As the automotive industry transitions towards software-defined vehicles (SDVs), manufacturers face an increasingly complex challenge: ensuring cybersecurity, functional safety and AI assurance evolve together rather than as separate engineering disciplines
During a recent panel at Vehicle Tech Week Europe, experts explained that integrating security and safety from the earliest stages of development is essential to reduce risk, lower validation costs and accelerate deployment.
Historically, functional safety and cybersecurity have been treated as largely independent activities. However, modern SDV architectures, with highly integrated domain controllers, AI-driven functions and continuous software updates, demand a far more unified approach.
Carlos Pérez Garrido, head of automotive cybersecurity – Automotive Technology Centre of Galicia (CTAG), believes the industry must rethink traditional development workflows: “Historically, activity has been isolated, but in SDV development it is really important that workflows are integrated to enable the same functionality and sensitivity across different architectures. It is crucial to shift to the left and incorporate security into the first stages of development.”
By embedding cybersecurity and assurance activities early in the design process, manufacturers can identify common failure scenarios before vehicles reach validation. A sensor malfunction and a malicious cyberattack may ultimately create identical hazardous vehicle behaviour, making joint analysis increasingly important. “A malfunction of a sensor and an exclusion of a sensor can lead to the same scenario, and it is important to treat these events as new scenarios,” he adds.
INCREASED COMPLEXITY
The growing complexity of vehicle electronics reinforces this need. Instead of dozens of standalone electronic control units (ECUs), many SDVs now rely on high-performance computing platforms (HCPs) hosting multiple virtualised ECUs running sophisticated software stacks connected via automotive Ethernet.
According to Salvador Ruiz Sedeño, automotive cybersecurity analyst at Dekra, this evolution has fundamentally changed cybersecurity validation: “Cybersecurity in today’s SDVs is becoming challenging because you have to test ECUs that are more complex than ever, and also more interconnected than ever.”
Unlike traditional ECUs, modern HCPs contain multiple interconnected applications supporting infotainment, gateways, diagnostics and increasingly safety-critical vehicle functions. As a result, penetration testing has become significantly more demanding. Sedeño adds, “The cost and time of this kind of test is quite substantial. For a HCP with multiple ECUs, it is even more expensive and time-consuming.”
For testing organisations, this means analysing not only software integrity but also the communication between virtualised systems, diagnostic interfaces and secure communication protocols operating across the vehicle network.
THE IMPACTS OF AI
AI introduces another layer of complexity. Unlike conventional software, AI systems cannot always be validated using deterministic testing methods because outputs are probabilistic rather than fixed. Instead, testing increasingly focuses on operational design domains, training data quality and uncertainty quantification to determine how confidently an AI system can make critical decisions.
“It is important to consider how robust the training data is,” says Dejan Arsic, business development specialist safeAI – IABG. “If you only have data for autonomous driving during sunshine, but then you are driving in rainy conditions, you have a problem.”
This approach becomes particularly important for perception systems responsible for detecting vulnerable road users under varying environmental conditions.
Dejan adds: “At the moment, there are different regulations and different standards that don’t cover all the use cases for object detection during autonomous driving. We are currently having to look at each use case individually, decide how to test it, what to test, and so on. We need come to a common agreement on regulation to be really able to test the systems and also certify them before the vehicle goes on the road.”
Looking ahead, all three panellists agreed that harmonised testing frameworks will be essential as software-defined vehicles continue to evolve. Existing standards provide a starting point, but closer collaboration between OEMs, suppliers, regulators and certification bodies will be needed to create common validation methodologies covering cybersecurity, functional safety and AI assurance.