arXiv:2507.06907cs.LGcs.SE2025-07

用多重模型加安全加权投票提升交通标志识别抗攻击能力

Robust and Safe Traffic Sign Recognition using N-version with Weighted Voting

  • 多模型集成并用FMEA动态分配安全权重
  • 对抗攻击下识别准确率提升显著,优于传统投票机制
  • 适合自动驾驶系统安全验证与高可靠性场景

自动驾驶正快速发展,但系统安全性仍是关键挑战。交通标志识别作为自动驾驶核心组件,易受对抗攻击影响。本文提出一种基于失效模式与影响分析(FMEA)的三版本机器学习(NVML)框架,引入安全感知加权软投票机制。通过评估潜在风险为集成输出动态分配安全权重。在使用快速梯度符号法(FGSM)和投影梯度下降(PGD)生成的对抗样本上测试,结果表明该方法显著提升了交通标志识别在对抗条件下的鲁棒性与安全性。

原文摘要 · Abstract (English)

Autonomous driving is rapidly advancing as a key application of machine learning, yet ensuring the safety of these systems remains a critical challenge. Traffic sign recognition, an essential component of autonomous vehicles, is particularly vulnerable to adversarial attacks that can compromise driving safety. In this paper, we propose an N-version machine learning (NVML) framework that integrates a safety-aware weighted soft voting mechanism. Our approach utilizes Failure Mode and Effects Analysis (FMEA) to assess potential safety risks and assign dynamic, safety-aware weights to the ensemble outputs. We evaluate the robustness of three-version NVML systems employing various voting mechanisms against adversarial samples generated using the Fast Gradient Sign Method (FGSM) and Projected Gradient Descent (PGD) attacks. Experimental results demonstrate that our NVML approach significantly enhances the robustness and safety of traffic sign recognition systems under adversarial conditions.

自动驾驶安全识别对抗防御

Thank you to arXiv for use of its open access interoperability. PaperDance 不是 arXiv 官方产品;中文卡片由大模型生成,请以原文为准。