arXiv:2501.05239cs.CRcs.CV2025-01AAAI被引 8

揭示电磁攻击如何骗过自动驾驶摄像头,提出仿真测试方案

Is Your Autonomous Vehicle Safe? Understanding the Threat of Electromagnetic Signal Injection Attacks on Traffic Scene Perception

  • 构建电磁信号注入攻击仿真方法,生成真实场景数据
  • 发现多种感知模型在攻击下准确率下降超60%
  • 为车载AI安全评估提供可复现的测试框架,适合安全研究者

自动驾驶车辆依赖基于摄像头的感知系统理解行驶环境并做出关键决策,确保安全行驶。然而,电磁信号注入攻击(ESIA)可扭曲摄像头捕获的图像,导致AI误判,威胁车辆安全。尽管后果严重,现有研究对ESIA在复杂驾驶场景中对AI模型鲁棒性的影响了解有限。为此,本文分析了多种模型在ESIA下的表现,揭示其脆弱性;由于真实攻击数据难以获取,我们开发了一种新型ESIA仿真方法,生成涵盖多种驾驶场景的模拟攻击数据集。研究构建了完整的仿真与评估框架,旨在推动更鲁棒的AI模型和安全智能系统的发展,助力提升多领域技术的安全性与可靠性。

原文摘要 · Abstract (English)

Autonomous vehicles rely on camera-based perception systems to comprehend their driving environment and make crucial decisions, thereby ensuring vehicles to steer safely. However, a significant threat known as Electromagnetic Signal Injection Attacks (ESIA) can distort the images captured by these cameras, leading to incorrect AI decisions and potentially compromising the safety of autonomous vehicles. Despite the serious implications of ESIA, there is limited understanding of its impacts on the robustness of AI models across various and complex driving scenarios. To address this gap, our research analyzes the performance of different models under ESIA, revealing their vulnerabilities to the attacks. Moreover, due to the challenges in obtaining real-world attack data, we develop a novel ESIA simulation method and generate a simulated attack dataset for different driving scenarios. Our research provides a comprehensive simulation and evaluation framework, aiming to enhance the development of more robust AI models and secure intelligent systems, ultimately contributing to the advancement of safer and more reliable technology across various fields.

自动驾驶安全攻击仿真测试

Thank you to arXiv for use of its open access interoperability. PaperDance 不是 arXiv 官方产品;中文卡片由大模型生成,请以原文为准。