Passenger Spoofing Attack for Artificial Intelligence-based Mobility-as-a-Service

Passenger Spoofing Attack for Artificial Intelligence-based Mobility-as-a-Service
复制标题

DOI:
10.1109/itsc57777.2023.10422567
复制
发表时间:
2023-09
期刊:
2023 IEEE 26th International Conference on Intelligent Transportation Systems (ITSC)
影响因子:
--
通讯作者:
Kai-Fung Chu;Weisi Guo
Kai-Fung Chu;Weisi Guo
中科院分区:
其他
文献类型:
--
作者:
Kai-Fung Chu;Weisi Guo

文献摘要

相似文献

移动即服务(MaaS)是一种新的移动服务模式,它集成了多个移动提供商,依靠多种数据处理技术来管理多式联运。人工智能(AI)是根据乘客的隐性经验和偏好来改善服务匹配的技术之一。然而,将人工智能纳入MaaS也可能会给系统带来漏洞。有人可能会利用乘客体验和偏好异质性的漏洞,通过伪造数据来优先考虑他们的旅程,这将危及MaaS的可信度。在本文中,我们研究了MaaS中的网络安全风险,重点研究了欺骗攻击,在欺骗攻击中,恶意乘客通过伪造数据来获得行程规划优势。欺骗攻击基于强化学习,学习通过伪造乘客状态请求旅行来降低乘客对MaaS的满意度及其利润。我们基于纽约市数据集进行实验来评估欺骗攻击。实验结果表明,该攻击可以减少约70%的利润。通过调查MaaS中的网络安全风险,我们可以增强对风险的认识和理解,从而构建一个安全可靠的MaaS。
Mobility-as-a-Service (MaaS), a new mobility service model that integrates multiple mobility providers, relies on many data processing technologies to manage multi-modal transport. Artificial Intelligence (AI) is one of the technologies to improve the services matching to passengers based on their implicit experience and preference. However, incorporating AI into MaaS may also introduce loopholes to the system. One may use the loophole in the heterogeneity of passenger experience and preference by falsifying data to prioritize their journey, which jeopardizes the trustworthiness of MaaS. In this paper, we investigate the cyber security risks in MaaS, focusing on the spoofing attack in which malicious passengers are prioritized by falsifying data to gain an advantage in journey planning. The spoofing attack is based on reinforcement learning that learns to reduce passenger satisfaction about the MaaS and its profit by requesting travel with falsifying passenger states. We conduct experiments based on New York City dataset to evaluate the spoofing attack. The experiment results indicate that the attack can reduce about 70% of the profit. By investigating the cyber security risks in MaaS, we could enhance the knowledge and understanding of the risks for building a secure and trustworthy MaaS.