EDBT 2026 Demo / reviewers in the wild / expert
Jonathan Petit
dblp:33/7861
· DBLP profile ↗
19ranked-venue papers
3as first author
11since 2021 · last 2026
0000-0002-8644-1442ORCID · corroborated
Domains — the database's venue-derived domains; a paper can count in several
Security and privacy · 7 · 5 since 2021Applied, interdisciplinary, general and emerging computing · 5 · 2 first-author · 3 since 2021Artificial intelligence and machine learning · 3 · 2 since 2021Systems, architecture and hardware · 1 · 1 since 2021Graphics, computer vision, multimedia, augmented reality and games · 1 · 1 since 2021
| Year | Publication | Venue | Position |
|---|---|---|---|
| 2026 | CP-FREEZER: Latency Attacks Against Vehicular Cooperative PerceptionabstractCooperative perception (CP) enhances situational awareness of connected and autonomous vehicles by exchanging and combining messages from multiple agents. While prior work has explored adversarial integrity attacks that degrade detection accuracy, little is known about CP's robustness against attacks on timeliness (or availability), a safety-critical requirement for autonomous driving. In this paper, we present CP-FREEZER, the first latency attack that maximizes the computation delay of CP algorithms by injecting adversarial perturbation via V2V messages. Our attack resolves several unique challenges, including the non-differentiability of point cloud preprocessing, asynchronous knowledge of the victim’s input due to transmission delays, and uses a novel loss function that effectively maximizes the execution time of the CP pipeline. Extensive experiments show that CP-FREEZER increases end-to-end CP latency by over 90×, pushing per-frame processing time beyond 3 seconds with a 100% success rate on our real-world vehicle testbed. Our findings reveal a critical threat to the availability of CP systems, highlighting the urgent need for robust defenses. Chenyi Wang 0005, Ruoyu Song 0001, Raymond Muller, Jean-Philippe Monteuuis, Z. Berkay Celik, Jonathan Petit, Ryan M. Gerdes, Ming Li 0003 |
AAAI | 6 |
| 2025 | Latency NMS Attacks: Is It Real Life or Is It Just Fantasy?abstract``Caught in a landslide, no escape from reality" summarizes the state of the research in AI offense: an attack might work on paper but does not necessarily in practice. In the last 5 years, we have seen the rise of latency attacks against computer vision systems. Most of them targeted 2D object detection, especially its Non-Max-Suppression (NMS) block, via adversarial images. However, we uncovered that, when tested in realistic deployment settings, the NMS latency attacks, accepted to top conferences, have very limited negative effects. In this paper, we define an evaluation framework (EVADE) to assess the practicality of attacks, and apply it to state-of-the-art NMS latency attacks. Attacks were tested on different hardware platforms, and different model formats and quantization. Results show that these attacks are not able to generate the claimed latency increase, nor transfer to other models (from the same family or not).
Moreover, the latency increases remain within the latency requirements of downstream tasks in our evaluation, suggesting limited practical impact under these conditions. We also tested three defenses, which were successful in mitigating the NMS latency attacks. Therefore, in their current form, NMS latency attacks are just fantasy. Jean-Philippe Monteuuis, Jonathan Petit |
NeurIPS | 3 |
| 2025 | Investigating Physical Latency Attacks Against Camera-Based PerceptionabstractCamera-based perception is a central component to the visual perception of autonomous systems. Recent works have investigated latency attacks against perception pipelines, which can lead to a Denial-of-Service against the autonomous system. Unfortunately, these attacks lack real-world applicability, either relying on digital perturbations or requiring large, unscalable, and highly visible patches that cover up the victim's view. In this paper, we propose Detstorm, a novel physically realizable latency attack against camera-based perception. Detstorm uses projector perturbations to cause delays in perception by creating a large number of adversarial objects. These objects are optimized on four objectives to evade filtering by multiple Non-Maximum Suppression (NMS) approaches. To maximize the number of created objects in a dynamic physical environment, Detstorm takes a unique greedy approach, segmenting the environment into “zones” containing distinct object classes and maximizing the number of created objects per zone. Detstorm adapts to changes in the environment in real time, recombining perturbation patterns via our zone stitching process into a contiguous, physically projectable image. Evaluations in both simulated and real-world experiments show that Detstorm causes a 506% increase in detected objects on average, delaying perception results by up to 8.1 seconds, and capable of causing physical consequences on real-world autonomous driving systems. Raymond Muller, Ruoyu Song 0001, Chenyi Wang 0005, Yuxia Zhan, Jean-Philippe Monteuuis, Yanmao Man, Ming Li 0003, Ryan M. Gerdes, Jonathan Petit, Z. Berkay Celik |
SP | 9 |
| 2025 | From Threat to Trust: Exploiting Attention Mechanisms for Attacks and Defenses in Cooperative Perception
Chenyi Wang 0005, Raymond Muller, Ruoyu Song 0001, Jean-Philippe Monteuuis, Jonathan Petit, Yanmao Man, Ryan M. Gerdes, Z. Berkay Celik, Ming Li 0003 |
USENIX Security Symposium | 5 |
| 2025 | VehiGAN: Generative Adversarial Networks for Adversarially Robust V2X Misbehavior Detection SystemsabstractVehicle-to-Everything (V2X) communication enables vehicles to communicate with other vehicles and roadside infrastructure, enhancing traffic management and improving road safety. However, the open and decentralized nature of V2X networks exposes them to various security threats, especially misbehaviors, necessitating a robust Misbehavior Detection System (MBDS). While Machine Learning (ML) has proved effective in different anomaly detection applications, the existing ML-based MBDSs have shown limitations in generalizing due to the dynamic nature of V2X and insufficient and imbalanced training data. Moreover, they are known to be vulnerable to adversarial ML attacks. On the other hand, Generative Adversarial Networks (GAN) possess the potential to mitigate the aforementioned issues and improve detection performance by synthesizing unseen samples of minority classes and utilizing them during their model training. Therefore, we propose the first application of GAN to design an MBDS that detects any misbehavior and ensures robustness against adversarial perturbation. In this article, we present several key contributions. First, we propose an advanced threat model for stealthy V2X misbehavior where the attacker can transmit malicious data and mask it using adversarial attacks to avoid detection by ML-based MBDS. We formulate two categories of adversarial attacks against the anomaly-based MBDS. Later, in the pursuit of a generalized and robust GAN-based MBDS, we train and evaluate a diverse set of Wasserstein GAN (WGAN) models and present Ve hicular GAN ( VehiGAN ), an ensemble of multiple top-performing WGANs, which transcends the limitations of individual models and improves detection performance. We present a physics-guided data preprocessing technique that generates effective features for ML-based MBDS. In the evaluation, we leverage the state-of-the-art V2X attack simulation tool VASP to create a comprehensive dataset of V2X messages with diverse misbehaviors. Evaluation results show that in 20 out of 35 misbehaviors, VehiGAN outperforms the baseline and exhibits comparable detection performance in other scenarios. Particularly, VehiGAN excels in detecting advanced misbehaviors that manipulate multiple fields in V2X messages simultaneously, replicating unique maneuvers. Moreover, VehiGAN provides approximately 92% improvement in false positive rate under powerful adaptive adversarial attacks, and possesses intrinsic robustness against other adversarial attacks that target the false negative rate. Finally, we make the data and code available for reproducibility and future benchmarking, available at https://github.com/shahriar0651/VehiGAN . Md Hasan Shahriar, Mohammad Raashid Ansari, Jean-Philippe Monteuuis, Md Shahedul Haque, Jonathan Petit, Y. Thomas Hou 0001, Wenjing Lou |
ACM Trans. Cyber Phys. Syst. | 6 |
| 2024 | Physical ID-Transfer Attacks against Multi-Object Tracking via Adversarial TrajectoryabstractMulti-Object Tracking (MOT) is a critical task in computer vision, with applications ranging from surveillance systems to autonomous driving. However, threats to MOT algorithms have yet been widely studied. In particular, incorrect association between the tracked objects and their assigned IDs can lead to severe consequences, such as wrong trajectory predictions. Previous attacks against MOT either focused on hijacking the trackers of individual objects, or manipulating the tracker IDs in MOT by attacking the integrated object detection (OD) module in the digital domain, which are model-specific, non-robust, and only able to affect specific samples in offline datasets. In this paper, we present AdvTraj, the first online and physical ID-manipulation attack against tracking-by-detection MOT, in which an attacker uses adversarial trajectories to transfer its ID to a targeted object to confuse the tracking system, without attacking OD. Our simulation results in CARLA show that AdvTraj can fool ID assignments with 100% success rate in various scenarios for white-box attacks against SORT, which also have high attack transferability (up to 93% attack success rate) against state-of-the-art (SOTA) MOT algorithms due to their common design principles. We characterize the patterns of trajectories generated by AdvTraj and propose two universal adversarial maneuvers that can be performed by a human walker/driver in daily scenarios. Our work reveals under-explored weaknesses in the object association phase of SOTA MOT systems, and provides insights into enhancing the robustness of such systems. Chenyi Wang 0005, Yanmao Man, Raymond Muller, Ming Li 0003, Z. Berkay Celik, Ryan M. Gerdes, Jonathan Petit |
ACSAC | 7 |
| 2024 | Vehigan:Generative Adversarial Networks for Adversarially Robust V2X Misbehavior Detection SystemsabstractVehicle-to-Everything (V2X) communication enables vehicles to communicate with other vehicles and roadside infrastructure, enhancing traffic management and improving road safety. However, the open and decentralized nature of V2X networks exposes them to various security threats, necessitating a robust misbehavior detection system (MBDS). While machine learning (ML) has proved effective in different anomaly detection applications, the existing ML-based MBDSs have shown limitations in generalizing due to the dynamic nature of V2X and insufficient and imbalanced training data. Moreover, they are known to be vulnerable to adversarial ML attacks. On the other hand, generative adversarial networks (GAN) possess the potential to mitigate such issues and improve detection performance by synthesizing unseen samples of minority classes and utilizing them during their model training. Therefore, we propose the first application of GAN to design an MBDS. Our contributions are manifold. In the pursuit of an effective GAN-based MBDS, we train and evaluate a diverse set of Wasserstein GAN (WGAN) models and present VEhicular GAN (VEHIGAN), an ensemble of multiple top-performing WGANs, which transcends the limitations of individual models and improves detection performance and adversarial robustness. We present a physics-guided data preprocessing technique that generates effective features for ML-based misbehavior detection. To evaluate the adversarial robustness, we formulate two categories of adversarial attacks against the WGAN-based MBDS. In the evaluation, we leverage the state-of-the-art V2X attack simulation tool VASP to create a comprehensive dataset of V2X messages with diverse misbehaviors. Evaluation results show that in 20 out of 35 misbehaviors, VehigAnoutperforms the baselines and exhibits comparable detection performance in other scenarios. Particularly, VehigAnexcels in detecting advanced misbehaviors that manipulate multiple fields in V2X messages simultaneously, replicating unique maneuvers. Moreover, VehigAnprovides approximately 92% improvement in false positive rates under powerful adaptive adversarial attacks and possesses intrinsic robustness against other adversarial attacks that target false negative rates. Finally, we make the data and code available for reproducibility and future benchmarking, available at https://eithub.com/shahriar0651/VehiGAN. Md Hasan Shahriar, Mohammad Raashid Ansari, Jean-Philippe Monteuuis, Jonathan Petit, Y. Thomas Hou 0001, Wenjing Lou |
ICDCS | 5 |
| 2024 | PatchCURE: Improving Certifiable Robustness, Model Utility, and Computation Efficiency of Adversarial Patch Defenses
Chong Xiang 0001, Sihui Dai, Jonathan Petit, Suman Jana, Prateek Mittal |
USENIX Security Symposium | 4 |
| 2024 | VOGUES: Validation of Object Guise using Estimated Components
Raymond Muller, Yanmao Man, Ming Li 0003, Ryan M. Gerdes, Jonathan Petit, Z. Berkay Celik |
USENIX Security Symposium | 5 |
| 2024 | Next Generation Vehicles, Safety, and Cybersecurity - The CMX FrameworkabstractSafety, privacy, efficiency and cybersecurity (SPEC) properties are mandatory in vehicular networks. Owing to intrinsic limitations, the V2X framework and related communicating autonomous vehicles are inadequate. We explore the CMX framework (Coordinated Mobility for X = SPEC), Next Generation Vehicles (NGVs), and protocols for safety-critical inter-vehicle communications and agreements that solve problems left open in the V2X framework. Then, we focus on cyberattacks and physical attacks against isolated NGVs and cohorts of NGVs. The cyberphysical security analysis investigates more than 20 attacks and demonstrates that the goal set for CMX is verified. In the presence of attacks, safety is never compromised, possibly at the expense of diminished efficiency. Jonathan Petit, Gérard Le Lann |
IEEE Trans. Intell. Transp. Syst. | 1 |
| 2021 | Spatial and Temporal Cross-Validation Approach for Misbehavior Detection in C-ITS
Mohammed Lamine Bouchouia, Jean-Philippe Monteuuis, Ons Jelassi, Houda Labiod, Wafa Ben Jaballah, Jonathan Petit |
RCIS | 6 |
| 2019 | Physical layer plausibility checks for misbehavior detection in V2X networksabstractLocation spoofing is a proven and powerful attack against Vehicle-to-everything (V2X) communication systems that can cause traffic congestion and other safety hazards. Recent work also demonstrates practical spoofing attacks that can circumvent application layer sanity checks. In this paper, we propose three novel physical layer plausibility checks that leverage the received signal strength indicator (RSSI) of basic safety messages (BSMs). These plausibility checks have multi-step mechanisms to improve not only the detection rate, but also to decrease false positives. These checks can be run independently by each vehicle and do not rely on the assumption that the majority of vehicles is honest. We comprehensively evaluate the performance of these plausibility checks using the VeReMi dataset (which we enhance along the way) for several types of attacks. We show that the best performing physical layer plausibility check among the three considered achieves an overall detection rate of 83.73% and a precision of 95.91%, far outperforming recently proposed machine learning-based misbehavior detection methods operating at the application layer. Steven So, Jonathan Petit, David Starobinski |
WiSec | 2 |
| 2018 | Integrating Plausibility Checks and Machine Learning for Misbehavior Detection in VANETabstractThe safety and efficiency of vehicular communications rely on the correctness of the data exchanged between vehicles. In this paper we address the issue of detecting and classifying location spoofing misbehavior using the VeReMi dataset. We propose a framework for a system that uses plausibility checks as a feature vector for machine learning models, used to detect and classify misbehavior. Using KNN and SVM, our results show we can improve the overall detection precision of the plausibility checks used in the feature vectors by over 20%, while maintaining a recall within 5%. We have also proven once a misbehavior has been detected it is possible to classify different types of known misbehavior's. Classifying the misbehavior types allows for more accurate and specific action steps to counteract the attacks, hence improving the ability to recover safety and security in the system. Steven So, Prinkle Sharma, Jonathan Petit |
ICMLA | 3 |
| 2018 | Pearson Correlation Analysis to Detect Misbehavior in VANETabstractVehicular Ad-hoc Networks (VANET) rely on Vehicle-to-Vehicle and Vehicle-to-Infrastructure communication to improve road safety and traffic efficiency. Therefore, malicious data could jeopardize the benefits of VANET communication. Hence, a data-centric misbehavior detection system should be deployed on each on-board unit to improve confidence in the received data. In this paper, we investigate the potential of using Pearson Correlation to detect location forging attacks. We analyze four location forging attacks and discuss how the correlation matrix detect them. The proposed solution works in real-time, without any training, but, depending on the type of road, requires at least four to seven seconds of history to be fully effective. Experiments are performed on real datasets from Wyoming Connected Vehicle Pilot Deployment and from University of Michigan Transportation Research Institute. Prinkle Sharma, Jonathan Petit |
VTC Fall | 2 |
| 2018 | An Evaluation of Pseudonym Changes for Vehicular Networks in Large-Scale, Realistic Traffic ScenariosabstractChanging pseudonym certificates are the agreed-upon approach for privacy-friendly message authentication in upcoming vehicular ad hoc networks and are included in recent standards. This paper examines the performance of four different pseudonym change strategies and their parameters using simulations of realistic, large-scale traffic scenarios. The strategies are assessed by measuring their effectiveness and efficiency in protecting drivers from being tracked by an attacker with limited coverage. In an urban scenario, all strategies achieve satisfactory privacy protection, but the change frequency required is rather high. In a highway scenario, the attacker algorithm achieves a high-tracking success for all strategies, especially in low traffic, even for very short change intervals. This paper proposes concrete change intervals for urban scenarios, which are higher than currently foreseen, but concludes that privacy protection in uniform traffic conditions remains a challenge. David Förster, Hans Löhr, Anne Gratz, Jonathan Petit, Frank Kargl |
IEEE Trans. Intell. Transp. Syst. | 4 |
| 2017 | Binary hash tree based certificate access management for connected vehiclesabstractWe present a certificate access management system to support the USDOT's proposed rule on Vehicle-to-Vehicle (V2V) communications, Federal Motor Vehicle Safety Standard (FMVSS) No. 150. Our proposal, which we call Binary Hash Tree based Certificate Access Management (BCAM) eliminates the need for vehicles to have bidirectional connectivity with the Security Credential Management System (SCMS) for certificate update. BCAM significantly improves the ability of the SCMS to manage large-scale software and/or hardware compromise events. Vehicles are provisioned at the start of their lifetime with all the certificates they will need. However, certificates and corresponding private key reconstruction values are provided to the vehicle encrypted, and the keys to decrypt them are only made available to the vehicles shortly before the start of the validity periods of those certificates. Vehicles that are compromised can be effectively removed from the V2V system by preventing them from decrypting the certificates. We demonstrate that the system is feasible with a broadcast channel for decryption keys and other revocation information, even if that channel has a relatively low capacity. Jonathan Petit, William Whyte |
WISEC | 2 |
| 2015 | Pre-Distribution of Certificates for Pseudonymous Broadcast Authentication in VANETabstractIn the context of vehicular networks, certificate management is challenging because of the dynamic topology and privacy requirements. In this paper we propose a technique that combines certificate omission and certificate pre-distribution in order to reduce communication overhead and to minimize cryptographic packet loss. Simulation results show that this technique is useful to improve awareness quality during pseudonym changes. Michael Feiri, Rolf Pielage, Jonathan Petit, Nicola Zannone, Frank Kargl |
VTC Spring | 3 |
| 2015 | Potential Cyberattacks on Automated VehiclesabstractVehicle automation has been one of the fundamental applications within the field of intelligent transportation systems (ITS) since the start of ITS research in the mid-1980s. For most of this time, it has been generally viewed as a futuristic concept that is not close to being ready for deployment. However, recent development of “self-driving” cars and the announcement by car manufacturers of their deployment by 2020 show that this is becoming a reality. The ITS industry has already been focusing much of its attention on the concepts of “connected vehicles” (United States) or “cooperative ITS” (Europe). These concepts are based on communication of data among vehicles (V2V) and/or between vehicles and the infrastructure (V2I/I2V) to provide the information needed to implement ITS applications. The separate threads of automated vehicles and cooperative ITS have not yet been thoroughly woven together, but this will be a necessary step in the near future because the cooperative exchange of data will provide vital inputs to improve the performance and safety of the automation systems. Thus, it is important to start thinking about the cybersecurity implications of cooperative automated vehicle systems. In this paper, we investigate the potential cyberattacks specific to automated vehicles, with their special needs and vulnerabilities. We analyze the threats on autonomous automated vehicles and cooperative automated vehicles. This analysis shows the need for considerably more redundancy than many have been expecting. We also raise awareness to generate discussion about these threats at this early stage in the development of vehicle automation systems. Jonathan Petit, Steven E. Shladover |
IEEE Trans. Intell. Transp. Syst. | 1 |
| 2011 | Dynamic consensus for secured vehicular ad hoc networksabstractVehicular ad hoc networks provide vehicle-to-vehicle communications and safety-related applications to enhance the road safety. However, safety-related applications, like Local Danger Warning, need a high trust level in received messages. Indeed, decisions are made depending on these messages. To increase the trustworthiness, a consensus mechanism is used. With consensus, vehicles need to receive at least X times the same warning before making a decision. Because the consensus should meet real-time constraints of safety applications, a main issue is to set parameter X. In this paper, we investigate the problem of consensus and propose a generic model to define decision method involved in consensus. Then, we propose to dynamically set the consensus parameter according to the neighborhood density and the warning criticalness. The proposed mechanism enhances the “majority of freshest X with threshold” decision method [1] and is analytically modeled. This context-aware and data-centric security mechanism ensures a quick and correct decision. We present some simulation results that validate our model. Jonathan Petit, Zoubir Mammeri |
WiMob | 1 |