测试自动驾驶感知系统对对抗攻击的脆弱性,评估多种防御方法效果。
Revisiting Adversarial Perception Attacks and Defense Methods on Autonomous Driving Systems
- 用真实车载系统和YOLO模型测试道路标志与目标检测的对抗攻击
- 发现现有防御方法在复杂攻击下仍有明显局限
- 适合研究自动驾驶安全与鲁棒性的人参考
自动驾驶系统(ADS)越来越多依赖基于深度学习的感知模型,但这些模型仍易受对抗攻击影响。本文重新审视对抗攻击与防御方法,聚焦于道路标志识别和前车检测与预测(如相对距离)。采用二级生产级自动驾驶系统OpenPilot(由Comma.ai提供)及广泛使用的YOLO模型,系统评估了对抗扰动的影响,并检验了包括对抗训练、图像处理、对比学习和扩散模型在内的多种防御技术。实验揭示了这些方法在缓解复杂攻击时的优势与不足。通过针对性的模型鲁棒性评估,旨在深入理解ADS感知系统的漏洞,并为构建更可靠的防御策略提供指导。
原文摘要 · Abstract (English)
Autonomous driving systems (ADS) increasingly rely on deep learning-based perception models, which remain vulnerable to adversarial attacks. In this paper, we revisit adversarial attacks and defense methods, focusing on road sign recognition and lead object detection and prediction (e.g., relative distance). Using a Level-2 production ADS, OpenPilot by Comma$.$ai, and the widely adopted YOLO model, we systematically examine the impact of adversarial perturbations and assess defense techniques, including adversarial training, image processing, contrastive learning, and diffusion models. Our experiments highlight both the strengths and limitations of these methods in mitigating complex attacks. Through targeted evaluations of model robustness, we aim to provide deeper insights into the vulnerabilities of ADS perception systems and contribute guidance for developing more resilient defense strategies.
Thank you to arXiv for use of its open access interoperability. PaperDance 不是 arXiv 官方产品;中文卡片由大模型生成,请以原文为准。