通过模块噪声注入,首次实现对端到端自动驾驶系统的高效攻击
Attack End-to-End Autonomous Driving through Module-Wise Noise
- 在模型推理过程中逐模块注入噪声,设计通用攻击方案
- 大规模实验验证攻击效果优于已有方法
- 揭示端到端自动驾驶系统安全漏洞,适合安全研究者参考
随着深度神经网络的突破,自动驾驶中的诸多任务已表现出卓越性能。然而,深度学习模型易受对抗攻击,给自动驾驶系统带来重大安全隐患。目前,端到端架构因其任务间的协同性已成为主流解决方案,但其对抗攻击的影响仍鲜有研究。本文首次针对模块化端到端自动驾驶模型开展全面的对抗安全研究,深入分析模型推理过程中的潜在漏洞,提出一种通过模块级噪声注入的通用攻击方案。在全栈自动驾驶模型上进行大规模实验,结果表明该攻击方法优于现有方法。本研究为保障自动驾驶系统的安全性与可靠性提供了新视角。
原文摘要 · Abstract (English)
With recent breakthroughs in deep neural networks, numerous tasks within autonomous driving have exhibited remarkable performance. However, deep learning models are susceptible to adversarial attacks, presenting significant security risks to autonomous driving systems. Presently, end-to-end architectures have emerged as the predominant solution for autonomous driving, owing to their collaborative nature across different tasks. Yet, the implications of adversarial attacks on such models remain relatively unexplored. In this paper, we conduct comprehensive adversarial security research on the modular end-to-end autonomous driving model for the first time. We thoroughly consider the potential vulnerabilities in the model inference process and design a universal attack scheme through module-wise noise injection. We conduct large-scale experiments on the full-stack autonomous driving model and demonstrate that our attack method outperforms previous attack methods. We trust that our research will offer fresh insights into ensuring the safety and reliability of autonomous driving systems.
Thank you to arXiv for use of its open access interoperability. PaperDance 不是 arXiv 官方产品;中文卡片由大模型生成,请以原文为准。