Change search
Link to record
Permanent link

Direct link
Publications (10 of 19) Show all publications
Skoglund, M., Warg, F., Mirzai, A., Thorsén, A., Lundgren, K., Folkesson, P. & Havers-Zulka, B. (2025). AI Safety Assurance in Electric Vehicles: A Case Study onAI-Driven SOC Estimation. In: EVS (Ed.), EVS 38 - Proceedings: . Paper presented at The 38th International Electric Vehicle Symposium & Exposition.
Open this publication in new window or tab >>AI Safety Assurance in Electric Vehicles: A Case Study onAI-Driven SOC Estimation
Show others...
2025 (English)In: EVS 38 - Proceedings / [ed] EVS, 2025Conference paper, Published paper (Refereed)
Abstract [en]

Integrating Artificial Intelligence (AI) technology in electric vehicles (EV) introduces unique challenges for safety assurance, particularly within the framework of ISO 26262, which governs functional safety in the automotive domain. Traditional assessment methodologies are not geared toward evaluating AI-based functions and require evolving standards and practices. This paper explores how an independent assessment of an AI component in an EV can be achieved when combining ISO 26262 with the recently released ISO/PAS 8800, whose scope is AI safety for road vehicles. The AI-driven State of Charge (SOC) battery estimation exemplifies the process. Key features relevant to the independent assessment of this extended evaluation approach are identified. As part of the evaluation, robustness testing of the AI component is conducted using fault injection experiments, wherein perturbed sensor inputs are systematically introduced to assess the component's resilience to input variance.

Keywords
Artificial Intelligence, AI, electric vehicles, EV, safety assurance, ISO 26262, functional safety, independent assessment, AI safety, road vehicles, State of Charge, SOC, battery estimation, robustness testing, fault injection
National Category
Computer Systems
Identifiers
urn:nbn:se:ri:diva-78774 (URN)
Conference
The 38th International Electric Vehicle Symposium & Exposition
Projects
SUNRISE 101069573RELIANT 20220130
Funder
EU, Horizon Europe, 101069573
Note

We acknowledge the support of the Swedish Knowledge Foundation via the industrial doctoral schoolRELIANT, grant nr: 20220130. This research was carried out within the SUNRISE project and is fundedby the European Union’s Horizon Europe Research and Innovation Actions under grant agreement No.EVS38 International Battery, Hybrid and Fuel Cell Electric Vehicle Symposium — Abstract 10101069573.

Available from: 2025-09-03 Created: 2025-09-03 Last updated: 2026-06-23Bibliographically approved
Folkesson, P., Sangchoolie, B., Kleberger, P., Nowdehi, N., Giantamidis, G., Tsachouridis, V. & Basagiannis, S. (2025). On the Reduction of Error Space for Model-Implemented Fault- and Attack Injection. IEEE Transactions on Dependable and Secure Computing, 1-14
Open this publication in new window or tab >>On the Reduction of Error Space for Model-Implemented Fault- and Attack Injection
Show others...
2025 (English)In: IEEE Transactions on Dependable and Secure Computing, ISSN 1545-5971, E-ISSN 1941-0018, p. 1-14Article in journal (Refereed) Published
Abstract [en]

Fault- and attack injection are techniques usedto measure dependability attributes of  omputer systems. Animportant property of such techniques is their efficiency inexploring the target system’s fault- or attack space. As this spaceis generally very large, pre-injection analysis techniques may beused to effectively explore the space. In this paper, we studytwo such techniques proposed in the past, namely inject-on-readand inject-on-write. Furthermore, we propose two new techniquescalled error space pruning of signals and error space pruning ofsignals and ports and evaluate their efficiency in reducing thespace needed to be explored by injection experiments. Thesetechniques were integrated into MODIFI, a fault- and attackinjector targeting Simulink models. To the best of our knowledge,we are the first to evaluate these pre-injection techniques for thiskind of injector.The results of our evaluation of 11 Simulink models from theautomotive domain and one from the avionics domain, show thatthe new proposed techniques reduce the fault- and attack spaceneeded to be explored by about 27–49%. Using MODIFI, we thenperformed injection experiments on two automotive models,  swell as an aero engine control model, while elaborating on theresults obtained.

Keywords
fault injection, attack injection, cybersecurity testing, pre-injection analysis, error space pruning
National Category
Computer Systems
Identifiers
urn:nbn:se:ri:diva-79072 (URN)10.1109/tdsc.2025.3625383 (DOI)
Note

QC 20260311

Available from: 2025-10-29 Created: 2025-10-29 Last updated: 2026-03-11Bibliographically approved
Mohamad, M., Avula, R. R., Folkesson, P., Kleberger, P., Mirzai, A., Skoglund, M. & Damschen, M. (2024). Cybersecurity Pathways Towards CE-Certified Autonomous Forestry Machines. In: Proceedings - 2024 54th Annual IEEE/IFIP International Conference on Dependable Systems and Networks Workshops, DSN-W 2024: . Paper presented at 54th Annual IEEE/IFIP International Conference on Dependable Systems and Networks Workshops, DSN-W 2024. Brisbane, Australia. 24 June 2024through 27 June 2024 (pp. 98-105).
Open this publication in new window or tab >>Cybersecurity Pathways Towards CE-Certified Autonomous Forestry Machines
Show others...
2024 (English)In: Proceedings - 2024 54th Annual IEEE/IFIP International Conference on Dependable Systems and Networks Workshops, DSN-W 2024, 2024, p. 98-105Conference paper, Published paper (Other academic)
Abstract [en]

he increased importance of cybersecurity in autonomous machinery is becoming evident in the forestry domain. Forestry worksites are becoming more complex with the involvement of multiple systems and system of systems. Hence, there is a need to investigate how to address cybersecurity challenges for autonomous systems of systems in the forestry domain. Using a literature review and adapting standards from similar domains, as well as collaborative sessions with domain experts, we identify challenges towards CE-certified autonomous forestry machines focusing on cybersecurity and safety. Furthermore, we discuss the relationship between safety and cybersecurity risk assessment and their relation to AI, highlighting the need for a holistic methodology for their assurance.

National Category
Mechanical Engineering
Identifiers
urn:nbn:se:ri:diva-74609 (URN)10.1109/DSN-W60302.2024.00030 (DOI)
Conference
54th Annual IEEE/IFIP International Conference on Dependable Systems and Networks Workshops, DSN-W 2024. Brisbane, Australia. 24 June 2024through 27 June 2024
Note

AGRARSENSE is supported by the Chips JU and its members, including the top up funding by Sweden, Czechia, Finland, Ireland, Italy, Latvia, Netherlands, Norway, Poland and Spain (Grant Agreement No.101095835). T

Available from: 2024-07-21 Created: 2024-07-21 Last updated: 2025-09-23Bibliographically approved
Malik, M., Aramrattana, M., Maleki, M., Folkesson, P., Sangchoolie, B. & Karlsson, J. (2023). Simulation-based Evaluation of a Remotely Operated Road Vehicle under Transmission Delays and Denial-of-Service Attacks. In: Proceedings of IEEE Pacific Rim International Symposium on Dependable Computing, PRDC: . Paper presented at 28th IEEE Pacific Rim International Symposium on Dependable Computing, PRDC 2023. Singapore. 24 October 2023 through 27 October 2023 (pp. 23-29). IEEE Computer Society
Open this publication in new window or tab >>Simulation-based Evaluation of a Remotely Operated Road Vehicle under Transmission Delays and Denial-of-Service Attacks
Show others...
2023 (English)In: Proceedings of IEEE Pacific Rim International Symposium on Dependable Computing, PRDC, IEEE Computer Society , 2023, p. 23-29Conference paper, Published paper (Refereed)
Abstract [en]

A remotely operated road vehicle (RORV) refers to a vehicle operated wirelessly from a remote location. In this paper, we report results from an evaluation of two safety mechanisms: safe braking and disconnection. These safety mechanisms are included in the control software for RORV developed by Roboauto, an intelligent mobility solutions provider. The safety mechanisms monitor the communication system to detect packet transmission delays, lost messages, and outages caused by naturally occurring interference as well as denial-of-service (DoS) attacks. When the delay in the communication channel exceeds certain threshold values, the safety mechanisms are to initiate control actions to reduce the vehicle speed or stop the affected vehicle safely as soon as possible. To evaluate the effectiveness of the safety mechanisms, we exposed the vehicle control software to various communication failures using a software-in-the-loop (SIL) testing environment developed specifically for this study. Our results show that the safety mechanisms behaved correctly for a vast majority of the simulated communication failures. However, in a few cases, we noted that the safety mechanisms were triggered incorrectly, either too early or too late, according to the system specification. 

Place, publisher, year, edition, pages
IEEE Computer Society, 2023
Keywords
Control system synthesis; Denial-of-service attack; Failure (mechanical); Remote control; Safety engineering; Software testing; Vehicle to vehicle communications; Vehicle transmissions; Communication failure; Control software; Denialof- service attacks; Remote location; Remotely operated road vehicle; Road vehicles; Safety mechanisms; Software in the loops; Software-in-the-loop testing; Transmission delays; Specifications
National Category
Mechanical Engineering
Identifiers
urn:nbn:se:ri:diva-70583 (URN)10.1109/PRDC59308.2023.00012 (DOI)2-s2.0-85182390657 (Scopus ID)
Conference
28th IEEE Pacific Rim International Symposium on Dependable Computing, PRDC 2023. Singapore. 24 October 2023 through 27 October 2023
Note

This work was supported by VALU3S project, which hasreceived funding from the ECSEL Joint Undertaking (JU)under grant agreement No 876852. We also would like toexpress our sincere gratitude to Stepan Kar ´ asek and Beata Davidova from Roboauto, who provided us with invaluable ´support to test their system in the simulation environment.

Available from: 2024-01-22 Created: 2024-01-22 Last updated: 2025-09-23Bibliographically approved
Malik, M., Aramrattana, M., Maleki, M., Folkesson, P., Sangchoolie, B. & Karlsson, J. (2023). Simulation-based Evaluation of a Remotely Operated Road Vehicle under Transmission Delays and Denial-of-Service Attacks. In: 28th IEEE Pacific Rim International Symposium on Dependable Computing (PRDC 2023): . Paper presented at Pacific Rim International Symposium on Dependable Computing. IEEE conference proceedings
Open this publication in new window or tab >>Simulation-based Evaluation of a Remotely Operated Road Vehicle under Transmission Delays and Denial-of-Service Attacks
Show others...
2023 (English)In: 28th IEEE Pacific Rim International Symposium on Dependable Computing (PRDC 2023), IEEE conference proceedings, 2023Conference paper, Published paper (Other academic)
Abstract [en]

A remotely operated road vehicle (RORV) refers to a vehicle operated wirelessly from a remote location. In this paper, we report results from an evaluation of two safety mechanisms: safe braking and disconnection. These safety mechanisms are included in the control software for RORV developed by Roboauto, an intelligent mobility solutions provider. The safety mechanisms monitor the communication system to detect packet transmission delays, lost messages, and outages caused by naturally occurring interference as well as denial-of-service (DoS) attacks. When the delay in the communication channel exceeds certain threshold values, the safety mechanisms are to initiate control actions to reduce the vehicle speed or stop the affected vehicle safely as soon as possible. To evaluate the effectiveness of the safety mechanisms, we exposed the vehicle control software to various communication failures using a software-in-the-loop (SIL) testing environment developed specifically for this study. Our results show that the safety mechanisms behaved correctly for a vast majority of the simulated communication failures. However, in a few cases, we noted that the safety mechanisms were triggered incorrectly, either too early or too late, according to the system specification.

Place, publisher, year, edition, pages
IEEE conference proceedings, 2023
Keywords
remotely operated road vehicle (RORV), communication failures, denial-of-service (DoS) attacks, safety mechanisms, software-in-the-loop (SIL) testing
National Category
Computer Systems
Identifiers
urn:nbn:se:ri:diva-67577 (URN)
Conference
Pacific Rim International Symposium on Dependable Computing
Available from: 2023-10-31 Created: 2023-10-31 Last updated: 2025-09-23Bibliographically approved
Kleberger, P., Folkesson, P. & Sangchoolie, B. (2022). An Integrated Safety and Cybersecurity Resilience Framework for the Automotive Domain. In: : . Paper presented at 7th International Workshop on Critical Automotive Applications: Robustness & Safety. HAL
Open this publication in new window or tab >>An Integrated Safety and Cybersecurity Resilience Framework for the Automotive Domain
2022 (English)Conference paper, Published paper (Other academic)
Abstract [en]

As vehicles become more and more connected with their surroundings and utilize an increasing number of services, they also become more exposed to threats as the attack surface increases. With increasing attack surfaces and continuing challenges of eliminating vulnerabilities, vehicles need to be designed to work even under malicious activities, i.e., under attacks. In this paper, we present a resilience framework that integrates analysis of safety and cybersecurity mechanisms. We also integrate resilience for safety and cybersecurity into the fault – error – failure chain. The framework is useful for analyzing the propagation of faults and attacks between different system layers. This facilitates identification of adequate resilience mechanisms at different system layers as well as deriving suitable test cases for verification and validation of system resilience using fault and attack injection.

Place, publisher, year, edition, pages
HAL, 2022
Keywords
utomotive, cybersecurity, safety, resilience, framework
National Category
Computer Systems
Identifiers
urn:nbn:se:ri:diva-59793 (URN)
Conference
7th International Workshop on Critical Automotive Applications: Robustness & Safety
Available from: 2022-07-11 Created: 2022-07-11 Last updated: 2025-09-23Bibliographically approved
Thorsén, A., Sangchoolie, B., Folkesson, P. & Strandberg, T. (2022). Combined Safety and Cybersecurity Risk Assessment for Intelligent Distributed Grids. World Academy of Science, Engineering and Technology International Journal of Energy and Power Engineering, 16(5), 69-76
Open this publication in new window or tab >>Combined Safety and Cybersecurity Risk Assessment for Intelligent Distributed Grids
2022 (English)In: World Academy of Science, Engineering and Technology International Journal of Energy and Power Engineering, Vol. 16, no 5, p. 69-76Article in journal (Other academic) Published
Abstract [en]

As more parts of the power grid become connected to the internet, the risk of cyberattacks increases. To identify the cybersecurity threats and subsequently reduce vulnerabilities, the common practice is to carry out a cybersecurity risk assessment. For safety classified systems and products, there is also a need for safety risk assessments in addition to the cybersecurity risk assessment to identify and reduce safety risks. These two risk assessments are usually done separately, but since cybersecurity and functional safety are often related, a more comprehensive method covering both aspects is needed. Some work addressing this has been done for specific domains like the automotive domain, but more general methods suitable for, e.g., Intelligent Distributed Grids, are still missing. One such method from the automotive domain is the Security-Aware Hazard Analysis and Risk Assessment (SAHARA) method that combines safety and cybersecurity risk assessments. This paper presents an approach where the SAHARA method has been modified to be more suitable for larger distributed systems. The adapted SAHARA method has a more general risk assessment approach than the original SAHARA. The proposed method has been successfully applied on two use cases of an intelligent distributed grid.

Keywords
Intelligent distribution grids, threat analysis, risk assessment, safety, cybersecurity.
National Category
Mechanical Engineering
Identifiers
urn:nbn:se:ri:diva-59289 (URN)
Available from: 2022-05-25 Created: 2022-05-25 Last updated: 2025-09-23Bibliographically approved
Thorsén, A., Sangchoolie, B., Folkesson, P. & Strandberg, T. (2022). Combined Safety and Cybersecurity Risk Assessment for Intelligent Distributed Grids. In: : . Paper presented at CSG 2022: 16. International Conference on Smart Grids January 28-29, 2022 in Dubai, United Arab Emirates.
Open this publication in new window or tab >>Combined Safety and Cybersecurity Risk Assessment for Intelligent Distributed Grids
2022 (English)Conference paper, Published paper (Refereed)
Abstract [en]

As more parts of the power grid become connected to the internet, the risk of cyberattacks increases. To identify the cybersecurity threats and subsequently reduce vulnerabilities, the common practice is to carry out a cybersecurity risk assessment. For safety classified systems and products, there is also a need for safety risk assessments in addition to the cybersecurity risk assessment in order to identify and reduce safety risks. These two risk assessments are usually done separately, but since cybersecurity and functional safety are often related, a more comprehensive method covering both aspects is needed. Some work addressing this has been done for specific domains like the automotive domain, but more general methods suitable for, e.g., Intelligent Distributed Grids, are still missing. One such method from the automotive domain is the Security-Aware Hazard Analysis and Risk Assessment (SAHARA) method that combines safety and cybersecurity risk assessments. This paper presents an approach where the SAHARA method has been modified in order to be more suitable for larger distributed systems. The adapted SAHARA method has a more general risk assessment approach than the original SAHARA. The proposed method has been successfully applied on two use cases of an intelligent distributed grid.

Keywords
Intelligent Distribution Grids, threat analysis, risk assessment, safety, cybersecurity
National Category
Computer Sciences
Identifiers
urn:nbn:se:ri:diva-57520 (URN)
Conference
CSG 2022: 16. International Conference on Smart Grids January 28-29, 2022 in Dubai, United Arab Emirates
Available from: 2022-01-03 Created: 2022-01-03 Last updated: 2025-09-23Bibliographically approved
Malik, M., Maleki, M., Folkesson, P., Sangchoolie, B. & Karlsson, J. (2022). ComFASE: A Tool for Evaluating the Effects of V2V Communication Faults and Attacks on Automated Vehicles. In: 52nd annual IEEE/IFIP international conference on dependable systems and networks (DSN2022): . Paper presented at 52nd annual IEEE/IFIP international conference on dependable systems and networks (DSN2022). Jun 27, 2022 - Jun 30, 2022. Baltimore, Maryland, USA.
Open this publication in new window or tab >>ComFASE: A Tool for Evaluating the Effects of V2V Communication Faults and Attacks on Automated Vehicles
Show others...
2022 (English)In: 52nd annual IEEE/IFIP international conference on dependable systems and networks (DSN2022), 2022Conference paper, Published paper (Refereed)
Abstract [en]

This paper presents ComFASE, a communication fault and attack simulation engine. ComFASE is used to identify and evaluate potentially dangerous behaviours of interconnected automated vehicles in the presence of faults and attacks in wireless vehicular networks. ComFASE is built on top of OMNET++ (a network simulator) and integrates SUMO (a traffic simulator) and Veins (a vehicular network simulator). The tool is flexible in modelling different types of faults and attacks and can be effectively used to study the interplay between safety and cybersecurity attributes by injecting cybersecurity attacks and evaluating their safety implications. To demonstrate the tool, we present results from a series of simulation experiments, where we injected delay and denial-of-service attacks on wireless messages exchanged between vehicles in a platooning application. The results show how different variants of attacks influence the platooning system in terms of collision incidents.

Keywords
attack injection, fault injection, simulation-based system, V2V communication, platooning, cybersecurity attack
National Category
Computer Systems
Identifiers
urn:nbn:se:ri:diva-59789 (URN)
Conference
52nd annual IEEE/IFIP international conference on dependable systems and networks (DSN2022). Jun 27, 2022 - Jun 30, 2022. Baltimore, Maryland, USA
Projects
VALU3S
Available from: 2022-07-11 Created: 2022-07-11 Last updated: 2025-09-23Bibliographically approved
Ferrari, E., Schlick, R., De la Vara, J. L., Folkesson, P. & Sangchoolie, B. (2022). Criteria for the Analysis of Gaps and Limitations of V&V Methods for Safety- and Security-Critical Systems. In: : . Paper presented at 17th International Workshop on Dependable Embedded Cyber-Physical Systems and Systems-of-Systems. Munich, Germany. 6-9 September 2022. Springer Berlin/Heidelberg
Open this publication in new window or tab >>Criteria for the Analysis of Gaps and Limitations of V&V Methods for Safety- and Security-Critical Systems
Show others...
2022 (English)Conference paper, Published paper (Refereed)
Abstract [en]

As society increasingly relies on safety- and security- critical systems, the need for confirming their dependability becomes essential. Adequate V&V (verification and validation) methods must be employed, e.g., for system testing. When selecting and using the methods, it is important to analyze their possible gaps and limitations, such as scalability issues. However, and as we have experienced, common, explicitly defined criteria are seldom used for such analyses. This results in analyses that consider different aspects and to a different extent, hindering their comparison and thus the comparison of the V&V methods. As a solution, we present a set of criteria for the analysis of gaps and limitations of V&V methods for safety- and security-critical systems. The criteria have been identified in the scope of the VALU3S project. Sixty-two people from 33 organizations agreed upon the use of nine criteria: functionality, accuracy, scalability, deployment, learning curve, automation, reference environment, cost, and standards. Their use led to more homogeneous and more detailed analyses when compared to similar previous efforts. We argue that the proposed criteria can be helpful to others when having to deal with similar activities.

Place, publisher, year, edition, pages
Springer Berlin/Heidelberg, 2022
Keywords
Verification & Validation, V&V method, Gaps, Limitations, Analysis criteria, Safety-critical systems, Security-critical systems
National Category
Computer Systems
Identifiers
urn:nbn:se:ri:diva-59792 (URN)
Conference
17th International Workshop on Dependable Embedded Cyber-Physical Systems and Systems-of-Systems. Munich, Germany. 6-9 September 2022
Projects
VALU3S
Available from: 2022-07-11 Created: 2022-07-11 Last updated: 2025-09-23Bibliographically approved
Organisations
Identifiers
ORCID iD: ORCID iD iconorcid.org/0000-0001-5224-9412

Search in DiVA

Show all publications