“Automotive cybersecurity testing has to reflect the whole ecosystem around the vehicle. A vulnerability in a cloud service, API or third-party component may look distant from the vehicle itself, but connected architectures can turn it into an automotive security risk,” says Klaudia Zaika, CEO of Apriorit.
AI creates a new cybersecurity assurance gap
AI introduces a different class of risk into automotive systems. Unlike conventional software, machine-learning systems can behave differently depending on training data, sensor inputs and changing real-world conditions.
This makes it harder to determine whether an unexpected outcome is a software defect, an AI limitation or the result of deliberate manipulation.
Industry standards are beginning to address different parts of this problem. ISO/PAS 8800:2024 specifically addresses safety and artificial intelligence in road vehicles, including risks arising from insufficient or erroneous AI outputs.
ISO 21448 (SOTIF) covers hazards caused by limitations in intended functionality, particularly for systems dependent on sensors and complex algorithms.
Meanwhile, ISO/SAE 21434 and UNECE R155 provide the broader cybersecurity risk-management framework for connected vehicle systems. UNECE has also established a dedicated working group on AI in vehicle regulations, reflecting how quickly the regulatory landscape is evolving.
The cybersecurity implications are already tangible. AI-powered ADAS and autonomous-driving functions depend on camera, radar, lidar and other sensor data that attackers may try to manipulate.
Source: cybermagazine.com


