arXiv:2512.19711cs.CVcs.AI2025-12

用变形艺术制造车辆感知欺骗,90%成功率且难被发现。

PHANTOM: PHysical ANamorphic Threats Obstructing Connected Vehicle Mobility

  • 用变形艺术生成视角依赖的对抗样本,骗过主流检测器。
  • 在最优条件下攻击成功率超90%,恶劣环境仍保持60%-80%有效。
  • 可引发全网通信混乱,适合研究自动驾驶安全的学者看。

联网自动驾驶汽车(CAVs)依赖基于视觉的深度神经网络(DNN)和低延迟车联万物(V2X)通信实现安全高效行驶。尽管技术进步显著,此类系统仍易受物理对抗攻击影响。本文提出PHANTOM(PHysical ANamorphic Threats Obstructing connected vehicle Mobility),一种利用变形艺术生成并部署视角依赖对抗样本的新框架。该方法通过人眼看似自然的几何畸变,使先进目标检测器以高置信度误判。与传统攻击不同,PHANTOM在无需模型访问的黑盒环境下运行,对四种不同检测器架构(YOLOv5、SSD、Faster R-CNN、RetinaNet)表现出强迁移性。在CARLA平台上的全面评估显示,最优条件下攻击成功率超过90%,恶劣环境仍维持60%-80%有效性。攻击在距离目标6-10米内激活,留给车辆避让时间不足。更严重的是,该攻击不仅欺骗单个车辆,还引发整个CAV系统的网络级扰动:SUMO-OMNeT++共仿真表明,虚假紧急消息经由V2X链路传播,导致信息年龄峰值上升68%-89%,严重削弱安全关键通信。这些发现揭示了CAV生态中感知与通信双层的关键漏洞。

原文摘要 · Abstract (English)

Connected autonomous vehicles (CAVs) rely on vision-based deep neural networks (DNNs) and low-latency (Vehicle-to-Everything) V2X communication to navigate safely and efficiently. Despite their advances, these systems remain vulnerable to physical adversarial attacks. In this paper, we introduce PHANTOM (PHysical ANamorphic Threats Obstructing connected vehicle Mobility), a novel framework for crafting and deploying perspective-dependent adversarial examples using \textit{anamorphic art}. PHANTOM exploits geometric distortions that appear natural to humans but are misclassified with high confidence by state-of-the-art object detectors. Unlike conventional attacks, PHANTOM operates in black-box settings without model access and demonstrates strong transferability across four diverse detector architectures (YOLOv5, SSD, Faster R-CNN, and RetinaNet). Comprehensive evaluation in CARLA across varying speeds, weather conditions, and lighting scenarios shows that PHANTOM achieves over 90\% attack success rate under optimal conditions and maintains 60-80\% effectiveness even in degraded environments. The attack activates within 6-10 meters of the target, providing insufficient time for safe maneuvering. Beyond individual vehicle deception, PHANTOM triggers network-wide disruption in CAV systems: SUMO-OMNeT++ co-simulation demonstrates that false emergency messages propagate through V2X links, increasing Peak Age of Information by 68-89\% and degrading safety-critical communication. These findings expose critical vulnerabilities in both perception and communication layers of CAV ecosystems.

自动驾驶对抗攻击安全威胁车联网

Thank you to arXiv for use of its open access interoperability. PaperDance 不是 arXiv 官方产品;中文卡片由大模型生成,请以原文为准。