{"id":{"repo_id":"houston","oai_identifier":"oai:uh-ir.tdl.org:10657/21528"},"canonical_url":"https://search.dev.ndltd.org/etd/houston/oai:uh-ir.tdl.org:10657/21528","repository":{"repo_id":"houston","name":"University of Houston","base_url":"https://uh-ir.tdl.org/server/oai/request"},"display":{"title":"Logic-Targeted Data Poisoning and Cascading Failures in AI-Driven Distributed Traffic Control Systems","abstract":"MARL (multi-agent reinforcement learning) is increasingly used to create intelligent traffc signal control systems for city-wide traffc management. This improves the movement of people and vehicles, but it also introduces new physical-layer safety risks at the sensor level that have not been studied suffciently. This thesis introduces the False Vacuum Attack, where one compromised sensor continuously reports “0” vehicles while the true intersection queue continues to grow. Because zero occupancy is a valid sensor reading, the attack can appear similar to an empty road or a sensor fault. In a coordinated MARL traffc system, nearby agents may interpret the compromised location as uncongested and continue sending traffc toward it. This can create a growing congestion cascade that spreads through the network even after the attack ends. The attack does not require access to the AI model, a breach of the control network, or compromise of more than one roadside sensor. To evaluate the attack, 20 trials were conducted on a 26-node network based on Glasgow City Center. In 90% of the trials, the attack spread congestion over at least two hops and affected approximately 27% of the network. The experiments also showed that MARL Coordination amplified the damage by up to 3.49 times compared with an equivalent single-point hardware failure. Standard anomaly detection methods were not effective because a zero-vehicle reading is physically plausible. The standard detector achieved an AUC close to 0.57, only slightly above random discrimination. This thesis proposes the False Vacuum Indicator (FVI), which checks for contradictions between the compromised sensor reading and the surrounding traffic conditions. The FVI achieved an AUC of 0.75, indicating moderate ability to distinguish attack conditions from normal conditions. Finally, this thesis evaluates a three-layer defense model that combines FVI with additional detection and containment policies. Under the tested susceptible conditions, the defense contained the observed attacks without event-level false alarms at the selected operating point. These results show that protecting AI-based transportation systems requires domain-aware detectors grounded in physical traffic behavior, rather than relying only on general statistical anomaly detection.","abstract_html":"MARL (multi-agent reinforcement learning) is increasingly used to create intelligent traffc signal control systems for city-wide traffc management. This improves the movement of people and vehicles, but it also introduces new physical-layer safety risks at the sensor level that have not been studied suffciently. This thesis introduces the False Vacuum Attack, where one compromised sensor continuously reports “0” vehicles while the true intersection queue continues to grow. Because zero occupancy is a valid sensor reading, the attack can appear similar to an empty road or a sensor fault. In a coordinated MARL traffc system, nearby agents may interpret the compromised location as uncongested and continue sending traffc toward it. This can create a growing congestion cascade that spreads through the network even after the attack ends. The attack does not require access to the AI model, a breach of the control network, or compromise of more than one roadside sensor. To evaluate the attack, 20 trials were conducted on a 26-node network based on Glasgow City Center. In 90% of the trials, the attack spread congestion over at least two hops and affected approximately 27% of the network. The experiments also showed that MARL Coordination amplified the damage by up to 3.49 times compared with an equivalent single-point hardware failure. Standard anomaly detection methods were not effective because a zero-vehicle reading is physically plausible. The standard detector achieved an AUC close to 0.57, only slightly above random discrimination. This thesis proposes the False Vacuum Indicator (FVI), which checks for contradictions between the compromised sensor reading and the surrounding traffic conditions. The FVI achieved an AUC of 0.75, indicating moderate ability to distinguish attack conditions from normal conditions. Finally, this thesis evaluates a three-layer defense model that combines FVI with additional detection and containment policies. Under the tested susceptible conditions, the defense contained the observed attacks without event-level false alarms at the selected operating point. These results show that protecting AI-based transportation systems requires domain-aware detectors grounded in physical traffic behavior, rather than relying only on general statistical anomaly detection.","abstract_has_math":false,"creators":["Gammanpilage, Danindu Suresh Gammanpila 1993-"],"institution":"University of Houston","degree_name":"Master of Science","degree_level":null,"degree_discipline":"Cybersecurity","degree_department":null,"school":null,"contributors":[],"advisors":["Zhang, Yunpeng"],"committee_chairs":[],"committee_members":["Lee, Kyu In","Banerjee, Tania"],"year":2026,"date_issued":"2026-05","date_published":"2026-05","updated_at":"2026-07-24T02:32:34Z","subjects":["Intelligent transportation systems","Cascading failure","Multi-agent reinforcement learning","Sensor poisoning","Cyber-physical security","Anomaly detection","Adversarial machine learning"],"languages":["English"],"rights":[],"rights_urls":[],"identifier_entries":[]},"links":{"outbound_url":"https://hdl.handle.net/10657/21528","outbound_label":"Handle","outbound_source":"dc:identifier.uri"},"metadata_groups":[{"id":"people","label":"People","entries":[{"key":"dc:contributor.advisor","label":"Advisor","values":["Zhang, Yunpeng"]},{"key":"dc:contributor.committeemember","label":"Committee Member","values":["Lee, Kyu In","Banerjee, Tania"]},{"key":"dc:creator","label":"Author","values":["Gammanpilage, Danindu Suresh Gammanpila 1993-"]}]},{"id":"academic_context","label":"Academic Context","entries":[{"key":"dc:date.accessioned","label":"Dc Date Accessioned","values":["2026-07-14T19:33:54Z"]},{"key":"dc:date.issued","label":"Date","values":["2026-05"]},{"key":"dc:type","label":"Dc Type","values":["Thesis"]},{"key":"thesis:degree_discipline","label":"Discipline","values":["Cybersecurity"]},{"key":"thesis:degree_name","label":"Degree Name","values":["Master of Science"]},{"key":"thesis:institution_name","label":"Thesis Institution Name","values":["University of Houston"]}]},{"id":"subjects_keywords","label":"Subjects and Keywords","entries":[{"key":"dc:subject","label":"Dc Subject","values":["Intelligent transportation systems","Cascading failure","Multi-agent reinforcement learning","Sensor poisoning","Cyber-physical security","Anomaly detection","Adversarial machine learning"]}]},{"id":"language_rights","label":"Language and Rights","entries":[{"key":"dc:language.iso","label":"Language (ISO)","values":["English"]}]},{"id":"identifiers","label":"Identifiers","entries":[{"key":"dc:identifier.uri","label":"Identifier URI","values":["https://hdl.handle.net/10657/21528"]}]},{"id":"additional","label":"Additional Metadata","entries":[{"key":"dc:description.abstract","label":"Abstract","values":["MARL (multi-agent reinforcement learning) is increasingly used to create intelligent traffc signal control systems for city-wide traffc management. This improves the movement of people and vehicles, but it also introduces new physical-layer safety risks at the sensor level that have not been studied suffciently. This thesis introduces the False Vacuum Attack, where one compromised sensor continuously reports “0” vehicles while the true intersection queue continues to grow. Because zero occupancy is a valid sensor reading, the attack can appear similar to an empty road or a sensor fault. In a coordinated MARL traffc system, nearby agents may interpret the compromised location as uncongested and continue sending traffc toward it. This can create a growing congestion cascade that spreads through the network even after the attack ends. The attack does not require access to the AI model, a breach of the control network, or compromise of more than one roadside sensor. To evaluate the attack, 20 trials were conducted on a 26-node network based on Glasgow City Center. In 90% of the trials, the attack spread congestion over at least two hops and affected approximately 27% of the network. The experiments also showed that MARL Coordination amplified the damage by up to 3.49 times compared with an equivalent single-point hardware failure. Standard anomaly detection methods were not effective because a zero-vehicle reading is physically plausible. The standard detector achieved an AUC close to 0.57, only slightly above random discrimination. This thesis proposes the False Vacuum Indicator (FVI), which checks for contradictions between the compromised sensor reading and the surrounding traffic conditions. The FVI achieved an AUC of 0.75, indicating moderate ability to distinguish attack conditions from normal conditions. Finally, this thesis evaluates a three-layer defense model that combines FVI with additional detection and containment policies. Under the tested susceptible conditions, the defense contained the observed attacks without event-level false alarms at the selected operating point. These results show that protecting AI-based transportation systems requires domain-aware detectors grounded in physical traffic behavior, rather than relying only on general statistical anomaly detection."]},{"key":"dc:format.mimetype","label":"Dc Format Mimetype","values":["application/pdf"]},{"key":"dc:title","label":"Title","values":["Logic-Targeted Data Poisoning and Cascading Failures in AI-Driven Distributed Traffic Control Systems"]}]}],"canonical_facts":{"dc:contributor.advisor":["Zhang, Yunpeng"],"dc:contributor.committeemember":["Lee, Kyu In","Banerjee, Tania"],"dc:creator":["Gammanpilage, Danindu Suresh Gammanpila 1993-"],"dc:date.accessioned":["2026-07-14T19:33:54Z"],"dc:date.issued":["2026-05"],"dc:description.abstract":["MARL (multi-agent reinforcement learning) is increasingly used to create intelligent traffc signal control systems for city-wide traffc management. This improves the movement of people and vehicles, but it also introduces new physical-layer safety risks at the sensor level that have not been studied suffciently. This thesis introduces the False Vacuum Attack, where one compromised sensor continuously reports “0” vehicles while the true intersection queue continues to grow. Because zero occupancy is a valid sensor reading, the attack can appear similar to an empty road or a sensor fault. In a coordinated MARL traffc system, nearby agents may interpret the compromised location as uncongested and continue sending traffc toward it. This can create a growing congestion cascade that spreads through the network even after the attack ends. The attack does not require access to the AI model, a breach of the control network, or compromise of more than one roadside sensor. To evaluate the attack, 20 trials were conducted on a 26-node network based on Glasgow City Center. In 90% of the trials, the attack spread congestion over at least two hops and affected approximately 27% of the network. The experiments also showed that MARL Coordination amplified the damage by up to 3.49 times compared with an equivalent single-point hardware failure. Standard anomaly detection methods were not effective because a zero-vehicle reading is physically plausible. The standard detector achieved an AUC close to 0.57, only slightly above random discrimination. This thesis proposes the False Vacuum Indicator (FVI), which checks for contradictions between the compromised sensor reading and the surrounding traffic conditions. The FVI achieved an AUC of 0.75, indicating moderate ability to distinguish attack conditions from normal conditions. Finally, this thesis evaluates a three-layer defense model that combines FVI with additional detection and containment policies. Under the tested susceptible conditions, the defense contained the observed attacks without event-level false alarms at the selected operating point. These results show that protecting AI-based transportation systems requires domain-aware detectors grounded in physical traffic behavior, rather than relying only on general statistical anomaly detection."],"dc:format.mimetype":["application/pdf"],"dc:identifier.uri":["https://hdl.handle.net/10657/21528"],"dc:language.iso":["English"],"dc:subject":["Intelligent transportation systems","Cascading failure","Multi-agent reinforcement learning","Sensor poisoning","Cyber-physical security","Anomaly detection","Adversarial machine learning"],"dc:title":["Logic-Targeted Data Poisoning and Cascading Failures in AI-Driven Distributed Traffic Control Systems"],"dc:type":["Thesis"],"thesis:degree_discipline":["Cybersecurity"],"thesis:degree_name":["Master of Science"],"thesis:institution_name":["University of Houston"]},"updated_at":"2026-07-24T02:32:34Z"}