arXiv:2508.01062cs.CRcs.CV2025-08被引 4

首个针对车载协同感知的延迟攻击,通过车际通信注入干扰,使处理延迟超90倍。

CP-FREEZER: Latency Attacks against Vehicular Cooperative Perception

  • 利用车联网消息注入对抗扰动,最大化协同感知计算延迟。
  • 实测使单帧处理时间超3秒,成功率100%,延迟提升90倍以上。
  • 揭示了协同感知在时效性上的严重安全隐患,适合安全与自动驾驶研究者关注。

协同感知(CP)通过多智能体间消息交换与融合,提升联网自动驾驶车辆的环境感知能力。尽管已有研究探讨了影响感知准确性的对抗完整性攻击,但对时效性(或可用性)攻击的鲁棒性研究仍不足,而这是自动驾驶中的关键安全需求。本文提出CP-FREEZER,首个通过车际通信(V2V)消息注入对抗扰动以最大化协同感知算法计算延迟的延迟攻击。该攻击克服了点云预处理不可微、受害者输入信息异步获取等独特挑战,并设计了一种新颖的损失函数,有效延长了CP流水线的执行时间。大量实验表明,CP-FREEZER使端到端协同感知延迟增加超过90倍,在真实车载测试平台上实现100%成功率,单帧处理时间突破3秒。研究结果揭示了协同感知系统在可用性方面的重大威胁,凸显构建鲁棒防御机制的紧迫性。

原文摘要 · Abstract (English)

Cooperative perception (CP) enhances situational awareness of connected and autonomous vehicles by exchanging and combining messages from multiple agents. While prior work has explored adversarial integrity attacks that degrade perceptual accuracy, little is known about CP's robustness against attacks on timeliness (or availability), a safety-critical requirement for autonomous driving. In this paper, we present CP-FREEZER, the first latency attack that maximizes the computation delay of CP algorithms by injecting adversarial perturbation via V2V messages. Our attack resolves several unique challenges, including the non-differentiability of point cloud preprocessing, asynchronous knowledge of the victim's input due to transmission delays, and uses a novel loss function that effectively maximizes the execution time of the CP pipeline. Extensive experiments show that CP-FREEZER increases end-to-end CP latency by over $90\times$, pushing per-frame processing time beyond 3 seconds with a 100% success rate on our real-world vehicle testbed. Our findings reveal a critical threat to the availability of CP systems, highlighting the urgent need for robust defenses.

协同感知延迟攻击自动驾驶安全

Thank you to arXiv for use of its open access interoperability. PaperDance 不是 arXiv 官方产品;中文卡片由大模型生成,请以原文为准。