On the security and privacy of LLMs in Mobility
Survey finds LLM mobility research largely neglects security, privacy, and EU AI Act compliance despite transportation AI's high-risk classification.
The paper surveys LLM applications in the mobility sector (a roughly $2.9 trillion annual market affecting over 1.5 billion vehicles) and derives nine technical requirement classes from the EU AI Act, which classifies transportation AI as high risk. Reviewed research focuses mainly on GPT and Llama models (over 50% of works) and traffic applications, while largely neglecting security, privacy, and reliability. Of 35 reviewed works, only one includes a partial vulnerability assessment and one a partial risk management system, revealing a large gap between optimization performance and regulatory adherence.
- Nine technical classes derived from EU AI Act high-risk requirements
- GPT and Llama dominate over 50% of reviewed mobility LLM research
- Only 1 of 35 works includes a partial vulnerability assessment
- Authors urge security-by-design for safety-critical intelligent transportation systems
Full article190 words · extracted from arxiv.org · click to collapse
The mobility sector is undergoing a paradigm shift driven by advances in Generative Artificial Intelligence. With a global market valued at approximately 2.9 trillion dollars annually, considering only cars, the integration of these technologies has the potential to impact more than 1.5 billion vehicles worldwide. As Large Language Models (LLMs) are increasingly adopted in mobility, concerns about cybersecurity, privacy, and reliability emerge. Accordingly, this paper surveys current applications and assesses these challenges. Since the European AI Act classifies transportation AI as high risk, we derive nine technical classes from its requirements to assess current research and future deployments. Our findings show that research mainly studies GPT and Llama models (over 50\% of reviewed works) and traffic applications while largely neglecting security, privacy, and reliability. This gap extends to AI Act compliance: among 35 reviewed works, only one includes a partial vulnerability assessment and one a partial risk management system. We identify a clear gap between strong optimization performance and regulatory adherence, suggesting compliance is limited less by technology than by a focus on static performance over lifecycle safety, and underscoring an urgent need for security-by-design in safety-critical intelligent transportation systems.
Text extracted automatically; images, tables and formatting may be missing. Original: https://arxiv.org/abs/2609.26295