which control core functionalities, active safety, diagnostics, comfort and infotainment. The Controller Area Network (CAN) bus is one of the most widespread bus technologies in use, and thus is a primary target for attackers. AUTOSAR, an open system platform for vehicles, introduced in version 4.3 SecOC Profile 3, a counter-based solution to provide freshness in authenticated messages to protect the system against replay attacks. In this paper, we analyse and assess this method regarding safety constraints and usability, and discuss design considerations when implementing such a system. Furthermore, we propose a novel security profile addressing the identified deficiencies which allows faster resynchronisation when only truncated counter values are transmitted. Finally, we evaluate our solution in an experimental setup in regard to communication overhead and time to synchronise the freshness counter.
Thomas Rosenstatter, Christian Sandberg, Tomas Olovsson
PRDC1
2018 Open Problems when Mapping Automotive Security Levels to System Requirements
abstract
Securing the vehicle has become an important matter in the automotive industry. The communication of vehicles increases tremendously, they communicate with each other and to the infrastructure, they will be remotely diagnosed and provide the users with third-party applications. Given these areas of application, it is evident that a security standard for the automotive domain that considers security from the beginning of the development phase to the operational and maintenance phases is needed. Proposed security models in the automotive domain describe how to derive different security levels that indicate the demand on security, but do not further provide methods that map these levels to predefined system requirements nor security mechanisms. We continue at this point and describe open problems that need to be addressed in a prospective security framework for the automotive domain. Based on a study of several safety and security standards from other areas as well as suggested automotive security models, we propose an appropriate representation of security levels which is similar to, and will work in parallel with traditional safety, and a method to perform the mapping to a set of predefined system requirements, design rules and security mechanisms.
Thomas Rosenstatter, Tomas Olovsson
VEHITS1
2018 Team Halmstad Approach to Cooperative Driving in the Grand Cooperative Driving Challenge 2016
abstract
This paper is an experience report of team Halmstad from the participation in a competition organised by the i-GAME project, the Grand Cooperative Driving Challenge 2016. The competition was held in Helmond, The Netherlands, during the last weekend of May 2016. We give an overview of our car's control and communication system that was developed for the competition following the requirements and specifications of the i-GAME project. In particular, we describe our implementation of cooperative adaptive cruise control, our solution to the communication and logging requirements, as well as the high level decision making support. For the actual competition we did not manage to completely reach all of the goals set out by the organizers as well as ourselves. However, this did not prevent us from outperforming the competition. Moreover, the competition allowed us to collect data for further evaluation of our solutions to cooperative driving. Thus, we discuss what we believe were the strong points of our system, and discuss post-competition evaluation of the developments that were not fully integrated into our system during competition time.
Maytheewat Aramrattana, Jerome Detournay, Cristofer Englund, Viktor Frimodig, Oscar Uddman Jansson, Tony Larsson, Wojciech Mostowski, Victor Diez Rodriguez, Thomas Rosenstatter, Golam Shahanoor
IEEE Trans. Intell. Transp. Syst.9
2018 Modelling the Level of Trust in a Cooperative Automated Vehicle Control System
abstract
Vehicle-to-vehicle communication is a key technology for achieving increased perception for automated vehicles, where the communication enables virtual sensing by means of sensors in other vehicles. In addition, this technology also allows detection and recognition of objects that are out-of-sight. This paper presents a trust system that allows a cooperative and automated vehicle to make more reliable and safe decisions. The system evaluates the current situation and generates a trust index indicating the level of trust in the environment, the ego vehicle, and the surrounding vehicles. This research goes beyond secure communication and concerns the verification of the received data on a system level. The results show that the proposed method is capable of correctly identifying various traffic situations and how the trust index is used while manoeuvring in a platoon merge scenario.
Thomas Rosenstatter, Cristofer Englund
IEEE Trans. Intell. Transp. Syst.1