| DATE: Thursday, October 1 |
TIME: 11:00 -11:45 am |
LOCATION: Bixby 1, 2, & 5 |
DURATION: |
This presentation introduces an AI-assisted vehicle cybersecurity platform that transforms AUTOSAR embedded software into a security-focused knowledge graph. The system combines abstract syntax trees (AST), control-flow graphs (CFG), data-flow analysis, symbol resolution, static analysis findings, and AI-generated annotations into a unified graph representation, enabling engineers to explore attack surfaces, trace source-to-sink paths, identify safety-critical components, and interact with the platform using natural-language queries.
To reduce the volume of manual analysis, the platform employs a two-tier AI architecture that combines lightweight models for orchestration, ranking, and clustering with more advanced models for deep reasoning. Findings are enriched with contextual information such as diagnostic exposure, and component criticality, while graph-aware retrieval provides the models with relevant code, relationships, and data-flow context. This approach helps prioritize actionable risks, reduce false positives, and focus engineering effort on vulnerabilities that are most likely to be reachable in real vehicle environments.
The system also incorporates a persistent project knowledge repository that stores validated findings, remediation guidance, diagnostic observations, analyst feedback, and lessons learned from previous investigations. This allows future analyses to benefit from accumulated expertise while supporting a human-in-the-loop workflow, where engineers can review findings, provide additional context, approve actions, or authorize higher-risk validation activities when required. The result is a collaborative environment that combines automation with expert oversight rather than replacing engineering judgment.
To move beyond vulnerability discovery, a Diagnostics Agent consumes prioritized findings and attempts to validate whether they are practically exploitable through vehicle diagnostic interfaces. Using AI-guided reasoning, the agent generates and evaluates multiple diagnostic interaction paths in parallel, analyzes responses, identifies missing preconditions, and determines whether a finding represents a real-world security risk or a theoretical issue. Knowledge from validated investigations can be shared through a separate cross-departmental vulnerability repository, enabling reuse of security intelligence across programs and organizations. The presentation will walk through the technical details of the architecture, demonstrate early results, and discuss the broader implications and future development of AI-assisted vulnerability validation.
Speaker

Ivan Granero
Senior Security Engineer, Bosch
Ivan Granero is an Automotive Cybersecurity Expert and has 15 years of development experience in Automotive Engineering (Passenger Cars, Commercial Vehicles – Fleets) in areas of acquisition, design, validation and manufacturing. He coordinates Bosch’s Americas commercial vehicle cross-divisional product security activities. He holds an MS in Software Engineering with a concentration in Cybersecurity from the University of Texas at El Paso and a BS EE, enjoys participating in Capture-the-Flag competitions and recently competed at DEFCON31 and 32 as part of BOSCH/ETAS team in the Car Hacking Village CTF obtaining 3rd place.
Ivan holds a MS in Cybersecurity from the University of Texas at El Paso. He is a PhD candidate of Engineering in Artificial Intelligence and Machine Learning (2027).



