用多源数据融合提升海事自动驾驶系统抗攻击能力
Preventing Adversarial AI Attacks Against Autonomous Situational Awareness: A Maritime Case Study
- 通过多输入数据融合构建防御组件,增强系统鲁棒性
- 对抗攻击下损失降低最高达100%,显著优于单一模型
- 适合关注AI安全的交通、航海系统开发者
对抗性人工智能攻击对依赖AI的自主运输系统(如海上船舶)构成重大威胁。恶意攻击者可利用这些系统欺骗和操控AI决策。本文针对传统防御范围有限、安全度量不足及仅依赖模型级防御的问题,提出数据融合网络安全韧性(DFCR)方法,通过多源输入与数据融合构建防御机制,并设计新型安全度量指标。在真实场景演示与定量分析中,相比单输入模型及现有先进防御模型,采用DFCR的系统在多角度扰动攻击下损失降低35%,对抗补丁攻击和欺骗攻击损失降低100%。实验表明,即使常规防御失效,DFCR及其置信度评分仍能降低系统误判概率,提升决策可靠性。本研究为构建更安全、更具韧性的自主AI系统提供了有效路径。
原文摘要 · Abstract (English)
Adversarial artificial intelligence (AI) attacks pose a significant threat to autonomous transportation, such as maritime vessels, that rely on AI components. Malicious actors can exploit these systems to deceive and manipulate AI-driven operations. This paper addresses three critical research challenges associated with adversarial AI: the limited scope of traditional defences, inadequate security metrics, and the need to build resilience beyond model-level defences. To address these challenges, we propose building defences utilising multiple inputs and data fusion to create defensive components and an AI security metric as a novel approach toward developing more secure AI systems. We name this approach the Data Fusion Cyber Resilience (DFCR) method, and we evaluate it through real-world demonstrations and comprehensive quantitative analyses, comparing a system built with the DFCR method against single-input models and models utilising existing state-of-the-art defences. The findings show that the DFCR approach significantly enhances resilience against adversarial machine learning attacks in maritime autonomous system operations, achieving up to a 35\% reduction in loss for successful multi-pronged perturbation attacks, up to a 100\% reduction in loss for successful adversarial patch attacks and up to 100\% reduction in loss for successful spoofing attacks when using these more resilient systems. We demonstrate how DFCR and DFCR confidence scores can reduce adversarial AI contact confidence and improve decision-making by the system, even when typical adversarial defences have been compromised. Ultimately, this work contributes to the development of more secure and resilient AI-driven systems against adversarial attacks.
Thank you to arXiv for use of its open access interoperability. PaperDance 不是 arXiv 官方产品;中文卡片由大模型生成,请以原文为准。