对比三种视觉语言模型在自动驾驶中的抗物理攻击能力,发现均存在严重漏洞。
Comparative Analysis of Patch Attack on VLM-Based Autonomous Driving Architectures
- 采用黑箱优化与语义一致性方法,公平评估三类VLM架构的抗攻击性。
- 所有模型在真实场景中均出现持续多帧失效和关键目标检测性能下降。
- 揭示不同架构的脆弱模式,提醒安全驾驶系统需重视对抗风险。
视觉语言模型正应用于自动驾驶,但其对物理对抗攻击的鲁棒性尚未被探索。本文提出一个系统框架,对三种VLM架构——Dolphins、OmniDrive(Omni-L)和LeapVAD——进行对比对抗评估。通过黑箱优化结合语义同质化方法,在CARLA仿真环境中评估可物理实现的贴纸攻击。结果表明,所有架构均存在严重漏洞,表现为持续多帧失效及关键目标检测性能显著下降。分析揭示了各架构独特的脆弱性模式,证明当前VLM设计在安全关键的自动驾驶应用中未能有效应对对抗威胁。
原文摘要 · Abstract (English)
Vision-language models are emerging for autonomous driving, yet their robustness to physical adversarial attacks remains unexplored. This paper presents a systematic framework for comparative adversarial evaluation across three VLM architectures: Dolphins, OmniDrive (Omni-L), and LeapVAD. Using black-box optimization with semantic homogenization for fair comparison, we evaluate physically realizable patch attacks in CARLA simulation. Results reveal severe vulnerabilities across all architectures, sustained multi-frame failures, and critical object detection degradation. Our analysis exposes distinct architectural vulnerability patterns, demonstrating that current VLM designs inadequately address adversarial threats in safety-critical autonomous driving applications.
Thank you to arXiv for use of its open access interoperability. PaperDance 不是 arXiv 官方产品;中文卡片由大模型生成,请以原文为准。