用可变显示车骗自动驾驶汽车长期偏离路线,不撞车却能劫持目的地。
Beyond Crash: Hijacking Your Autonomous Vehicle for Fun and Profit
- 将攻击视为闭环控制,用动态贴图作为转向指令实时调整。
- 在仿真和真实场景中实现高成功率劫持,使车辆驶向指定地点。
- 适合研究自动驾驶安全与对抗样本的学者或工程师参考。
自动驾驶汽车(AV)尤其是基于视觉的系统正快速部署且无需人工干预。由于其运行于安全关键环境,理解其在对抗性条件下的鲁棒性至关重要。以往针对视觉自动驾驶的物理对抗攻击主要引发即时安全事故(如碰撞、违规或短暂偏离车道),通过制造短暂感知或控制错误实现。本文揭示了一种质的不同风险:长期路线完整性破坏,即攻击者逐步引导目标车辆偏离原定路线,驶向攻击者选定的目的地,而车辆仍看似正常行驶。这虽不对车辆本身造成直接危险,但可能危及车内乘客安全,因他们难以察觉路径变化。本文提出首个对抗框架JackZebra,利用一辆装有可重构显示屏和后置摄像头的攻击车辆,对基于视觉的端到端驾驶系统实施路线级劫持。核心挑战在于时间持续性:对抗影响需在视角、光照、天气、交通及目标车辆持续重规划的变化下保持有效,且不触发明显故障。关键洞察是将路线劫持视为闭环控制问题,并将对抗贴图转化为可在线根据目标行为反馈调整的转向基元。在仿真与真实场景中的评估表明,JackZebra能以高成功率使目标车辆偏离原路线并停靠至攻击者指定位置。
原文摘要 · Abstract (English)
Autonomous Vehicles (AVs), especially vision-based AVs, are rapidly being deployed without human operators. As AVs operate in safety-critical environments, understanding their robustness in an adversarial environment is an important research problem. Prior physical adversarial attacks on vision-based autonomous vehicles predominantly target immediate safety failures (e.g., a crash, a traffic-rule violation, or a transient lane departure) by inducing a short-lived perception or control error. This paper shows a qualitatively different risk: a long-horizon route integrity compromise, where an attacker gradually steers a victim AV away from its intended route and into an attacker-chosen destination while the victim continues to drive ``normally.'' This will not pose a danger to the victim vehicle itself, but also to potential passengers sitting inside the vehicle, who may not notice the route changes. In this paper, we design and implement the first adversarial framework, called JackZebra, which performs route-level hijacking of a vision-based end-to-end driving stack using a physically plausible attacker vehicle with a reconfigurable display and a camera sensor mounted on the rear. The central challenge is temporal persistence: adversarial influence must remain effective in changing viewpoints, lighting, weather, traffic, and the victim's continual replanning -- without triggering conspicuous failures. Our key insight is to treat route hijacking as a closed-loop control problem and to convert adversarial patches into steering primitives that can be selected online via an interactive adjustment loop based on observed victim behavior using the rear camera. Our evaluations in both simulated and real-world scenarios show that JackZebra can successfully hijack victim vehicles to deviate from original routes and stop at places designated by the adversary with a high success rate.
Thank you to arXiv for use of its open access interoperability. PaperDance 不是 arXiv 官方产品;中文卡片由大模型生成,请以原文为准。