arXiv:2503.17168cs.CVcs.LG2025-03被引 2

提出分层对抗扰动系统,量化6种激光雷达目标检测模型的鲁棒性。

Hi-ALPS -- An Experimental Robustness Quantification of Six LiDAR-based Object Detection Systems for Autonomous Driving

  • 构建分层级对抗扰动体系,逐步提升扰动强度测试模型鲁棒性。
  • 实验表明所有6种模型均无法通过全部扰动层级,且扰动后人类仍可识别物体。
  • 为提升鲁棒性提供新思路,适合自动驾驶安全评估研究者参考。

激光雷达是自动驾驶的关键传感器,可捕捉高分辨率三维数据。三维目标检测系统(OD)负责解析点云数据,直接影响车辆决策。因此,这类系统必须对各类扰动具备鲁棒性,需进行充分测试。一种方法是使用对抗样本——在输入数据中施加微小但精心设计的扰动,使检测结果被误导。然而,仅靠对抗样本难以准确量化模型鲁棒性,因为若模型易受攻击,可能是模型本身脆弱,也可能是攻击算法过于强大。本文提出Hi-ALPS(分层对抗式激光雷达扰动等级系统),要求模型在逐级增强的扰动下仍能保持正确输出。该系统依次结合启发式策略与主流对抗攻击方法。通过一系列全面实验,我们量化了六种先进3D OD在不同扰动类型下的表现。结果表明,没有任何一种模型能在所有级别上保持鲁棒;一个重要因素是:尽管模型失效,人类观察者仍可正确识别被扰动物体,因扰动本身较小。为提升模型鲁棒性,我们讨论了现有防御措施的适用性,并基于实验结果提出了新的防御建议。

原文摘要 · Abstract (English)

Light Detection and Ranging (LiDAR) is an essential sensor technology for autonomous driving as it can capture high-resolution 3D data. As 3D object detection systems (OD) can interpret such point cloud data, they play a key role in the driving decisions of autonomous vehicles. Consequently, such 3D OD must be robust against all types of perturbations and must therefore be extensively tested. One approach is the use of adversarial examples, which are small, sometimes sophisticated perturbations in the input data that change, i.e., falsify, the prediction of the OD. These perturbations are carefully designed based on the weaknesses of the OD. The robustness of the OD cannot be quantified with adversarial examples in general, because if the OD is vulnerable to a given attack, it is unclear whether this is due to the robustness of the OD or whether the attack algorithm produces particularly strong adversarial examples. The contribution of this work is Hi-ALPS -- Hierarchical Adversarial-example-based LiDAR Perturbation Level System, where higher robustness of the OD is required to withstand the perturbations as the perturbation levels increase. In doing so, the Hi-ALPS levels successively implement a heuristic followed by established adversarial example approaches. In a series of comprehensive experiments using Hi-ALPS, we quantify the robustness of six state-of-the-art 3D OD under different types of perturbations. The results of the experiments show that none of the OD is robust against all Hi-ALPS levels; an important factor for the ranking is that human observers can still correctly recognize the perturbed objects, as the respective perturbations are small. To increase the robustness of the OD, we discuss the applicability of state-of-the-art countermeasures. In addition, we derive further suggestions for countermeasures based on our experimental results.

激光雷达目标检测鲁棒性对抗攻击

Thank you to arXiv for use of its open access interoperability. PaperDance 不是 arXiv 官方产品;中文卡片由大模型生成,请以原文为准。