用智能攻击策略在关键时刻制造车祸,效率超传统方法1.3倍以上。
Less is More: A Stealthy and Efficient Adversarial Attack Method for DRL-based Autonomous Driving Policies
- 基于强化学习设计攻击者,自动选择关键时机投毒。
- 多数场景下3次攻击内碰撞率超90%,效率提升130%以上。
- 无需领域知识,适合研究自动驾驶安全漏洞的学者使用。
尽管深度强化学习(DRL)在自动驾驶政策中取得显著进展,但其仍易受对抗攻击影响,威胁实际部署。为提升政策鲁棒性,需设计有效的对抗攻击。本文提出一种隐蔽且高效的DRL驱动自动驾驶攻击方法:构建基于DRL的攻击者,在关键时刻注入对抗样本以引发安全事故(如碰撞)。将攻击建模为混合整数优化问题,并转化为马尔可夫决策过程求解。通过训练攻击者自主学习最优攻击策略,无需领域知识。引入攻击相关信息与轨迹截断方法增强学习能力。在无保护左转场景下,不同交通密度条件下验证该方法。实验表明,多数情况下3次攻击内碰撞率超过90%;相比无限攻击方法,攻击效率提升超130%。
原文摘要 · Abstract (English)
Despite significant advancements in deep reinforcement learning (DRL)-based autonomous driving policies, these policies still exhibit vulnerability to adversarial attacks. This vulnerability poses a formidable challenge to the practical deployment of these policies in autonomous driving. Designing effective adversarial attacks is an indispensable prerequisite for enhancing the robustness of these policies. In view of this, we present a novel stealthy and efficient adversarial attack method for DRL-based autonomous driving policies. Specifically, we introduce a DRL-based adversary designed to trigger safety violations (e.g., collisions) by injecting adversarial samples at critical moments. We model the attack as a mixed-integer optimization problem and formulate it as a Markov decision process. Then, we train the adversary to learn the optimal policy for attacking at critical moments without domain knowledge. Furthermore, we introduce attack-related information and a trajectory clipping method to enhance the learning capability of the adversary. Finally, we validate our method in an unprotected left-turn scenario across different traffic densities. The experimental results show that our method achieves more than 90% collision rate within three attacks in most cases. Furthermore, our method achieves more than 130% improvement in attack efficiency compared to the unlimited attack method.
Thank you to arXiv for use of its open access interoperability. PaperDance 不是 arXiv 官方产品;中文卡片由大模型生成,请以原文为准。