Cybersecurity–Safety Integration: L2 ADAS · L3/4 ADS · Mobile Physical AI
Abstract: L2 driver assistance, L3/L4 autonomous driving, and humanoid and passenger-carrying quadruped robots share one cybersecurity methodology yet differ in who is responsible, how they are regulated, and how deeply cybersecurity couples with safety. This post systematically maps the requirements, differences, standards/regulations, and best practices across the three families, with a focus on how deeply cybersecurity integrates with functional safety (FuSa), SOTIF, and whole-machine safety. Key takeaways All three families have entered the “cybersecurity is an entry gate” stage, but with a clear gradient: L2 is enforced, L3/L4 has the highest bar, and mobile physical AI is weakest yet fastest-moving. The essence: L2 treats the network as an information asset, L3/L4 as a safety system, and physical AI as a physical safety device. Integration: L2 is coordinated, L3/L4 is integrated/converging, and mobile physical AI is mechanistically unified but method-empty. The adversarial AI surface (data poisoning, evasion, model theft) is the common new gap in 2026, under-covered by 21434/62443. Best practices are highly shared (TARA, defense in depth, SBOM, secure OTA, monitoring, pentest, PIA) and transferable across bodies. 1. Framework: three threads + two axes Three threads decide requirements: whether a human bails out, what physical environment the system operates in, and what the regulator can grab. L2 has a human fallback, L3/L4 has none, and mobile physical AI controls the physical body and balance — deciding whether cybersecurity is an “information asset problem,” a “safety system problem,” or a “physical safety device problem.” ...