arXiv:2502.05208cs.CRcs.AI2025-02被引 9

伪装成正常交通标志的对抗攻击可骗过自动驾驶系统,危及行车安全。

Mitigation of Camouflaged Adversarial Attacks in Autonomous Vehicles--A Case Study Using CARLA Simulator

  • 通过修改停车标志纹理生成视觉伪装攻击
  • 实测使自动驾驶刹车延迟,引发安全隐患
  • 方法适用于其他端到端自动驾驶系统

自动驾驶汽车严重依赖摄像头和人工智能进行安全决策。然而,由于人工智能是核心技术,这带来了严峻的网络威胁,阻碍了自动驾驶的大规模应用。因此,分析自动驾驶安全系统对操纵摄像头输入的复杂攻击的鲁棒性至关重要。本文开发了一种针对自动驾驶中交通标志识别(TSR)的相机伪装对抗攻击。具体而言,通过修改停车标志的纹理来欺骗自动驾驶的目标检测系统,进而影响车辆执行器。利用CARLA自动驾驶模拟器测试攻击效果,结果表明此类攻击可导致自动驾驶系统对停车标志的自动制动响应延迟,造成潜在安全风险。我们在多种条件下进行了广泛实验,验证了该攻击的有效性和鲁棒性。此外,本文还提出了相应的缓解策略。所提出的攻击与防御方法可推广至其他端到端训练的自主网络物理系统。

原文摘要 · Abstract (English)

Autonomous vehicles (AVs) rely heavily on cameras and artificial intelligence (AI) to make safe and accurate driving decisions. However, since AI is the core enabling technology, this raises serious cyber threats that hinder the large-scale adoption of AVs. Therefore, it becomes crucial to analyze the resilience of AV security systems against sophisticated attacks that manipulate camera inputs, deceiving AI models. In this paper, we develop camera-camouflaged adversarial attacks targeting traffic sign recognition (TSR) in AVs. Specifically, if the attack is initiated by modifying the texture of a stop sign to fool the AV's object detection system, thereby affecting the AV actuators. The attack's effectiveness is tested using the CARLA AV simulator and the results show that such an attack can delay the auto-braking response to the stop sign, resulting in potential safety issues. We conduct extensive experiments under various conditions, confirming that our new attack is effective and robust. Additionally, we address the attack by presenting mitigation strategies. The proposed attack and defense methods are applicable to other end-to-end trained autonomous cyber-physical systems.

自动驾驶对抗攻击安全防御

Thank you to arXiv for use of its open access interoperability. PaperDance 不是 arXiv 官方产品;中文卡片由大模型生成,请以原文为准。