给自动驾驶视觉语言模型植入自然反光后门,触发时响应延迟严重
Natural Reflection Backdoor Attack on Vision Language Model for Autonomous Driving
- 用玻璃水面反光图案+冗长文本前缀训练模型产生延迟响应
- 触发时推理延迟显著增加,清洁数据下性能正常
- 揭示实时系统安全漏洞,适合关注AI安防的研究者
视觉语言模型(VLM)被集成到自动驾驶系统中,以通过视觉问答(VQA)等任务提升推理能力。然而,这些系统对后门攻击的鲁棒性仍缺乏研究。本文提出一种基于自然反射的后门攻击,针对自动驾驶场景中的VLM系统,旨在当特定视觉触发器出现时引发显著响应延迟。我们在DriveLM数据集的子集图像中嵌入微弱反射模式(模拟玻璃或水面),同时在对应文本标签前添加冗长无关前缀(如虚构故事或系统更新通知)。该策略使模型在遇到触发器时生成异常长的响应。我们使用参数高效方法微调了两种前沿VLM模型:Qwen2-VL和LLaMA-Adapter。实验表明,模型在干净输入上保持正常性能,但触发时推理延迟显著增加,可能在真实自动驾驶中导致危险决策延迟。进一步分析考察了中毒率、摄像头视角及跨视角迁移性等因素。研究揭示了一类新型攻击,利用自动驾驶系统的严格实时性要求,对增强型VLM驱动系统的安全与可靠性构成严峻挑战。
原文摘要 · Abstract (English)
Vision-Language Models (VLMs) have been integrated into autonomous driving systems to enhance reasoning capabilities through tasks such as Visual Question Answering (VQA). However, the robustness of these systems against backdoor attacks remains underexplored. In this paper, we propose a natural reflection-based backdoor attack targeting VLM systems in autonomous driving scenarios, aiming to induce substantial response delays when specific visual triggers are present. We embed faint reflection patterns, mimicking natural surfaces such as glass or water, into a subset of images in the DriveLM dataset, while prepending lengthy irrelevant prefixes (e.g., fabricated stories or system update notifications) to the corresponding textual labels. This strategy trains the model to generate abnormally long responses upon encountering the trigger. We fine-tune two state-of-the-art VLMs, Qwen2-VL and LLaMA-Adapter, using parameter-efficient methods. Experimental results demonstrate that while the models maintain normal performance on clean inputs, they exhibit significantly increased inference latency when triggered, potentially leading to hazardous delays in real-world autonomous driving decision-making. Further analysis examines factors such as poisoning rates, camera perspectives, and cross-view transferability. Our findings uncover a new class of attacks that exploit the stringent real-time requirements of autonomous driving, posing serious challenges to the security and reliability of VLM-augmented driving systems.
Thank you to arXiv for use of its open access interoperability. PaperDance 不是 arXiv 官方产品;中文卡片由大模型生成,请以原文为准。