arXiv:2506.06563cs.CVcs.CR2025-06被引 1

提出防御交通标志识别模型数据中毒攻击的新方法,显著提升安全性。

Securing Traffic Sign Recognition Systems in Autonomous Vehicles

  • 用非线性数据增强干扰恶意扰动,提升模型鲁棒性。
  • 攻击使识别准确率从99.90%降至10.6%,防御后恢复至96.05%。
  • 可检测人眼无法察觉的中毒数据,检测成功率超99%,适合自动驾驶安全研究者。

深度神经网络(DNN)广泛用于交通标志识别,因其能自动提取图像高层特征。这些DNN在来源未知的大规模数据集上训练,因此确保模型在训练过程中不被篡改或污染至关重要。本文研究了用于交通标志识别的DNN的鲁棒性。首先,通过在训练数据中添加人眼难以察觉的扰动,实施最小化误差攻击,破坏模型性能。随后,提出一种基于数据增强的训练方法以缓解此类攻击,该方法利用非线性变换干扰扰动,提升模型鲁棒性。我们在两个知名交通标志数据集上进行实验,验证了攻击的严重性及所提方法的有效性:攻击使DNN预测准确率从99.90%降至10.6%,而所提方案成功将准确率恢复至96.05%,且优于对抗训练。此外,我们还提出一种检测模型,可在扰动不可见时仍识别中毒数据,检测成功率超过99%。本研究强调需采用先进训练方法,防范交通标志识别系统中的数据投毒攻击。

原文摘要 · Abstract (English)

Deep Neural Networks (DNNs) are widely used for traffic sign recognition because they can automatically extract high-level features from images. These DNNs are trained on large-scale datasets obtained from unknown sources. Therefore, it is important to ensure that the models remain secure and are not compromised or poisoned during training. In this paper, we investigate the robustness of DNNs trained for traffic sign recognition. First, we perform the error-minimizing attacks on DNNs used for traffic sign recognition by adding imperceptible perturbations on training data. Then, we propose a data augmentation-based training method to mitigate the error-minimizing attacks. The proposed training method utilizes nonlinear transformations to disrupt the perturbations and improve the model robustness. We experiment with two well-known traffic sign datasets to demonstrate the severity of the attack and the effectiveness of our mitigation scheme. The error-minimizing attacks reduce the prediction accuracy of the DNNs from 99.90% to 10.6%. However, our mitigation scheme successfully restores the prediction accuracy to 96.05%. Moreover, our approach outperforms adversarial training in mitigating the error-minimizing attacks. Furthermore, we propose a detection model capable of identifying poisoned data even when the perturbations are imperceptible to human inspection. Our detection model achieves a success rate of over 99% in identifying the attack. This research highlights the need to employ advanced training methods for DNNs in traffic sign recognition systems to mitigate the effects of data poisoning attacks.

交通识别数据安全对抗攻击

Thank you to arXiv for use of its open access interoperability. PaperDance 不是 arXiv 官方产品;中文卡片由大模型生成,请以原文为准。