arXiv:2504.03089cs.CV2025-04被引 2

用少量点注入攻击激光雷达导航系统,破坏定位与建图却保持扫描质量。

SLACK: Attacking LiDAR-based SLAM with Adversarial Point Injections

  • 设计生成式对抗模型,通过注入少量点干扰激光雷达SLAM
  • 在KITTI和CARLA-64数据集上优于现有基线,保持扫描质量
  • 揭示学习型激光雷达系统的安全漏洞,适合安全与自动驾驶研究者

基于学习的激光雷达方法在自动驾驶中的广泛应用使其易受对抗性点注入(PiJ)攻击,严重威胁导航与地图生成安全。目前尚无针对基于学习的激光雷达SLAM的系统性攻击研究。本文提出SLACK,一种端到端深度生成对抗模型,可在不降低激光雷达扫描质量的前提下,实现多点注入攻击。为支持SLACK,我们设计了一种新型简单自编码器,结合分割注意力增强对比学习,提升重建精度。SLACK在KITTI和CARLA-64数据集上显著优于最优基线,在仅使用少量点的情况下成功实施了点注入攻击,导致导航与地图质量严重下降,但激光雷达扫描本身未受损。

原文摘要 · Abstract (English)

The widespread adoption of learning-based methods for the LiDAR makes autonomous vehicles vulnerable to adversarial attacks through adversarial \textit{point injections (PiJ)}. It poses serious security challenges for navigation and map generation. Despite its critical nature, no major work exists that studies learning-based attacks on LiDAR-based SLAM. Our work proposes SLACK, an end-to-end deep generative adversarial model to attack LiDAR scans with several point injections without deteriorating LiDAR quality. To facilitate SLACK, we design a novel yet simple autoencoder that augments contrastive learning with segmentation-based attention for precise reconstructions. SLACK demonstrates superior performance on the task of \textit{point injections (PiJ)} compared to the best baselines on KITTI and CARLA-64 dataset while maintaining accurate scan quality. We qualitatively and quantitatively demonstrate PiJ attacks using a fraction of LiDAR points. It severely degrades navigation and map quality without deteriorating the LiDAR scan quality.

激光雷达对抗攻击自动驾驶安全

Thank you to arXiv for use of its open access interoperability. PaperDance 不是 arXiv 官方产品;中文卡片由大模型生成,请以原文为准。