arXiv:2508.19290cs.CVcs.AI2025-08

针对2D激光雷达分割设计轻量级抗对抗攻击净化框架

Efficient Model-Based Purification Against Adversarial Attacks for LiDAR Segmentation

  • 在二维距离图域直接建模攻击,优化防御策略
  • 计算开销极小,仍保持强对抗鲁棒性
  • 适合真实自动驾驶场景部署,效果优于生成式方法

基于激光雷达的语义分割对自动驾驶感知至关重要,但现代分割网络极易受到对抗攻击威胁。现有多数防御方法针对原始3D点云网络,依赖大型计算密集型生成模型。然而,许多先进激光雷达分割流程采用更高效的二维距离图表示。尽管广泛应用,该领域缺乏轻量级专用对抗防御。本文提出一种面向二维距离图激光雷达分割的高效模型驱动净化框架,首次在距离图域构建直接攻击形式,并设计基于数学可解释优化问题的净化网络,在极低计算开销下实现强对抗鲁棒性。在公开基准上性能表现优异,持续优于生成式与对抗训练基线。更重要的是,实车测试验证了该框架在实际自动驾驶场景中仍能保持高精度运行。

原文摘要 · Abstract (English)

LiDAR-based segmentation is essential for reliable perception in autonomous vehicles, yet modern segmentation networks are highly susceptible to adversarial attacks that can compromise safety. Most existing defenses are designed for networks operating directly on raw 3D point clouds and rely on large, computationally intensive generative models. However, many state-of-the-art LiDAR segmentation pipelines operate on more efficient 2D range view representations. Despite their widespread adoption, dedicated lightweight adversarial defenses for this domain remain largely unexplored. We introduce an efficient model-based purification framework tailored for adversarial defense in 2D range-view LiDAR segmentation. We propose a direct attack formulation in the range-view domain and develop an explainable purification network based on a mathematical justified optimization problem, achieving strong adversarial resilience with minimal computational overhead. Our method achieves competitive performance on open benchmarks, consistently outperforming generative and adversarial training baselines. More importantly, real-world deployment on a demo vehicle demonstrates the framework's ability to deliver accurate operation in practical autonomous driving scenarios.

激光雷达对抗防御轻量化自动驾驶

Thank you to arXiv for use of its open access interoperability. PaperDance 不是 arXiv 官方产品;中文卡片由大模型生成,请以原文为准。