Back to results

University of Houston

Logic-Targeted Data Poisoning and Cascading Failures in AI-Driven Distributed Traffic Control Systems

Abstract

dc:description.abstract

MARL (multi-agent reinforcement learning) is increasingly used to create intelligent traffc signal control systems for city-wide traffc management. This improves the movement of people and vehicles, but it also introduces new physical-layer safety risks at the sensor level that have not been studied suffciently. This thesis introduces the False Vacuum Attack, where one compromised sensor continuously reports “0” vehicles while the true intersection queue continues to grow. Because zero occupancy is a valid sensor reading, the attack can appear similar to an empty road or a sensor fault. In a coordinated MARL traffc system, nearby agents may interpret the compromised location as uncongested and continue sending traffc toward it. This can create a growing congestion cascade that spreads through the network even after the attack ends. The attack does not require access to the AI model, a breach of the control network, or compromise of more than one roadside sensor. To evaluate the attack, 20 trials were conducted on a 26-node network based on Glasgow City Center. In 90% of the trials, the attack spread congestion over at least two hops and affected approximately 27% of the network. The experiments also showed that MARL Coordination amplified the damage by up to 3.49 times compared with an equivalent single-point hardware failure. Standard anomaly detection methods were not effective because a zero-vehicle reading is physically plausible. The standard detector achieved an AUC close to 0.57, only slightly above random discrimination. This thesis proposes the False Vacuum Indicator (FVI), which checks for contradictions between the compromised sensor reading and the surrounding traffic conditions. The FVI achieved an AUC of 0.75, indicating moderate ability to distinguish attack conditions from normal conditions. Finally, this thesis evaluates a three-layer defense model that combines FVI with additional detection and containment policies. Under the tested susceptible conditions, the defense contained the observed attacks without event-level false alarms at the selected operating point. These results show that protecting AI-based transportation systems requires domain-aware detectors grounded in physical traffic behavior, rather than relying only on general statistical anomaly detection.

Degree

thesis:*
Name thesis:degree_name
Master of Science
Discipline thesis:degree_discipline
Cybersecurity
Grantor
University of Houston
Year dc:date.issued
2026

Author and committee

dc:creator, dc:contributor.*
Author dc:creator
  • Gammanpilage, Danindu Suresh Gammanpila 1993-
Advisor dc:contributor.advisor
  • Zhang, Yunpeng
Committee members dc:contributor.committeemember
  • Lee, Kyu In
  • Banerjee, Tania

Subjects

dc:subject × 7

Rights

Language dc:language.iso
English

Identifiers

dc:identifier.*
Handle dc:identifier.uri
https://hdl.handle.net/10657/21528
OAI identifier oai:identifier
oai:uh-ir.tdl.org:10657/21528

Chain of custody

source
Harvested from
University of Houston
Base URL
uh-ir.tdl.org/server/oai/request
Last updated
2026-07-24
Source record
OAI-PMH GetRecord
citation

Gammanpilage, Danindu Suresh Gammanpila 1993-. Logic-Targeted Data Poisoning and Cascading Failures in AI-Driven Distributed Traffic Control Systems. University of Houston, 2026. https://hdl.handle.net/10657/21528