arXiv:2602.19596cs.CV2026-02中稿 · CVPR被引 4

提出新型自适应攻击框架,暴露协同感知系统安全漏洞。

Learning Mutual View Information Graph for Adaptive Adversarial Collaborative Perception

  • 构建互视信息图统一建模防御系统漏洞知识
  • 攻击成功率下降62%,持续攻击检测率降低47%
  • 适合研究自动驾驶安全与对抗攻击的学者

协同感知(CP)通过联网自动驾驶车辆间的数据共享提升行车安全。然而,现有系统易受对抗攻击,恶意节点通过特征级扰动伪造虚假目标。当前防御依赖阈值一致性验证,但对系统性时序与目标区域优化攻击仍不鲁棒,且会无意泄露防御知识。本文提出MVIG攻击框架,通过统一的互视信息图(MVIG)表示学习不同防御系统的漏洞知识,结合时序图学习生成动态伪造风险图,并采用熵感知漏洞搜索优化攻击位置、时机和持续性,实现跨防御配置的自适应攻击。在OPV2V和Adv-OPV2V数据集上的实验表明,该方法使先进防御成功率下降高达62%,持续攻击下检测率降低47%,推理速度达29.9 FPS,揭示了协同感知系统的重大安全隐患。代码将开源于https://github.com/yihangtao/MVIG.git。

原文摘要 · Abstract (English)

Collaborative perception (CP) enables data sharing among connected and autonomous vehicles (CAVs) to enhance driving safety. However, CP systems are vulnerable to adversarial attacks where malicious agents forge false objects via feature-level perturbations. Current defensive systems use threshold-based consensus verification by comparing collaborative and ego detection results. Yet, these defenses remain vulnerable to more sophisticated attack strategies that could exploit two critical weaknesses: (i) lack of robustness against attacks with systematic timing and target region optimization, and (ii) inadvertent disclosure of vulnerability knowledge through implicit confidence information in shared collaboration data. In this paper, we propose MVIG attack, a novel adaptive adversarial CP framework learning to capture vulnerability knowledge disclosed by different defensive CP systems from a unified mutual view information graph (MVIG) representation. Our approach combines MVIG representation with temporal graph learning to generate evolving fabrication risk maps and employs entropy-aware vulnerability search to optimize attack location, timing and persistence, enabling adaptive attacks with generalizability across various defensive configurations. Extensive evaluations on OPV2V and Adv-OPV2V datasets demonstrate that MVIG attack reduces defense success rates by up to 62\% against state-of-the-art defenses while achieving 47\% lower detection for persistent attacks at 29.9 FPS, exposing critical security gaps in CP systems. Code will be released at https://github.com/yihangtao/MVIG.git

协同感知对抗攻击自动驾驶

Thank you to arXiv for use of its open access interoperability. PaperDance 不是 arXiv 官方产品;中文卡片由大模型生成,请以原文为准。