arXiv:2604.23362cs.SEcs.LG2026-04

UniAda可同时干扰自动驾驶的转向和速度,提升攻击效果。

UniAda: Universal Adaptive Multi-objective Adversarial Attack for End-to-End Autonomous Driving Systems

论文配图:UniAda: Universal Adaptive Multi-objective Adversarial Attack for End-to-End Autonomous Driving Systems
图 1 · 摘自论文原文
  • 设计多目标优化函数与自适应权重机制,生成通用扰动。
  • 实测使转向偏差达3.54至29度,速度偏差达11至22 km/h。
  • 适合研究自动驾驶安全或对抗攻击的学者与工程师。

对抗攻击在测试和提升深度学习(DL)系统可靠性方面起着关键作用。现有研究表明,输入的微小扰动可引发错误输出,严重威胁DL系统的安全性,尤其在基于DL的安全关键系统如端到端自动驾驶系统(E2E ADSs)中尤为突出。现有针对E2E ADSs的对抗攻击方法主要关注转向角的异常行为,忽略了速度控制或不可察觉的扰动。为此,我们提出UniAda,一种多目标白盒攻击技术,核心能力是生成与图像无关的对抗扰动,能同时影响转向和速度控制。UniAda利用精心设计的多目标优化函数与自适应权重方案(AWS),实现多种目标的协同优化。在模拟与真实驾驶数据上验证,UniAda在两项指标上优于五种基准方法,平均使转向偏差从3.54度增至29度,速度偏差从11 km/h增至22 km/h。该系统性方法证明了UniAda在现代基于DL的E2E ADSs对抗攻击中的有效性。

原文摘要 · Abstract (English)

Adversarial attacks play a pivotal role in testing and improving the reliability of deep learning (DL) systems. Existing literature has demonstrated that subtle perturbations to the input can elicit erroneous outcomes, thereby substantially compromising the security of DL systems. This has emerged as a critical concern in the development of DL-based safety-critical systems like Autonomous Driving Systems (ADSs). The focus of existing adversarial attack methods on End-to-End (E2E) ADSs has predominantly centered on misbehaviors of steering angle, which overlooks speed-related controls or imperceptible perturbations. To address these challenges, we introduce UniAda, a multi-objective white-box attack technique with a core function that revolves around crafting an image-agnostic adversarial perturbation capable of simultaneously influencing both steering and speed controls. UniAda capitalizes on an intricately designed multi-objective optimization function with the Adaptive Weighting Scheme (AWS), enabling the concurrent optimization of diverse objectives. Validated with both simulated and real-world driving data, UniAda outperforms five benchmarks across two metrics, inducing steering and speed deviations from 3.54 degrees to 29 degrees and 11 km per hour to 22 km per hour on average. This systematic approach establishes UniAda as a proven technique for adversarial attacks on modern DL-based E2E ADSs.

对抗攻击自动驾驶多目标优化

Thank you to arXiv for use of its open access interoperability. PaperDance 不是 arXiv 官方产品;中文卡片由大模型生成,请以原文为准。