I think you're wearing rose-colored glasses, and you're underestimating the number of attackers that will be targeting autonomous vehicle systems.
Your faith in "common sense good security engineering" saving the day flies in the face of years of IT security reality. Computer security has been discussed, both formally and informally, since there have been networked computers (have a look at the "Ware Report", prepared by the RAND corporation for the DoD in 1967), yet the general state of IT security is horrendous.
The Toyota uncontrolled acceleration bug and the subsequent software quality issues were reported by Phil Koopman make me think the auto industry isn't particularly qualified to take on security, reliability, or formal verification of their software. (Toyota might be a single example, but I find it hard to believe that software quality is generally any better across the industry. VW's software-based emissions defeat device makes me that much more suspicious of the industry as a whole.)
Attackers are going to be everyone from nation-states who want to surveil their citizenry to individuals who "game" the algorithms in other drivers' autonomous cars to allow themselves to move more quickly through traffic. I'm sure that staged accident insurance fraud, carjacking, hit-and-run, and other vehicle-related crimes will evolve in the face of the rise of autonomous vehicles.
I expect an outcry from law enforcement and "grass roots" groups to demand draconian measures to "lock down" autonomous vehicles. I expect that copyright maximalists and others who would benefit from restrictions on the use of general purpose computers will jump on the bandwagon too. I'm envisioning a future like Stallman's "Right to Read", but applied to our cars and any computers that interface with them.