arXiv:2603.08498cs.CV2026-03中稿 · CVPR

提出一种无需可信车辆的高效防御方法,利用前后帧差异识别恶意车辆。

All Vehicles Can Lie: Efficient Adversarial Defense in Fully Untrusted-Vehicle Collaborative Perception via Pseudo-Random Bayesian Inference

  • 基于前后帧感知差异,动态参考上一帧可靠信息
  • 每帧仅需2.5次验证,恢复攻击后检测精度至原水平的79.4%~86.9%
  • 适用于无信任假设的真实车联网场景,适合自动驾驶系统部署

协同感知(CP)使多车通过交换特征级传感数据增强各自感知能力。然而,该融合机制在完全不可信车辆环境中极易受对抗攻击。现有防御方法常依赖可信自车作为参考或引入额外二分类器,限制了其在真实场景中的实用性,因自车可信性存疑、实时检测需求及跨场景泛化要求。为此,本文提出首个面向全不可信车辆协同感知的高效防御框架——伪随机贝叶斯推断(PRBI)。PRBI通过利用时间感知差异检测对抗行为,以先前帧的可靠感知作为动态参考。同时采用伪随机分组策略,每帧仅需两次验证,并结合贝叶斯推断估计恶意车辆的数量与身份。理论分析证明了框架的收敛性与稳定性。大量实验表明,PRBI平均每帧仅需2.5次验证,显著优于现有方法,且将检测精度恢复至攻击前水平的79.4%至86.9%。

原文摘要 · Abstract (English)

Collaborative perception (CP) enables multiple vehicles to augment their individual perception capacities through the exchange of feature-level sensory data. However, this fusion mechanism is inherently vulnerable to adversarial attacks, especially in fully untrusted-vehicle environments. Existing defense approaches often assume a trusted ego vehicle as a reference or incorporate additional binary classifiers. These assumptions limit their practicality in real-world deployments due to the questionable trustworthiness of ego vehicles, the requirement for real-time detection, and the need for generalizability across diverse scenarios. To address these challenges, we propose a novel Pseudo-Random Bayesian Inference (PRBI) framework, a first efficient defense method tailored for fully untrusted-vehicle CP. PRBI detects adversarial behavior by leveraging temporal perceptual discrepancies, using the reliable perception from the preceding frame as a dynamic reference. Additionally, it employs a pseudo-random grouping strategy that requires only two verifications per frame, while applying Bayesian inference to estimate both the number and identities of malicious vehicles. Theoretical analysis has proven the convergence and stability of the proposed PRBI framework. Extensive experiments show that PRBI requires only 2.5 verifications per frame on average, outperforming existing methods significantly, and restores detection precision to between 79.4% and 86.9% of pre-attack levels.

协同感知对抗防御车联网贝叶斯推理

Thank you to arXiv for use of its open access interoperability. PaperDance 不是 arXiv 官方产品;中文卡片由大模型生成,请以原文为准。