Try GOLD - Free

EMFI-Triggered Software Faults

Circuit Cellar

|

September 2025

Can They Drive a Car Crazy?

- By Colin O'Flynn

EMFI-Triggered Software Faults

This article follows up on some previous work presented about using electromagnetic fault injection (EMFI) for triggering bugs in an automotive ECU which appeared to make it open up the throttle without the user pushing the pedal. While the previous research was done on a workbench, now Colin takes his tests to a running car and reports on his findings.

Back in my January 2021 article “Finding a $Billion Dollar Fault Mode” (Circuit Cellar 366), I described some work I did to try and track down what I believed to be an elusive ECU “bug” [1]. The term bug is used loosely, as really it was some form of corrupted data triggering unintended throttle control problems, and I was using an electromagnetic fault injection (EMFI) tool to trigger these modes.

In this article, I'm going to wrap up that work by discussing some additional tests I conducted over the past few years. But as some readers may not have been with me for the initial article (or your memory of an article you read four years ago isn't perfect), I'll quickly summarize what led me down this path, and what we can learn about safety-critical design.

UNINTENDED BEGINNINGS

The core of my bug hunting was to try and see if I could validate the claim that cars with electronic throttles can unintentionally accelerate without the user depressing the throttle. Such events are high-stress and rare, which make them difficult to prove, and if the car works perfectly afterwards, was someone just pushing the wrong pedal? Cases of “pedal misapplication” are known, but is every event driver error, or is there a reasonable chance some could be software or hardware failures?

The technical reason we might suspect it could be a software bug is because of the control loop shown in Figure 1. You can see there is no physical connection between the accelerator pedal and the throttle; this is all managed in software running on the controller.

MORE STORIES FROM Circuit Cellar

Circuit Cellar

Circuit Cellar

A GPS-Disciplined Frequency Counter using the PSoC 5LP

In this month's column, Brian tasks one of his mixed-signal favorite MCUs, the Infineon PSoC 5LP, to build a frequency/ period counter using a GPS satellite module to discipline the project's time base.

time to read

16 mins

November 2025

Circuit Cellar

Designing Analog Electronics

Part 1: Error and Uncertainty

time to read

23 mins

November 2025

Circuit Cellar

Samtec Launches 800-Position AcceleRate HP High-Performance Array Connectors

Samtec, Inc., a global leader in high-performance interconnect solutions and a service leader in the industry, announces the expansion of its AcceleRate HP product line with the release of 800-position APM6 and APF6 high-performance array connectors available in a low-profile 5mm stack height.

time to read

1 min

November 2025

Circuit Cellar

Circuit Cellar

CIA for SBCs (and More)

Securing Embedded Systems from Evolving Threats

time to read

14 mins

November 2025

Circuit Cellar

Circuit Cellar

The Future of Embedded Systems and AI: AI in Embedded Systems

Cybersecurity Challenges and Opportunities in a Smarter World

time to read

4 mins

November 2025

Circuit Cellar

Circuit Cellar

An ESP32 Dashboard

Monitoring How a Popular Microcontroller Uses Resources

time to read

11 mins

November 2025

Circuit Cellar

Circuit Cellar

Vishay Intertechnology Power Metal Strip Resistor Delivers Power to 5 W in Compact 1206 Case Size

Vishay Intertechnology, Inc. introduced a new surfacemount Power Metal Strip current sense resistor that combines a high power rating up to 5W, TCR down to ± 75ppm/°C, and extremely low resistance values down to 0.3mΩ in the compact 1206 case size.

time to read

2 mins

November 2025

Circuit Cellar

Circuit Cellar

ROHM Develops New Smart Switches Optimized for Zonal Controllers

ROHM Semiconductor announced the release of six new high-side smart switches (IPDs: Intelligent Power Devices) featuring highly accurate current sensing and low ON resistances ranging from 9mΩ to 180mΩ.

time to read

1 min

November 2025

Circuit Cellar

Circuit Cellar

Bourns Expands Semi-Shielded Power Inductor Portfolio with New Series Featuring Higher Maximum Inductance Values

Bourns, Inc., a leading manufacturer and supplier of electronic components for power, protection, and sensing solutions, announced the expansion of its semi-shielded power inductors.

time to read

1 min

November 2025

Circuit Cellar

Circuit Cellar

STMicroelectronics' New Automotive Linear Voltage Regulator Preserves Battery Energy in Challenging Conditions

The TL99VR03 300mA low-dropout (LDO) regulator provides resilient and efficient power, with a wide input-voltage range and very low quiescent current consumption, only 3.5µA at no load. The IC has an enable pin for turning the regulator off, which reduces the idle current to 800nA, and integrates soft-start circuitry to limit current during power-up and fault recovery.

time to read

1 min

November 2025

Listen

Translate

Share

-
+

Change font size