提出防御视觉定位攻击的检测机制,提升机器人导航安全性
Adversarial Attacks and Detection in Visual Place Recognition for Safer Robot Navigation
- 设计新型对抗攻击检测模块,与导航系统闭环联动
- 检测准确率75%时,定位误差降低约50%
- 首次分析FGSM攻击在视觉定位中的影响,适合安全关键场景研究
独立的视觉定位(VPR)系统对精心设计的对抗攻击缺乏防御能力,部署于机器人导航时可能引发灾难性后果。本文系统分析了四种常见感知任务中的对抗攻击及四种新型专用于VPR的攻击对定位性能的影响。提出通过将VPR、对抗攻击检测器(AAD)与主动导航决策闭环连接的新实验范式,验证了模拟AAD在性能上的提升效果。结果显示,在检测准确率为75%、误报率最高达25%的情况下,平均沿轨迹定位误差可减少约50%。评估指标包括沿轨迹误差、受攻击时间占比、处于‘不安全’状态的时间占比以及连续受攻击最长时间。进一步首次研究了快速梯度符号法(FGSM)攻击在VPR中的有效性。本工作强调了真实系统中部署AAD的必要性,并为系统设计提供了量化要求。
原文摘要 · Abstract (English)
Stand-alone Visual Place Recognition (VPR) systems have little defence against a well-designed adversarial attack, which can lead to disastrous consequences when deployed for robot navigation. This paper extensively analyzes the effect of four adversarial attacks common in other perception tasks and four novel VPR-specific attacks on VPR localization performance. We then propose how to close the loop between VPR, an Adversarial Attack Detector (AAD), and active navigation decisions by demonstrating the performance benefit of simulated AADs in a novel experiment paradigm -- which we detail for the robotics community to use as a system framework. In the proposed experiment paradigm, we see the addition of AADs across a range of detection accuracies can improve performance over baseline; demonstrating a significant improvement -- such as a ~50% reduction in the mean along-track localization error -- can be achieved with True Positive and False Positive detection rates of only 75% and up to 25% respectively. We examine a variety of metrics including: Along-Track Error, Percentage of Time Attacked, Percentage of Time in an `Unsafe' State, and Longest Continuous Time Under Attack. Expanding further on these results, we provide the first investigation into the efficacy of the Fast Gradient Sign Method (FGSM) adversarial attack for VPR. The analysis in this work highlights the need for AADs in real-world systems for trustworthy navigation, and informs quantitative requirements for system design.
Thank you to arXiv for use of its open access interoperability. PaperDance 不是 arXiv 官方产品;中文卡片由大模型生成,请以原文为准。