arXiv:2501.02450cs.CV2025-01中稿 · IEEE TDSC被引 12

提出时空感知的防御框架,有效识别自动驾驶中恶意车辆的隐蔽攻击。

GCP: Guarded Collaborative Perception with Spatial-Temporal Aware Malicious Agent Detection

  • 通过置信度加权的空间一致性损失保持单帧感知一致
  • 重建低置信区域历史轨迹流,检测时间异常模式
  • 结合双域检验提升对隐蔽攻击的检测可靠性,适合智能驾驶安全防护

协同感知通过联网自动驾驶车辆间的消息共享显著扩展感知范围,但易受恶意节点的对抗性消息攻击,导致性能严重下降。现有防御方法依赖单帧异常值检测,忽略了消息的时间相关性,难以应对输入与输出空间中细微却有害的扰动。本文揭示一种新型盲区混淆(BAC)攻击,可绕过现有单帧异常检测机制。为此,我们提出GCP框架——基于时空感知的受保护协同感知系统:通过置信度缩放的空间一致性损失维持单帧空间一致性,同时在低置信区域重建历史鸟瞰图运动流以检测时间异常。采用联合时空本杰明-霍希伯格检验融合双域异常结果,实现可靠恶意节点检测。大量实验表明,在多种攻击场景下,GCP相较于最先进的协同感知防御策略,在BAC攻击下最高提升34.69%的[email protected],其他典型攻击下保持稳定5-8%的性能增益。代码将开源于https://github.com/yihangtao/GCP.git。

原文摘要 · Abstract (English)

Collaborative perception significantly enhances autonomous driving safety by extending each vehicle's perception range through message sharing among connected and autonomous vehicles. Unfortunately, it is also vulnerable to adversarial message attacks from malicious agents, resulting in severe performance degradation. While existing defenses employ hypothesis-and-verification frameworks to detect malicious agents based on single-shot outliers, they overlook temporal message correlations, which can be circumvented by subtle yet harmful perturbations in model input and output spaces. This paper reveals a novel blind area confusion (BAC) attack that compromises existing single-shot outlier-based detection methods. As a countermeasure, we propose GCP, a Guarded Collaborative Perception framework based on spatial-temporal aware malicious agent detection, which maintains single-shot spatial consistency through a confidence-scaled spatial concordance loss, while simultaneously examining temporal anomalies by reconstructing historical bird's eye view motion flows in low-confidence regions. We also employ a joint spatial-temporal Benjamini-Hochberg test to synthesize dual-domain anomaly results for reliable malicious agent detection. Extensive experiments demonstrate GCP's superior performance under diverse attack scenarios, achieving up to 34.69% improvements in [email protected] compared to the state-of-the-art CP defense strategies under BAC attacks, while maintaining consistent 5-8% improvements under other typical attacks. Code will be released at https://github.com/yihangtao/GCP.git.

自动驾驶协同感知安全防御时空检测

Thank you to arXiv for use of its open access interoperability. PaperDance 不是 arXiv 官方产品;中文卡片由大模型生成,请以原文为准。