arXiv:2603.14124cs.CReess.IV2026-03

通过实测发现自动驾驶平台攻击有可区分的特征指纹。

Experimental Evaluation of Security Attacks on Self-Driving Car Platforms

  • 在真实硬件上测试五类攻击,分析控制偏差、计算开销和响应速度。
  • 不同攻击产生独特行为模式,如对抗攻击导致转向偏移但计算负担小。
  • 指纹框架适用于数字与环境攻击,可用于防御系统设计。

基于深度学习的自动驾驶感知系统易受对抗干扰和网络层破坏影响。本文在低成本自动驾驶平台(JetRacer 和 Yahboom)上开展系统性硬件实验,评估五类攻击:FGSM、PGD、中间人(MitM)、拒绝服务(DoS)及假目标攻击。采用标准化13秒实验协议与全面自动化日志记录,系统分析攻击在三个维度的表现:(i) 控制偏差,(ii) 计算成本,(iii) 运行时响应性。结果表明,各类攻击在这些维度上呈现出一致且可分离的“指纹”特征:感知类攻击(MitM输出篡改与假目标投影)产生显著转向偏差,但计算开销低;PGD攻击则同时引发转向扰动与多重维度的计算负载;DoS攻击表现为帧率下降与延迟增加,但对控制平面影响极小。本研究证明,该指纹框架在数字攻击(对抗扰动、网络操纵)与环境攻击(投影虚假特征)之间具有泛化能力,为构建感知攻击的监测系统与基于签名的针对性防御机制提供了基础。

原文摘要 · Abstract (English)

Deep learning-based perception pipelines in autonomous ground vehicles are vulnerable to both adversarial manipulation and network-layer disruption. We present a systematic, on-hardware experimental evaluation of five attack classes: FGSM, PGD, man-in-the-middle (MitM), denial-of-service (DoS), and phantom attacks on low-cost autonomous vehicle platforms (JetRacer and Yahboom). Using a standardized 13-second experimental protocol and comprehensive automated logging, we systematically characterize three dimensions of attack behavior:(i) control deviation, (ii) computational cost, and (iii) runtime responsiveness. Our analysis reveals that distinct attack classes produce consistent and separable "fingerprints" across these dimensions: perception attacks (MitM output manipulation and phantom projection) generate high steering deviation signatures with nominal computational overhead, PGD produces combined steering perturbation and computational load signatures across multiple dimensions, and DoS exhibits frame rate and latency degradation signatures with minimal control-plane perturbation. We demonstrate that our fingerprinting framework generalizes across both digital attacks (adversarial perturbations, network manipulation) and environmental attacks (projected false features), providing a foundation for attack-aware monitoring systems and targeted, signature-based defense mechanisms.

自动驾驶安全对抗攻击指纹识别硬件验证

Thank you to arXiv for use of its open access interoperability. PaperDance 不是 arXiv 官方产品;中文卡片由大模型生成,请以原文为准。