EDBT 2026 Demo / reviewers in the wild / expert
Mohammad Hamad
dblp:168/2446
· DBLP profile ↗
29ranked-venue papers
8as first author
26since 2021 · last 2026
0000-0002-9049-7254ORCID · verified
Domains — the database's venue-derived domains; a paper can count in several
Systems, architecture and hardware · 8 · 3 first-author · 8 since 2021Software engineering, systems software and programming languages · 6 · 3 first-author · 6 since 2021Computer networks · 5 · 2 first-author · 5 since 2021Security and privacy · 5 · 2 first-author · 3 since 2021Artificial intelligence and machine learning · 3 · 1 first-author · 2 since 2021Applied, interdisciplinary, general and emerging computing · 2 · 2 since 2021
| Year | Publication | Venue | Position |
|---|---|---|---|
| 2026 | SoK: Security of the Image Processing Pipeline for Camera-based Sensing in Autonomous VehiclesabstractCameras are crucial sensors for autonomous vehicles. They capture images that are essential for many safety-critical tasks. To process these images, a complex pipeline with multiple layers is used. Security attacks on this pipeline can severely affect passenger safety and system performance. However, many attacks presented in scientific literature overlook the fact that there are different layers and, hence, the feasibility and impact of these attacks can vary. While there has been research to improve the quality and robustness of the image processing pipeline, these efforts are often orthogonal to security research without exploiting potential overlap and synergies. In this work, we aim to bridge this gap by combining security and robustness research for the image processing pipeline in autonomous vehicles. We thoroughly investigated the body of literature on the security and robustness of the image processing pipeline and selected 92 papers for deeper discussion in this SoK. For the security domain, we classify the risk of attacks using the automotive security standard ISO 21434, emphasizing the need to consider all layers for overall system security. With our online tool TARA-CAM, we propose an interactive method to perform threat analysis and risk assessment following the ISO standard. We also demonstrate how existing robustness research can help mitigate the impact of attacks, addressing the current research gap. Finally, we present PICT, an embedded open-source testbed that can influence various parameters across all layers, allowing researchers to analyze the effects of different defense strategies and attack impacts. With this SoK, we contribute a comprehensive discussion and systematic analysis of existing approaches to image processing pipeline security and robustness, together with an open-source tool and testbed that jointly facilitates hardening the image processing pipeline against existing and future security attacks. Michael Kühr, Mohammad Hamad, Pedram MohajerAnsari, Mert D. Pesé, Sebastian Steinhorst |
AsiaCCS | 2 |
| 2026 | Toward Inherently Robust VLMs Against Visual Perception AttacksabstractAutonomous vehicles rely on deep neural networks (DNNs) for traffic sign recognition, lane centering, and vehicle detection, yet these models are vulnerable to attacks that induce misclassification and threaten safety. Existing defenses (e.g., adversarial training) often fail to generalize and degrade clean accuracy. We introduce Vehicle Vision-Language Models (V2LMs), fine-tuned vision-language models specialized for autonomous vehicle perception, and show that they are inherently more robust to unseen attacks without adversarial training, maintaining substantially higher adversarial accuracy than conventional DNNs. We study two deployments: Solo (task-specific V2LMs) and Tandem (a single V2LM for all three tasks). Under attacks, DNNs drop 33-74%, whereas V2LMs decline by under 8% on average. Tandem achieves comparable robustness to Solo while being more memory-efficient. We also explore integrating V2LMs in parallel with existing perception stacks to enhance resilience. Our results suggest V2LMs are a promising path toward secure, robust AV perception. Pedram MohajerAnsari, Amir Salarpour, Michael Kühr, Siyu Huang, Mohammad Hamad, Habeeb Olufowobi, Sebastian Steinhorst, Mert D. Pesé |
IV | 5 |
| 2025 | Multi-Partner Project: CyberSecDome - Framework for Secure, Collaborative, and Privacy-Aware Incident Handling for Digital InfrastructureabstractDigital infrastructure is vital for the economy, democracy, and everyday life, yet it is becoming increasingly vulnerable to strategic cyber-attacks. These attacks can lead to significant disruptions, resulting in widespread service outages, financial losses, and a decline in public trust. Ensuring resilience is difficult due to the infrastructure's complexity, the large volume of data involved, and the growing need for quick, coordinated responses. In the EU Horizon project CyberSecDome, we propose a multi-layered framework that provides AI-driven solutions for incident prediction and detection, automated testing, risk assessment, and rapid incident response, supporting continuity amid complex, large-scale cyber threats. Additionally, Cyber-SecDome introduces a virtual reality interface to enhance AI model explainability and provide real-time contextual awareness of ongoing attacks and defense mechanisms. It also enables privacy-aware model sharing across AI systems, fostering secure collaboration among different domes. Mohammad Hamad, Michael Kühr, Haralambos Mouratidis, Eleni-Maria Kalogeraki, Christos-Antonios Gizelis, Dimitrios Papanikas, Athanasios Bountioukos-Spinaris, Charilaos Skandylas, Evangelos Raptis, Andreas Alexopoulos, Grigorios Chrysos 0001, Mina Marmpena, Sevasti Politi, Konstantinos Lieros, Nikolaos Papagiannopoulos, Iordanis Xanthopoulos, Spyridon Papastergiou, Sotiris Ioannidis, Mikael Asplund, Marc-Oliver Pahl, Sebastian Steinhorst |
DATE | 1 |
| 2025 | Cybersecurity Challenges of Autonomous SystemsabstractWith the recent dramatic increase in performance of artificial intelligence and related computing systems, together with advanced sensing, connectivity, and technological platforms, autonomous systems are poised to enter many application domains such as transportation and manufacturing. As autonomy increases, the risks of cybersecurity threats are equally rising, requiring the development of sophisticated methods on all layers of autonomous systems architectures. Therefore, this paper systematically introduces cybersecurity challenges ranging from the physical layer to the system of systems layer defining the collaboration of autonomous systems. Without loss of generality, autonomous vehicles are used to highlight current developments, illustrating which efforts are necessary to achieve secure and safe autonomous systems. Our discussions are comprehensively highlighting which research domains require further investigation and offer promising opportunities to contribute to mitigating cybersecurity challenges of autonomous systems. Mohammad Hamad, Christian Prehofer, Mikael Asplund, Tobias Löhr, Lucas Bublitz, Alexander Zeh, Mridula Singh, Sebastian Steinhorst |
DATE | 1 |
| 2025 | Designing Secure Space SystemsabstractAs space exploration advances and the commercialization and militarization of space technologies expand, ensuring the security of space assets has become a paramount concern. A key factor contributing to this challenge is the growing reliance on off-the-shelf hardware and software. While such components accelerate the adoption and commercial use of space technologies, they also introduce new vulnerabilities and broaden the attack surface. This paper highlights the critical importance of integrating cybersecurity concepts throughout the entire design lifecycle of space systems. It examines key dimensions of secure space system development, including secure engineering practices, comprehensive testing methodologies, strategies for cyber resiliency, and the role of standardization in fostering a consistent and robust security posture across the industry. By addressing these essential aspects, the paper underscores the need for a holistic, lifecycle-driven approach to safeguarding space systems against evolving cyber threats. Zain Alabedin Haj Hammadeh, Mohammad Hamad, Andrzej Olchawa, Milenko Starcik, Ricardo Fradique, Stefan Langhammer, Manuel Dossinger, Florian Göhler, Daniel Lüdtke, Michael Felderer, Sebastian Steinhorst |
DATE | 2 |
| 2025 | Cati - An Open-Source Framework to Evaluate Attacks on Cameras for Autonomous VehiclesabstractCameras and the subsequently applied perception algorithms are essential for the safe operation of autonomous vehicles. While many attacks on this processing pipeline are known, their impact is often evaluated on generic, non-automotive Machine Learning models. Although such models are still widely used in research, a realistic attack evaluation is not possible with them. A central problem for security researchers is the lack of realistic open-source Machine Learning models that represent autonomous driving functionalities. In our work, we propose CATI, an open-source framework to evaluate attacks on cameras in autonomous vehicles. Besides two trained models for automotive object detection and traffic sign detection, it is designed to be modular to include further models for other tasks. The two integrated models are specifically trained versions of the established object detection model YOLO. We show different attacks that successfully trick commonly available implementations of YOLO but not our trained models. Additionally, we highlight how the model robustness benefits in challenging real-world scenarios. Michael Kühr, Maximilian Mittmann, Mohammad Hamad, Sebastian Steinhorst |
DSD | 3 |
| 2025 | MichiCAN: Spoofing and Denial-of-Service Protection using Integrated CAN ControllersabstractThe Controller Area Network (CAN) has been the de facto in-vehicle network protocol since the 1980s, despite lacking essential security principles like authenticity, confidentiality, integrity, and availability. CAN is especially vulnerable to Denial-of-Service (DoS) attacks, threatening the availability of safety-critical functions. Existing countermeasures have seen limited adoption due to challenges in real-time detection, prevention, and high overhead on Electronic Control Units (ECUs). To address these issues, we propose MichiCAN, a distributed, backward-compatible, real-time defense against DoS and spoofing attacks. MichiCAN leverages integrated/on-chip CAN controllers in modern MCUs, enabling bit-level access to CAN messages. This allows MichiCAN to detect DoS attacks during the arbitration phase and neutralize them by bussing off the attacker ECU swiftly. Experiments on a CAN bus prototype and a real vehicle demonstrate MichiCAN’s effectiveness in enhancing automotive network security. Mert D. Pesé, Bulut Gözübüyük, Eric Andrechek, Habeeb Olufowobi, Mohammad Hamad, Kang G. Shin |
DSN | 5 |
| 2025 | Sensor Fusion Desynchronization AttacksabstractEnvironmental perception and 3D object detection are key factors for advancing autonomous driving and require robust security measures to ensure optimal performance and safety. However, established methods often focus only on protecting the involved data and overlook synchronization and timing aspects, which are equally crucial for ensuring profound system security. For instance, multi-modal sensor fusion techniques for object detection can be affected by input desynchronization resulting from random communication delays or malicious cyber attacks, as these techniques combine various sensor inputs to extract shared features present in their data streams simultaneously. Current research acknowledges the importance of temporal alignment in this context. However, the presented studies typically assume genuine system behavior and neglect the potential threat of malicious attacks, as the suggested solutions lack strategies to prevent intentional data misalignment. Additionally, they do not adequately address how sensor input desynchronization affects fusion performance in depth. This paper investigates how desynchronization attacks impact sensor fusion algorithms for 3D object detection. We evaluate how varying sensor delays affect the detection performance and link our findings to the internal architecture of the sensor fusion algorithms and the influence of specific traffic scenarios and their dynamics. We compiled four datasets covering typical traffic scenarios for our empirical evaluation and tested them on four representative fusion algorithms. Our results show that all evaluated algorithms are vulnerable to input desynchronization, as the performance declines with increasing sensor delays, highlighting the existing lack of resilience to desynchronization attacks. Furthermore, we observe that the Light Detection and Ranging (LiDAR) sensor is significantly more susceptible to delays than the camera. Finally, our experiments indicate that the chosen fusion architecture correlates with the system’s resilience against desynchronization, as our results demonstrate that the early fusion approach provides greater robustness than others. Andreas Finkenzeller, Andrew Roberts, Mauro Bellone, Olaf Maennel, Mohammad Hamad, Sebastian Steinhorst |
ECRTS | 5 |
| 2025 | ADSecLang: a Domain-Specific Language for Cybersecurity Testing of Autonomous VehiclesabstractDomain-specific languages for safety validation testing have reduced the complexity of safety scenario generation and enhanced the adoption of Autonomous Driving (AD) safety testing. Yet, there is a lack of comparable solutions for cybersecurity testing. In this work, we present ADSecLang, a domain-specific language for cybersecurity testing of AD systems. ADSecLang provides a concise syntax that enables the tester to construct scenarios for AD cybersecurity straightforwardly that can be implemented in an AD test simulation platform. The proposed language is validated within the CARLA AD simulation platform in a use-case scenario of two diverse AV camera sensor manipulation attacks on a state-of-the-art trajectory-guided AD solution. The results show that the language is able to support the translation of threats from an abstract description to the technical implementation of the attack test cases and that these test cases could identify vulnerabilities in the target AD solution. Andrew Roberts, Jingyue Cheng, Olaf Maennel, Mohammad Hamad, Sebastian Steinhorst |
VTC2025-Spring | 4 |
| 2025 | Adsecdata Platform: An Open-Source Data Platform for Autonomous Driving CybersecurityabstractAutonomous driving (AD) software needs to be secure, and its decision control must be robust against cyber threats. The development of cybersecurity solutions for legacy and connected vehicles has been supported by an array of opensource datasets, mainly focused on the CAN Bus protocol. There exists a lack of open-source cybersecurity data and communitydriven platforms that enable fair and reproducible evaluations of AD algorithms from a cybersecurity perspective and defensive mechanisms. This study addresses this problem by conducting an in-depth analysis of the data ecosystem for AD cybersecurity and introducing an initial open-source data platform, ADSecData. ADSecData offers the community a comprehensive 4 -stage method for the creation of AD cybersecurity datasets, along with an initial common dataset. We evaluate the utility of ADSecData through a case study featuring diverse malicious injection attacks, including GPS spoofing, LiDAR point-cloud manipulation, and sensor interference. The results demonstrate the viability of ADSecData in generating AD cybersecurity datasets and supporting community research and development. Andrew Roberts, Mohsen Malayjerdi, Mauro Bellone, Raivo Sell, Olaf Maennel, Mohammad Hamad, Sebastian Steinhorst |
VTC2025-Spring | 6 |
| 2025 | Enhancing Security Through Task Migration in Software-Defined VehiclesabstractThe growing trend of software-controlled operation, control, and development of modern vehicles has led to the emergence of the software-defined vehicle (SDV) design paradigm. SDVs contain increasing software components and, like other cyber-physical systems, are more susceptible to cyber-attacks. However, patching vulnerabilities in these systems may take time, exposing them to cyber threats. To limit the effect of an attack, one solution is tomigratecritical tasks co-located on the same electronic control unit (ECU) with a compromised component to another ECU. However, existing migration solutions, often designed for fault tolerance, introduce overhead and ignore security parameters. This paper introduces ShiftGuard,a security-aware, distributed task migration mechanismfor SDVs. We explore various design decisions that may affect the performance of ShiftGuard. We implemented and demonstrated the efficacy of ShiftGuard on an automotive platform running the controller area network (CAN) protocol and found that the end-to-end latency of the task migration decision is less than 17 ms for a system with 15 tasks hosted in 3 ECUs. We also performed extensive design-space exploration using a custom-developed simulator. Our experiments with synthetic workloads show that any task migration request has a 76%-100% success rate. Additionally, we demonstrate ShiftGuard’s scalability for large networks of up to 70 ECUs, making it highly suitable for automotive systems with SDV capabilities. Mohammad Hamad, Zain Alabedin Haj Hammadeh, Davide Alessi, Monowar Hasan, Mert D. Pesé, Daniel Lüdtke, Sebastian Steinhorst |
IEEE Internet Things J. | 1 |
| 2025 | Securing the Precision Time Protocol with SDN-enabled Cyclic Path Asymmetry AnalysisabstractHigh-precision time synchronization is a vital prerequisite for many modern applications and technologies, including Smart Grids, Time-sensitive Networking (TSN), and 5G networks. Although the Precision Time Protocol (PTP) can accomplish this requirement in trusted environments, it becomes unreliable in the presence of specific cyber attacks. Mainly, time delay attacks pose the highest threat to the protocol, enabling attackers to diverge targeted clocks undetected. With the increasing danger of cyber attacks, especially against critical infrastructure, there is a great demand for effective countermeasures to secure both time synchronization and the applications that depend on it. However, current solutions are not sufficiently capable of mitigating sophisticated delay attacks. For example, they lack proper integration into the PTP protocol, scalability, or sound evaluation with the required microsecond-level accuracy. This work proposes an approach to detect and counteract delay attacks against PTP, which is based on cyclic path asymmetry measurements over redundant paths. We leverage Software-defined Networking (SDN) capabilities to dynamically find these redundant paths in arbitrary networks, recommend new links to increase the network’s security, and ensure deterministic routing. Furthermore, we show how path redundancy can be utilized to reveal and mitigate undesirable asymmetries on the synchronization path that cause the malicious clock divergence. Moreover, we propose PTPsec, a secure PTP protocol, and its implementation based on the latest IEEE 1588-2019 standard. With PTPsec, we advance the conventional PTP to support reliable delay attack detection and mitigation. We validate our approach in software simulations and on a hardware testbed, which includes an attacker capable of performing static and incremental delay attacks at a microsecond precision. Our experimental results show that the proposed approach is scalable, and all attack scenarios can be reliably detected and mitigated with minimal detection time. Andreas Finkenzeller, Arne Fucks, Emanuel Regnath, Mohammad Hamad, Sebastian Steinhorst |
ACM Trans. Cyber Phys. Syst. | 4 |
| 2025 | RESCUE: A Reconfigurable Scheduling Framework for Securing Multi-Core Real-Time SystemsabstractModern real-time systems face increasing vulnerabilities to cyber-attacks, particularly those that use multi-core chips, where safety-critical and non-safety-critical tasks execute concurrently. Existing solutions for multi-core systems often lack either determinism or cost-efficiency. This article introduces an offline analysis technique that computes all feasible schedules for real-time tasks running on multi-core platforms. Our proposed technique isolates compromised tasks while ensuring a fail-operational system and supports low-cost, reconfigurable scheduling. The analytical models presented in this article guarantee the hard real-time constraints of safety-critical tasks while allowing bounded deadline misses for some non-safety-critical tasks during an attack to enhance security. We name our scheme RESCUE. We conduct a comprehensive design-space exploration and evaluate its real-world efficacy using a UAV autopilot system case study deployed on a quad-core platform (Raspberry Pi). Results show that the proposed scheme introduces minimal recovery overhead, measured in microseconds on a Raspberry Pi, and achieves 100% coverage in reconfiguration responses to compromised tasks in synthetic test cases. Zain Alabedin Haj Hammadeh, Monowar Hasan, Mohammad Hamad |
ACM Trans. Cyber Phys. Syst. | 3 |
| 2024 | ADAssure: Debugging Methodology for Autonomous Driving Control AlgorithmsabstractAutonomous driving (AD) system designers need methods to efficiently debug vulnerabilities found in control algorithms. Existing methods lack alignment to the requirements of AD control designers to provide an analysis of the parameters of the AD system and how they are affected by cyber-attacks. We introduce ADAssure, a methodology for debugging AD control system algorithms that incorporates automated mechanisms which support generation of assertions to guide the AD system designer to identify vulnerabilities in the system. Our evaluation of ADAssure on a real-world AD vehicular system using diverse cyber-attacks developed a set of assertions that identified weaknesses in the OpenPlanner 2.5 AD planning algorithm and its constituent planning functions. Working with an AD control system designer and safety validation engineer, the results of ADAssure identified remediation of the AD control system, which can support the implementation of a redundant observer for data integrity checking and improvements to the planning algorithm. The adoption of ADAssure improves autonomous system design by providing a systematic approach to enhance safety and reliability through the identification and mitigation of vulnerabilities from corner cases. Andrew Roberts, Mohammad Reza Heidari Iman, Mauro Bellone, Tara Ghasempouri, Jaan Raik, Olaf Maennel, Mohammad Hamad, Sebastian Steinhorst |
DATE | 7 |
| 2024 | PTPsec: Securing the Precision Time Protocol Against Time Delay Attacks Using Cyclic Path Asymmetry AnalysisabstractHigh-precision time synchronization is a vital prerequisite for many modern applications and technologies, including Smart Grids, Time-Sensitive Networking (TSN), and 5G networks. Although the Precision Time Protocol (PTP) can accomplish this requirement in trusted environments, it becomes unreliable in the presence of specific cyber attacks. Mainly, time delay attacks pose the highest threat to the protocol, enabling attackers to diverge targeted clocks undetected. With the increasing danger of cyber attacks, especially against critical infrastructure, there is a great demand for effective countermeasures to secure both time synchronization and the applications that depend on it. However, current solutions are not sufficiently capable of mitigating sophisticated delay attacks. For example, they lack proper integration into the PTP protocol, scalability, or sound evaluation with the required microsecond-level accuracy. This work proposes an approach to detect and counteract delay attacks against PTP based on cyclic path asymmetry measurements over redundant paths. For that, we provide a method to find redundant paths in arbitrary networks and show how this redundancy can be exploited to reveal and mitigate undesirable asymmetries on the synchronization path that cause the malicious clock divergence. Furthermore, we propose PTPsec, a secure PTP protocol and its implementation based on the latest IEEE 1588-2019 standard. With PTPsec, we advance the conventional PTP to support reliable delay attack detection and mitigation. We validate our approach on a hardware testbed, which includes an attacker capable of performing static and incremental delay attacks at a microsecond precision. Our experimental results show that all attack scenarios can be reliably detected and mitigated with minimal detection time. Andreas Finkenzeller, Oliver Butowski, Emanuel Regnath, Mohammad Hamad, Sebastian Steinhorst |
INFOCOM | 4 |
| 2024 | Securing Real-Time Systems using Schedule ReconfigurationabstractModern real-time systems are susceptible to cyber-attacks. The growing adoption of multi-core platforms, where safety and non-safety critical tasks coexist, further introduces new security challenges. Existing solutions suffer from either a lack of determinism or excessive cost. This paper addresses these shortcomings and proposes an offline analysis to compute all feasible schedules for real-time tasks running on a multi-core platform, isolating compromised tasks while guaranteeing a fail-operational system and low-cost reconfigurable scheduling. Our experimental results using a UAV autopilot system on a quad-core platform (Raspberry Pi) demonstrate that the proposed scheme incurs run-time recovery overhead at the level of microseconds. Also, the reconfiguration process covers up to 100% of all possible responses for compromised tasks in the synthetic test cases. Zain Alabedin Haj Hammadeh, Monowar Hasan, Mohammad Hamad |
ISORC | 3 |
| 2024 | Advanced IDPS Architecture for Connected and Autonomous VehiclesabstractHighly connected and automated driving technologies have ushered digital transformation and flexibility to modern cars. However, the vehicle's attack surface has significantly expanded due to increased connectivity. To address this problem, automotive manufacturers are adopting more secure practices driven by standards and regulations. In addition to the deployed cryptographically strong security measures in automotive, we need an Intrusion Detection and Prevention System (IDPS) that actively monitors the vehicle for intrusions, prevents them, and provides notification, as required by UN Regulation No. 155. In this work, we aim to identify the current limitations of the existing automotive approaches and contribute to an advanced IDPS solution. We propose architectural changes that improve reliability and form a framework to propose reactions in a safety-related automotive context. We evaluate our proposed architecture with regard to performance and security design. With the proposed changes to the IDPS architecture, our aim is to integrate a dynamic and adaptive strategy for IDPS, enhancing resilience against emerging threats and vulnerabilities. Sherin Kalli Valappil, Lars Vogel, Mohammad Hamad, Sebastian Steinhorst |
IV | 3 |
| 2024 | REACT: Autonomous intrusion response system for intelligent vehicles
Mohammad Hamad, Andreas Finkenzeller, Michael Kühr, Andrew Roberts, Olaf Maennel, Vassilis Prevelakis, Sebastian Steinhorst |
Comput. Secur. | 1 |
| 2023 | TEEVseL4: Trusted Execution Environment for Virtualized seL4-Based SystemsabstractThe growing computing power of embedded systems has led to an increase in the use of general-purpose Operating Systems (OSs) such as Linux. However, the substantial attack surface arising from their complexity makes them unsuitable for safety and security-critical use cases. Addressing this issue requires isolating the security-critical functionalities into separate execution environments and protecting them from the untrusted OS. Arm TrustZone applies this approach by providing hardware-based partitioning of the system into a secure and non-secure world, facilitating a Trusted Execution environment for the protection of security-critical functionality in the secure world. TrustZone, however, falls short when dealing with systems that virtualize multiple operating systems. Another approach to isolate functionality is employing a microkernel, such as the formally proven correct seL4 kernel, especially if it also offers virtualization functions. While current seL4-based virtualization systems offer good security and safety properties, they do not provide TrustZone-compatible security services to their virtualized guests. In this paper, we propose TEEVseL4, a TrustZone-compatible virtualization system leveraging the strengths of the seL4 microkernel, that can provide security services to the Linux guests based on the dynamic, scalable and flexible Trusted Computing Base of an seL4 system. A high-level performance benchmarking shows that TEEVseL4 can provide security services with acceptable overheads (less than 20%) when compared to a native TrustZone system, making it an attractive option for platforms with multiple, mutually-distrustful virtualized guests. Borna Blazevic, Michael Peter, Mohammad Hamad, Sebastian Steinhorst |
RTCSA | 3 |
| 2023 | Simutack - An Attack Simulation Framework for Connected and Autonomous VehiclesabstractWith the ongoing efforts toward autonomous driving, modern vehicles become increasingly digital and smart. Hence, the vehicle architecture including smart sensors, ECUs, and in-vehicle communication also faces new challenges to satisfy the ever-changing safety and security requirements. The complexity of the system naturally exposes many attack surfaces that demand for sound security solutions to protect the vehicle from potential intrusions. State-of-the-art approaches such as intrusion detection and intrusion response systems require lots of training and testing against various attack scenarios. However, implementing such attacks in real environments is difficult, expensive, and involves many legal and safety considerations. With Simutack, we present an open-source attack simulation framework that is capable of generating realistic attack scenarios for comprehensive security testing in the automotive development process. The framework integrates several classes of attacks, for instance, smart sensor attacks, V2X attacks, and attacks targeting the in-vehicle networks, which are all among the most commonly exploited attack vectors. We evaluate three common attack scenarios that showcase the applicability and capabilities of our work. In each scenario, the generated attack data is processed and returned to the simulation to visualize the attack’s effect on the vehicle and its environment. Furthermore, a custom autopilot application demonstrates the attack’s impact on autonomous driving systems. Andreas Finkenzeller, Anshu Mathur, Jan Lauinger, Mohammad Hamad, Sebastian Steinhorst |
VTC2023-Spring | 4 |
| 2023 | SEEMQTT: Secure End-to-End MQTT-Based Communication for Mobile IoT Systems Using Secret Sharing and Trust DelegationabstractThe publish/subscribe (Pub/Sub) model offers a communication scheme that is appropriate for a variety of mobile Internet of Things (IoT) systems (e.g., autonomous vehicles). In most of these systems, ensuring the end-to-end (E2E) security of exchanged information is a critical requirement. However, the Pub/Sub scheme lacks appropriate mechanisms to ensure the E2E security, even when state-of-the-art solutions, such as transport layer security (TLS) or attribute-based encryption (ABE), were adopted. These solutions either do not offer E2E security or are infeasible to be adopted in mobile IoT systems with resource-constrained platforms. In this article, we propose a framework, so-called SEEMQTT, to ensure secure E2E Pub/Sub-based communication for mobile IoT systems. Our solution allows the publisher to encrypt the published messages and control which subscribers can decrypt these messages without violating the decoupling requirement of the Pub/Sub model. Our solution leverages multiple honest-but-curious KeyStores to store secret shares generated from a secret key using a secret sharing scheme. The links between the publisher and every KeyStores are secured using identity-based encryption (IBE). The publisher uses the secret key to encrypt published messages. Trust delegation is used to authorize certain subscribers to access these shares and consequently decrypt the published messages. We provide an Arduino-based library that implements our proposed protocol. Also, we perform an extensive performance evaluation using real IoT hardware. Experimental results show that adopting our proposed solution, SEEMQTT, makes E2E security for mobile IoT systems feasible. Mohammad Hamad, Andreas Finkenzeller, Hangmao Liu, Jan Lauinger, Vassilis Prevelakis, Sebastian Steinhorst |
IEEE Internet Things J. | 1 |
| 2022 | Attack Data Generation Framework for Autonomous Vehicle SensorsabstractDriving scenarios of autonomous vehicles combine many data sources with new networking requirements in highly dynamic system setups. To keep security mechanisms applicable to new application fields in the automotive domain, our work introduces a security framework to generate, attack, and validate realistic data sets at rest and in transit. Concerning realistic data sets, our framework leverages autonomous driving simulators as well as static data sets of vehicle sensors. A configurable networking setup enables flexible data encapsulation to perform and validate networking attacks on data in transit. We validate our results with intrusion detection algorithms and simulation environments. Generated data sets and configurations are reproducible, portable, storable, and support iterative security testing of scenarios. Jan Lauinger, Andreas Finkenzeller, Henrik Lautebach, Mohammad Hamad, Sebastian Steinhorst |
DATE | 4 |
| 2022 | Feasible Time Delay Attacks Against the Precision Time ProtocolabstractTime synchronization in packet-switched networks has evolved into an indispensable prerequisite for many modern applications. In addition to high accuracy demands, also reliability and security are evermore of great concern. Despite the proposal of supplementary security concepts in the past years such as the four prongs in Annex P of the IEEE 1588 standard, available protocols are still vulnerable to time delay attacks. In this paper, we propose multiple methods to implement realistic delay attacks and verify the feasibility on a hardware testbed. Furthermore, we perform a risk analysis to evaluate the actual threat of delay attacks in practical applications. Our analysis shows that time delay attacks still pose a great threat to current systems and further research is required to find sound countermeasures. Andreas Finkenzeller, Thomas Wakim, Mohammad Hamad, Sebastian Steinhorst |
GLOBECOM | 3 |
| 2022 | FLaaS6G: Federated Learning as a Service in 6G Using Distributed Data Management ArchitectureabstractAI/ML is envisioned to play an essential role in 6G mobile communication systems. The privacy-preserving capabil-ities of Federated Learning (FL) make it promising in vertical applications; however, the central server-based system and lack of trusted data management limit its widespread use. To effectively support FL as a service from a network architecture perspective, this work provides a comprehensive design including three key features: First, the network architecture enables transparent and traceable data management based on Distributed Ledger Technology (DLT) platform, and realizes distributed and off-chain data storage by adopting Distributed Data Storage Entity (DDSE). Second, the central aggregator of an FL service is decoupled from the data management scheme mentioned above, and is decentralized through smart contracts for aggregator selection among a set of aggregator candidates, with the selected aggregator subsequently responsible for client selection and model aggregation. Third, a completed set of procedures for FL services operations is defined. A simulation system is developed to verify the feasibility of the proposed architecture and to study the impact of introducing the data management mechanisms on the overall performance overhead. The results show that the impact is related to the FL settings, with a worst-case time overhead of 15% observed in selected test cases, i.e., 15% of the total time spent on the interactions with the DLT platform and DDSE. Wenxuan Ye, Xueli An, Xueqiang Yan, Mohammad Hamad, Sebastian Steinhorst |
GLOBECOM | 4 |
| 2022 | Toward a Multi-Layer Intrusion Response System for Connected VehiclesabstractCyber attacks are increasingly targeting connected vehicles. Due to this, Intrusion Response System (IRS) is becoming necessary to respond to unpreventable attacks. This paper proposes a multi-layer IRS prototype that incorporates distributed process management to support continuous control and monitoring of incident responses. Based on our analysis of IRS taxonomies, our prototype respects the latest IRS system requirements. Jan Lauinger, Mohammad Hamad, Sebastian Steinhorst |
VTC Fall | 2 |
| 2021 | SPPS: Secure Policy-based Publish/Subscribe System for V2C CommunicationabstractThe Publish/Subscribe (Pub/Sub) pattern is an attractive paradigm for supporting Vehicle to Cloud (V2C) communication. However, the security threats on confidentiality, integrity, and access control of the published data challenge the adoption of the Pub/Sub model. To address that, our paper proposes a secure policy-based Pub/Sub model for V2C communication, which allows to encrypt and control the access to messages published by vehicles. A vehicle encrypts messages with a symmetric key while saving the key in distributed shares on semi-honest services, called KeyStores, using the concept of secret sharing. The security policy, generated by the same vehicle, authorizes certain cloud services to obtain the shares from the KeyStores. Here, granting access rights takes place without violating the decoupling requirement of the Pub/Sub model. Experimental results show that, besides the end-to-end security protection, our proposed system introduces significantly less overhead (almost 70% less) than the state-of-the-art approach SSL when reestablishing connections, which is a common scenario in the V2C context due to unreliable network connection. Mohammad Hamad, Emanuel Regnath, Jan Lauinger, Vassilis Prevelakis, Sebastian Steinhorst |
DATE | 1 |
| 2019 | Red-Zone: Towards an Intrusion Response Framework for Intra-vehicle SystemabstractModern vehicles are increasingly equipped with highly automated control systems both for driving and for\n\npassenger comfort. An integral part of these systems are the communication channels that allow the on-board\n\nsystems to interact with passenger devices (e.g. tablets), ITS systems (e.g. road-side units), and other vehicles.\n\nThese advances have significantly enlarged the attack surface and we already have numerous instances of\n\nsuccessful penetration of vehicular networks both from inside the vehicle and from the outside. Traditional\n\nmechanisms for detecting and responding to such attacks are ill-suited to the vehicular domain mainly due to\n\nthe fact that the entire process of dealing with an attack must be handled automatically and in a way that does\n\nnot affect safety or severely impacts the continued availability of the vehicle or its key systems. Once a security\n\nbreach is suspected, the system must evaluate the circumstances in order to determine whether the threat is\n\nreal (and not a false positive) and select the optimal response through the use of an Intrusion Response System\n\n(IRS). Although IRSs have been adopted in other domains, there is a lack of such systems in the vehicular\n\nfield. In this paper, we investigate the challenges and requirements for integrating such a mechanism inside a\n\nvehicle. In addition, we present an Intrusion Response System based on the Red-Zone principle which meets\n\nthe identified requirements. Finally, we discuss the integration of IRS through the vehicle system development\n\nand the different aspects which support such a process. Mohammad Hamad, Marinos Tsantekidis, Vassilis Prevelakis |
VEHITS | 1 |
| 2017 | Secure APIs for Applications in Microkernel-based Systems
Mohammad Hamad, Vassilis Prevelakis |
ICISSP | 1 |
| 2015 | A Policy-based Communications Architecture for VehiclesabstractDespite the fact that numerous studies have indicated that vehicular networks are vulnerable to external and internal attacks, very little effort has been expended in safeguarding communications both between elements within the vehicle and between the vehicle and the outside world. In this paper we present a mechanism that allows communications policy (essentially who can talk with whom and the security parameters of the channel) to be defined during the design of the software component and then adapted as the component undergoes integration first within subsystems and so on all the way to the final integration in the operational vehicle. We provide a mechanism that can maintain the integrity of the policy throughout the development effort and, finally, enforce the policy during the operation of the component in the production vehicle. Vassilis Prevelakis, Mohammad Hamad |
ICISSP | 2 |