提出检测自动驾驶视觉攻击的轻量模型AD²,发现系统极易受物理、电磁和数字攻击
AD$^2$: Analysis and Detection of Adversarial Threats in Visual Perception for End-to-End Autonomous Driving Systems
- 基于注意力机制检测视觉输入的时间空间一致性异常
- 在CARLA上使驾驶评分下降最高达99%,暴露严重安全隐患
- 适用于多摄像头自动驾驶系统,兼顾检测精度与计算效率
端到端自动驾驶系统虽取得显著进展,但其对抗鲁棒性仍缺乏深入研究。本文在CARLA平台上对先进自动驾驶代理进行闭环评估,针对视觉感知链路设计三类黑盒攻击:(i) 声波引发的物理模糊攻击,(ii) 电磁干扰导致的图像失真,(iii) 数字域添加鬼影物体的有界扰动攻击。在Transfuser与Interfuser两个先进模型上的实验表明,这些攻击可使驾驶评分最高下降99%,暴露出严重安全风险。为此,我们提出基于注意力机制的轻量级攻击检测模型AD²,通过捕捉时空一致性来识别异常输入。在CARLA多摄像头场景下的全面实验显示,该方法在检测性能和计算效率方面均优于现有方案。
原文摘要 · Abstract (English)
End-to-end autonomous driving systems have achieved significant progress, yet their adversarial robustness remains largely underexplored. In this work, we conduct a closed-loop evaluation of state-of-the-art autonomous driving agents under black-box adversarial threat models in CARLA. Specifically, we consider three representative attack vectors on the visual perception pipeline: (i) a physics-based blur attack induced by acoustic waves, (ii) an electromagnetic interference attack that distorts captured images, and (iii) a digital attack that adds ghost objects as carefully crafted bounded perturbations on images. Our experiments on two advanced agents, Transfuser and Interfuser, reveal severe vulnerabilities to such attacks, with driving scores dropping by up to 99% in the worst case, raising valid safety concerns. To help mitigate such threats, we further propose a lightweight Attack Detection model for Autonomous Driving systems (AD$^2$) based on attention mechanisms that capture spatial-temporal consistency. Comprehensive experiments across multi-camera inputs on CARLA show that our detector achieves superior detection capability and computational efficiency compared to existing approaches.
Thank you to arXiv for use of its open access interoperability. PaperDance 不是 arXiv 官方产品;中文卡片由大模型生成,请以原文为准。