{"id":{"repo_id":"uiuc","oai_identifier":"oai:www.ideals.illinois.edu:2142/125495"},"canonical_url":"https://search.dev.ndltd.org/etd/uiuc/oai:www.ideals.illinois.edu:2142/125495","repository":{"repo_id":"uiuc","name":"University of Illinois - Urbana-Champaign","base_url":"https://www.ideals.illinois.edu/oai-pmh"},"display":{"title":"Safe and secure autonomous vehicles","abstract":"The advent of machine learning has enabled autonomy applications that may have remained impossible otherwise. However, the inherent limitations of machine learning make its use for safety-critical tasks perilous. This is evident in the plethora of safety challenges facing autonomous vehicles. Autonomous vehicles have the potential to save and improve lives, however, their widespread usage and adoption have been severely inhibited by challenges in ensuring the safe operation of these vehicles. This work redesigns the autonomy software with separated fulfillment of safety and mission responsibilities. Safety-critical requirements are disentangled from mission-critical requirements, reduced while maintaining sufficiency, and fulfilled using verifiable software. A safety-critical layer, composed of verifiable software only, monitors the existing complex learning-dependent mission-critical system for faults at runtime, overriding the actions of the vehicle when faults in the mission-critical system may lead to safety violations. Learning from a study of real-world fatal collisions involving autonomous driving, the proposed system design is first applied to the crucial challenge of obstacle existence detection faults, or false negatives, in autonomous vehicles. Requirements for obstacle existence detection, i.e., when is an obstacle considered sufficiently detected to enable collision avoidance, are analyzed and reduced. A LiDAR-based classical geometrical obstacle detection algorithm is then analyzed to determine the bounds for its capability to detect an obstacle and its limitations. This algorithm is evaluated against real-world datasets showing that it meets the reduced but sufficient safety-critical requirements. Finally, using this obstacle detection algorithm, a safety monitor for the autonomous driving system is designed to provide deterministic guarantees against collisions due to obstacle existence detection faults. The developed safety properties were validated using simulation for autonomous ground and air vehicles. To ensure the reliable operation of the autonomous system, it needs to be monitored for security incidents and malicious attacks. In general-purpose systems, system auditing is a crucial tool for the detection and analysis of such events. Therefore, in this work, system-level auditing is adapted to real-time systems, developing Ellipsis, the first system-level security auditing system designed specifically for real-time systems. Ellipsis leverages the predictable repetition of behaviors in real-time systems to aggressively reduce the audit event logs generated by benign activity while preserving all security-relevant information and recording suspicious events in complete detail.","abstract_html":"The advent of machine learning has enabled autonomy applications that may have remained impossible otherwise. However, the inherent limitations of machine learning make its use for safety-critical tasks perilous. This is evident in the plethora of safety challenges facing autonomous vehicles. Autonomous vehicles have the potential to save and improve lives, however, their widespread usage and adoption have been severely inhibited by challenges in ensuring the safe operation of these vehicles. This work redesigns the autonomy software with separated fulfillment of safety and mission responsibilities. Safety-critical requirements are disentangled from mission-critical requirements, reduced while maintaining sufficiency, and fulfilled using verifiable software. A safety-critical layer, composed of verifiable software only, monitors the existing complex learning-dependent mission-critical system for faults at runtime, overriding the actions of the vehicle when faults in the mission-critical system may lead to safety violations. Learning from a study of real-world fatal collisions involving autonomous driving, the proposed system design is first applied to the crucial challenge of obstacle existence detection faults, or false negatives, in autonomous vehicles. Requirements for obstacle existence detection, i.e., when is an obstacle considered sufficiently detected to enable collision avoidance, are analyzed and reduced. A LiDAR-based classical geometrical obstacle detection algorithm is then analyzed to determine the bounds for its capability to detect an obstacle and its limitations. This algorithm is evaluated against real-world datasets showing that it meets the reduced but sufficient safety-critical requirements. Finally, using this obstacle detection algorithm, a safety monitor for the autonomous driving system is designed to provide deterministic guarantees against collisions due to obstacle existence detection faults. The developed safety properties were validated using simulation for autonomous ground and air vehicles. To ensure the reliable operation of the autonomous system, it needs to be monitored for security incidents and malicious attacks. In general-purpose systems, system auditing is a crucial tool for the detection and analysis of such events. Therefore, in this work, system-level auditing is adapted to real-time systems, developing Ellipsis, the first system-level security auditing system designed specifically for real-time systems. Ellipsis leverages the predictable repetition of behaviors in real-time systems to aggressively reduce the audit event logs generated by benign activity while preserving all security-relevant information and recording suspicious events in complete detail.","abstract_has_math":false,"creators":["Bansal, Ayoosh"],"institution":"University of Illinois at Urbana-Champaign","degree_name":"Ph.D.","degree_level":"Dissertation","degree_discipline":"Computer Science","degree_department":null,"school":null,"contributors":["Sha, Lui Raymond","Caccamo, Marco","Yuile, Adam Bates","Ramanathan, Parameswaran"],"advisors":[],"committee_chairs":[],"committee_members":[],"year":2024,"date_issued":"2024-07-03","date_published":"2024-07-03","updated_at":"2026-07-22T22:25:02Z","subjects":["Autonomous Vehicles","Safety","Fault Tolerance","Software Reliability","Cyber-physical Systems","Real-time Systems","Object Detection","Security","Auditing","Air Mobility","Vertical Takeoff And Landing"],"languages":["eng"],"rights":["Copyright 2024 Ayoosh Bansal"],"rights_urls":[],"identifier_entries":[]},"links":{"outbound_url":"https://hdl.handle.net/2142/125495","outbound_label":"Handle","outbound_source":"dc:identifier"},"metadata_groups":[{"id":"people","label":"People","entries":[{"key":"dc:contributor","label":"Contributor","values":["Sha, Lui Raymond","Caccamo, Marco","Yuile, Adam Bates","Ramanathan, Parameswaran"]},{"key":"dc:creator","label":"Author","values":["Bansal, Ayoosh"]}]},{"id":"academic_context","label":"Academic Context","entries":[{"key":"dc:date","label":"Dc Date","values":["2024-07-03","2024-08"]},{"key":"dc:type","label":"Dc Type","values":["Thesis"]},{"key":"thesis:degree_discipline","label":"Discipline","values":["Computer Science"]},{"key":"thesis:degree_level","label":"Degree Level","values":["Dissertation"]},{"key":"thesis:degree_name","label":"Degree Name","values":["Ph.D."]},{"key":"thesis:institution_name","label":"Thesis Institution Name","values":["University of Illinois at Urbana-Champaign"]}]},{"id":"subjects_keywords","label":"Subjects and Keywords","entries":[{"key":"dc:subject","label":"Dc Subject","values":["Autonomous Vehicles","Safety","Fault Tolerance","Software Reliability","Cyber-physical Systems","Real-time Systems","Object Detection","Security","Auditing","Air Mobility","Vertical Takeoff And Landing"]}]},{"id":"language_rights","label":"Language and Rights","entries":[{"key":"dc:language","label":"Dc Language","values":["eng"]},{"key":"dc:rights","label":"Dc Rights","values":["Copyright 2024 Ayoosh Bansal"]}]},{"id":"identifiers","label":"Identifiers","entries":[{"key":"dc:identifier","label":"Identifier","values":["https://hdl.handle.net/2142/125495"]}]},{"id":"additional","label":"Additional Metadata","entries":[{"key":"dc:description","label":"Description","values":["The advent of machine learning has enabled autonomy applications that may have remained impossible otherwise. However, the inherent limitations of machine learning make its use for safety-critical tasks perilous. This is evident in the plethora of safety challenges facing autonomous vehicles. Autonomous vehicles have the potential to save and improve lives, however, their widespread usage and adoption have been severely inhibited by challenges in ensuring the safe operation of these vehicles. This work redesigns the autonomy software with separated fulfillment of safety and mission responsibilities. Safety-critical requirements are disentangled from mission-critical requirements, reduced while maintaining sufficiency, and fulfilled using verifiable software. A safety-critical layer, composed of verifiable software only, monitors the existing complex learning-dependent mission-critical system for faults at runtime, overriding the actions of the vehicle when faults in the mission-critical system may lead to safety violations. Learning from a study of real-world fatal collisions involving autonomous driving, the proposed system design is first applied to the crucial challenge of obstacle existence detection faults, or false negatives, in autonomous vehicles. Requirements for obstacle existence detection, i.e., when is an obstacle considered sufficiently detected to enable collision avoidance, are analyzed and reduced. A LiDAR-based classical geometrical obstacle detection algorithm is then analyzed to determine the bounds for its capability to detect an obstacle and its limitations. This algorithm is evaluated against real-world datasets showing that it meets the reduced but sufficient safety-critical requirements. Finally, using this obstacle detection algorithm, a safety monitor for the autonomous driving system is designed to provide deterministic guarantees against collisions due to obstacle existence detection faults. The developed safety properties were validated using simulation for autonomous ground and air vehicles. To ensure the reliable operation of the autonomous system, it needs to be monitored for security incidents and malicious attacks. In general-purpose systems, system auditing is a crucial tool for the detection and analysis of such events. Therefore, in this work, system-level auditing is adapted to real-time systems, developing Ellipsis, the first system-level security auditing system designed specifically for real-time systems. Ellipsis leverages the predictable repetition of behaviors in real-time systems to aggressively reduce the audit event logs generated by benign activity while preserving all security-relevant information and recording suspicious events in complete detail."]},{"key":"dc:format","label":"Dc Format","values":["application/pdf"]},{"key":"dc:title","label":"Title","values":["Safe and secure autonomous vehicles"]}]}],"canonical_facts":{"dc:contributor":["Sha, Lui Raymond","Caccamo, Marco","Yuile, Adam Bates","Ramanathan, Parameswaran"],"dc:creator":["Bansal, Ayoosh"],"dc:date":["2024-07-03","2024-08"],"dc:description":["The advent of machine learning has enabled autonomy applications that may have remained impossible otherwise. However, the inherent limitations of machine learning make its use for safety-critical tasks perilous. This is evident in the plethora of safety challenges facing autonomous vehicles. Autonomous vehicles have the potential to save and improve lives, however, their widespread usage and adoption have been severely inhibited by challenges in ensuring the safe operation of these vehicles. This work redesigns the autonomy software with separated fulfillment of safety and mission responsibilities. Safety-critical requirements are disentangled from mission-critical requirements, reduced while maintaining sufficiency, and fulfilled using verifiable software. A safety-critical layer, composed of verifiable software only, monitors the existing complex learning-dependent mission-critical system for faults at runtime, overriding the actions of the vehicle when faults in the mission-critical system may lead to safety violations. Learning from a study of real-world fatal collisions involving autonomous driving, the proposed system design is first applied to the crucial challenge of obstacle existence detection faults, or false negatives, in autonomous vehicles. Requirements for obstacle existence detection, i.e., when is an obstacle considered sufficiently detected to enable collision avoidance, are analyzed and reduced. A LiDAR-based classical geometrical obstacle detection algorithm is then analyzed to determine the bounds for its capability to detect an obstacle and its limitations. This algorithm is evaluated against real-world datasets showing that it meets the reduced but sufficient safety-critical requirements. Finally, using this obstacle detection algorithm, a safety monitor for the autonomous driving system is designed to provide deterministic guarantees against collisions due to obstacle existence detection faults. The developed safety properties were validated using simulation for autonomous ground and air vehicles. To ensure the reliable operation of the autonomous system, it needs to be monitored for security incidents and malicious attacks. In general-purpose systems, system auditing is a crucial tool for the detection and analysis of such events. Therefore, in this work, system-level auditing is adapted to real-time systems, developing Ellipsis, the first system-level security auditing system designed specifically for real-time systems. Ellipsis leverages the predictable repetition of behaviors in real-time systems to aggressively reduce the audit event logs generated by benign activity while preserving all security-relevant information and recording suspicious events in complete detail."],"dc:format":["application/pdf"],"dc:identifier":["https://hdl.handle.net/2142/125495"],"dc:language":["eng"],"dc:rights":["Copyright 2024 Ayoosh Bansal"],"dc:subject":["Autonomous Vehicles","Safety","Fault Tolerance","Software Reliability","Cyber-physical Systems","Real-time Systems","Object Detection","Security","Auditing","Air Mobility","Vertical Takeoff And Landing"],"dc:title":["Safe and secure autonomous vehicles"],"dc:type":["Thesis"],"thesis:degree_discipline":["Computer Science"],"thesis:degree_level":["Dissertation"],"thesis:degree_name":["Ph.D."],"thesis:institution_name":["University of Illinois at Urbana-Champaign"]},"updated_at":"2026-07-22T22:25:02Z"}