针对自动驾驶视觉语言模型设计新型视觉对抗攻击,揭示其安全风险
Visual Adversarial Attack on Vision-Language Models for Autonomous Driving
- 用大语言模型生成语义一致的多样化指令库,提升攻击鲁棒性
- 通过注意力机制选择关键帧与视角,使扰动在时序场景中广泛生效
- 首个面向自动驾驶场景的视觉对抗攻击框架,适用于安全评估与防御研究
视觉语言模型(VLMs)显著提升了自动驾驶(AD)的推理能力,但其仍极易受到对抗攻击。现有研究多关注通用VLM攻击,忽视了对安全关键型自动驾驶场景的针对性攻击。本文首次提出面向自动驾驶VLM的对抗攻击框架ADvLM,揭示该领域潜在的重大风险。我们识别出两大挑战:文本指令的多样性与视觉场景的时间序列特性。为此,提出语义不变诱导(Semantic-Invariant Induction),利用大语言模型构建语义一致、多样性高的指令库,基于语义熵进行引导;并引入场景关联增强(Scenario-Associated Enhancement),通过注意力机制选择驾驶场景中的关键帧与视角,优化跨场景泛化的对抗扰动。在多个基准和主流AD VLM上进行的大量实验表明,ADvLM达到当前最佳攻击效果。真实世界攻击测试进一步验证其实际适用性与潜在威胁。
原文摘要 · Abstract (English)
Vision-language models (VLMs) have significantly advanced autonomous driving (AD) by enhancing reasoning capabilities. However, these models remain highly vulnerable to adversarial attacks. While existing research has primarily focused on general VLM attacks, the development of attacks tailored to the safety-critical AD context has been largely overlooked. In this paper, we take the first step toward designing adversarial attacks specifically targeting VLMs in AD, exposing the substantial risks these attacks pose within this critical domain. We identify two unique challenges for effective adversarial attacks on AD VLMs: the variability of textual instructions and the time-series nature of visual scenarios. To this end, we propose ADvLM, the first visual adversarial attack framework specifically designed for VLMs in AD. Our framework introduces Semantic-Invariant Induction, which uses a large language model to create a diverse prompt library of textual instructions with consistent semantic content, guided by semantic entropy. Building on this, we introduce Scenario-Associated Enhancement, an approach where attention mechanisms select key frames and perspectives within driving scenarios to optimize adversarial perturbations that generalize across the entire scenario. Extensive experiments on several AD VLMs over multiple benchmarks show that ADvLM achieves state-of-the-art attack effectiveness. Moreover, real-world attack studies further validate its applicability and potential in practice.
Thank you to arXiv for use of its open access interoperability. PaperDance 不是 arXiv 官方产品;中文卡片由大模型生成,请以原文为准。