surroundings. We have been taught to fear the “hacker”—the hooded figure in a dark room typing lines of code to seize control of our vehicles. But recent doctoral research has uncovered a far more insidious threat. In a new class of “SOTIF-oriented” attacks, an adversary doesn’t need to breach your firewall, find a software bug, or execute a single line of malicious code. They simply need to drive near you. [1]
SOTIF stands for Safety of the Intended Functionality. It refers to the inherent limitations of an autonomous vehicle’s “brain”—its sensors and algorithms. Because these systems are programmed with rigid safety thresholds and mathematical models, they can be manipulated by “adversarial driving.” In such cases, researchers investigate how the constraints of the safety logic of an autonomous vehicle can cause unexpected consequences in difficult traffic situations [1].
The Shadow-Target Attack: Hiding a Hazard
One of the most terrifying methods identified in the 2024 security investigation at Nanyang Technological University is the Shadow-Target Attack. In this maneuver, an attacker vehicle (the “Shadow”) purposefully maneuvers in front of a victim autonomous vehicle (AV). The attacker vehicle masks a stationary hazard—like a parked car, a road barrier, or a pedestrian—from the AV’s sensors until the very last possible second. [1]
By the time the attacker swerves out of the way, the victim AV is left with a “SOTIF limit” scenario. Its sensors finally detect the obstacle, but because the car’s processing speed and braking physics have a hard limit, when the obstacle comes into view, the vehicle may not have enough time or space to react safely. The result is a high-speed collision caused entirely by the car’s own programmed response to its surroundings. [1]
Indirect Attacks: Paralyzing Traffic
Attackers can also use “Indirect Traffic Flow Attacks” to manipulate “smart” cars from a distance. Research using the STFA (System-level Vulnerability Testing Platform) demonstrated that a single vehicle driving at a very slow speed (e.g., 0.5 m/s) can trigger the conservative safety thresholds of an AV [1].
This creates a “traffic wave” or bottleneck. The autonomous vehicle, following its strict “intended” behavior, may perceive the slow traffic as a permanent blockage, forcing it to stop indefinitely or attempt an extremely dangerous overtaking maneuver. Research simulations have shown high rates of task failure at certain intersections and junctions under certain experimental conditions. [1]
The Expertise Gap and Industrial Trust
The core of this crisis is that automotive engineering and cybersecurity are two different worlds. It is rare to find individuals who understand both the mechanical momentum of a car and the digital logic of its sensors. Much of this technology was implemented by people who prioritize convenience, while safety-critical security was an afterthought. [2, 3]
As vehicles become more connected, the attack surface grows. In 2025, ransomware attacks on the automotive sector doubled, accounting for 44% of all cyber incidents. While companies like Jaguar Land Rover saw billions in damages from production halts, individual drivers are now facing extortion cases where their ignitions are remotely locked for ransom. [4, 5]
The Principled Stand for Analog Driving
Why do I stick with “dumb” vehicles? Because physics doesn’t have a “SOTIF limitation.” In a mechanical vehicle, your eyes are the sensors and your experience is the algorithm. Both automated systems and human drivers have limitations; however, human drivers may be able to recognize and respond to some situations differently than automated systems. In an analog car, the steering column and the brake lines are a direct mechanical extension of your intent—not a software request that can be trapped in a logic loop by an adversarial driver.
At Qualitex Trading Co. Ltd. , we remain the world’s most trusted exporter of the one thing “smart” technology can’t replace: mechanical certainty. Our expertise in Japanese imports ensures that our clients receive vehicles where they, and only they, are in the driver’s seat. As the world of the car gets more connected, we still believe in durability, mechanical simplicity and driver involvement
Frequently Asked Questions
1. What does SOTIF mean for my car?
SOTIF (Safety of the Intended Functionality) refers to safety risks that come from the limitations of the car’s design—such as sensor ranges or processing speed—rather than software bugs or hacks. [1]
2. Can an autonomous car be “hacked” without code?
Yes. Research have demonstrated that specific traffic behaviors can lead to difficult situations for self-driving cars, which may influence their decision-making without needing any direct manipulation of the software. [1]
3. What is a “Shadow-Target” attack?
It is an attack where a lead vehicle hides a road hazard from an AV’s sensors until it is too late for the AV to brake, resulting in a collision. [1]
4. How does a “Low-Speed Attack” work?
An attacker drives at a very slow speed (around 0.5 m/s) to trigger an AV’s conservative safety programming, causing it to stall or make dangerous maneuvers. [1]
5. Why are T-junctions and intersections more dangerous for AVs?
Research shows SOTIF attacks have a near 100% success rate in these complex scenarios because the AV’s decision-making module struggles with unpredictable human behaviors. [1]
6. Did ransomware really cause a $2.5 billion loss in the auto industry?
Yes. In late 2025, a massive ransomware attack on Jaguar Land Rover halted global production for over three weeks, causing massive economic damage. [4]
7. Can a hacker lock me out of my own car for ransom?
Documented cases in 2025 show attackers seizing remote control of individual cars, locking doors and ignitions, and demanding payments to restore access. [4, 6]
8. Why are third-party suppliers a security risk?
Most automotive cyber incidents in 2024 hit smaller suppliers who have privileged access to manufacturer systems but lack the budget for high-end security. [4, 7]
9. Is a “dumb” vehicle really safer?
Vehicles that offer fewer connected features typically have a reduced remote attack surface, even though both conventional and contemporary vehicles pose distinct safety and security challenges [8].
10. What is Qualitex Trading Co. Ltd.’s stance on this?
We prioritize mechanical durability and driver sovereignty. We believe that numerous drivers still appreciate having direct mechanical control, straightforwardness, and less reliance on connected vehicle technologies.