多人协同动态欺骗,让自动驾驶车突然急停
Dynamic Deception: When Pedestrians Team Up to Fool Autonomous Cars
- 多行人协作移动携带对抗贴纸,增强干扰效果
- 双人协同攻击使车辆急停率达50%,单人攻击全失败
- 揭示感知模型鲁棒性与系统安全间的巨大鸿沟
许多针对自动驾驶感知模型的对抗攻击在实际部署后难以引发系统级失效。主要原因是攻击在系统中(如模拟器内)往往因车辆运动而持续时间短、空间范围小,难以影响车辆行为。本文提出一种系统级攻击:多个动态元素(如两名行人)携带对抗贴纸(如衣物上),通过协调动作和运动放大干扰效果。我们在CARLA模拟器中使用最先进的自动驾驶代理评估该攻击。结果表明,单人攻击在10次实验中全部失败;而两人协同动态攻击可使车辆完全停止,成功率最高达50%;静态协同则无一次成功。这说明系统级失效仅在持续且被协同放大的对抗信号下发生,暴露出模型级鲁棒性与端到端安全性之间的显著差距。
原文摘要 · Abstract (English)
Many adversarial attacks on autonomous-driving perception models fail to cause system-level failures once deployed in a full driving stack. The main reason for such ineffectiveness is that once deployed in a system (e.g., within a simulator), attacks tend to be spatially or temporally short-lived, due to the vehicle's dynamics, hence rarely influencing the vehicle behaviour. In this paper, we address both limitations by introducing a system-level attack in which multiple dynamic elements (e.g., two pedestrians) carry adversarial patches (e.g., on cloths) and jointly amplify their effect through coordination and motion. We evaluate our attacks in the CARLA simulator using a state-of-the-art autonomous driving agent. At the system level, single-pedestrian attacks fail in all runs (out of 10), while dynamic collusion by two pedestrians induces full vehicle stops in up to 50\% of runs, with static collusion yielding no successful attack at all. These results show that system-level failures arise only when adversarial signals persist over time and are amplified through coordinated actors, exposing a gap between model-level robustness and end-to-end safety.
Thank you to arXiv for use of its open access interoperability. PaperDance 不是 arXiv 官方产品;中文卡片由大模型生成,请以原文为准。