重新设计路标以抵御攻击,提升自动驾驶安全性
RED: Robust Environmental Design
- 通过无攻击者依赖的自动学习设计抗干扰路标
- 数字与物理测试中对贴纸攻击的脆弱性显著降低
- 适合自动驾驶安全系统设计者参考
自动驾驶系统依赖视觉输入对道路标志进行分类,极易受到对抗攻击影响。传统方法聚焦于提升分类模型的鲁棒性,本文则提出根本性新策略:通过重新设计路标本身增强鲁棒性。我们提出一种攻击无关的自动学习方案,用于生成对多种基于贴片的攻击具有抵抗力的路标。在数字和物理环境中进行的实证测试表明,该方法显著降低了路标对贴片攻击的脆弱性,优于现有技术。
原文摘要 · Abstract (English)
The classification of road signs by autonomous systems, especially those reliant on visual inputs, is highly susceptible to adversarial attacks. Traditional approaches to mitigating such vulnerabilities have focused on enhancing the robustness of classification models. In contrast, this paper adopts a fundamentally different strategy aimed at increasing robustness through the redesign of road signs themselves. We propose an attacker-agnostic learning scheme to automatically design road signs that are robust to a wide array of patch-based attacks. Empirical tests conducted in both digital and physical environments demonstrate that our approach significantly reduces vulnerability to patch attacks, outperforming existing techniques.
Thank you to arXiv for use of its open access interoperability. PaperDance 不是 arXiv 官方产品;中文卡片由大模型生成,请以原文为准。