Georgia Tech researchers identified a new vulnerability they call VillainNet in AI “super networks” used by autonomous driving systems. Super networks work by swapping small subnetworks to handle tasks such as rain, heavy traffic or lane changes. David Oygenblik, a PhD student and lead researcher, helped lead the project.
The team found an attacker can hide a backdoor inside one subnetwork. The backdoor remains dormant until that specific subnetwork is selected; when triggered, it activates and can take control of the vehicle. The researchers describe a possible trigger: a self-driving taxi responding to rainfall and changing road conditions. Once in control, attackers could threaten passengers or force the car to crash.
In experiments the attack was almost certain to succeed when activated, with a 99% success rate. The researchers say detecting such a backdoor would need far more computing power and time than current methods allow. They warn the threat can be inserted at any development stage and call for stronger defenses. The work was presented at the ACM CCS conference in October 2025.
Difficult words
- vulnerability — a weakness that attackers can use
- super network — a large AI model made of many partsSuper networks
- subnetwork — a smaller part of a larger networksubnetworks
- backdoor — a secret access point for attackers
- dormant — inactive and not working now
- trigger — an event that makes something starttriggered
- attacker — a person who tries to harm the systemattackers
- detect — to find or notice a problem or faultdetecting
Tip: hover, focus or tap highlighted words in the article to see quick definitions while you read or listen.
Discussion questions
- What steps could developers take to make autonomous cars safer against this kind of threat?
- Would you feel safe riding in a self-driving taxi after reading this? Why or why not?
- The researchers say detecting the backdoor needs more computing power and time. How might that affect testing and development of self-driving systems?
Related articles
Touchscreens on car dashboards increase driver distraction
A simulator study found that using a car touchscreen while driving makes steering and touchscreen tasks worse. Multitasking reduced lane control and touchscreen accuracy; researchers suggest simple sensors could monitor attention and change the interface.
AI expands sexual and reproductive health access in Latin America
Research groups in Peru and Argentina use AI tools to give sexual and reproductive health information to young and marginalised people. Experts praise potential but warn of bias and call for better data, rules and oversight.
Traffic and Pollution in Asian Cities
Traffic congestion in many Asian cities raises pollution, lowers living standards and costs economies money. Cities such as Delhi, Bangkok and Metro Manila are expanding metros, switching to electric vehicles and using pricing and technology to reduce traffic.
New ultrasound method improves diagnosis of breast masses
Researchers developed a new ultrasound signal-processing method that distinguishes fluid cysts from solid breast masses. In initial patient tests doctors identified masses correctly far more often than with conventional ultrasound, which could reduce biopsies and follow-ups.