arXiv:2605.12743cs.CRcs.CV2026-05

用静态伪装利用视角变化诱导自动驾驶误判轨迹,导致急刹。

Still Camouflage, Moving Illusion: View-Induced Trajectory Manipulation in Autonomous Driving

论文配图:Still Camouflage, Moving Illusion: View-Induced Trajectory Manipulation in Autonomous Driving
图 1 · 摘自论文原文
  • 静态伪装随视角变化自然演化,触发持续特征偏移
  • 在nuScenes上实现87.5%急刹成功率,跨场景鲁棒
  • 无需多视角优化或主动干预,部署简单

现有视觉感知的物理对抗攻击通过复杂贴纸或动态变化的图案,在不同时间引发感知误差,如目标追踪偏差或轨迹预测错误。这类方法将视角变化视为挑战,需对抗贴纸在多视角下保持有效性,导致复杂的多视角优化。本文提出新思路:将视角变化本身作为攻击工具。设计一种静态被动对抗伪装,安装于车辆上,其外观随相对运动自然变化,引起帧间一致的特征漂移,使系统推断出看似合理但错误的轨迹(如假变道),并传播至下游决策,引发不必要的紧急制动。与以往需多视角鲁棒性或主动干预的方法不同,本攻击源于正常驾驶动态,部署简便:停放车辆上的自然伪装即可诱发经过的自动驾驶车辆急刹。在nuScenes数据集上验证,端到端成功率达87.5%(以急刹事件衡量),且对不同场景背景、目标车速和感知模型均具鲁棒性。

原文摘要 · Abstract (English)

Existing physical adversarial attacks on vision-based autonomous driving induce time-evolving perception errors, including biased object tracking or trajectory prediction, through (i) sophisticated physical patch inducing detection box drift when entering the view distance, or (ii) dynamically changing patches that cause different perception errors at different time. In both cases, viewing-angle variation is treated as a challenge, requiring adversarial patches to remain effective across frames under varying views, leading to complex multi-view optimization. In contrast, we show that viewing-angle variation itself can be turned into an attack tool. We design a new attack paradigm where a static, passive adversarial camouflage is mounted on a vehicle whose view-dependent appearance naturally evolves with relative motion, inducing consistent feature drift across frames. This causes the system to infer a physically plausible but incorrect trajectory, such as a false cut-in, which propagates to downstream decision-making and triggers unnecessary braking. Unlike prior approaches that require multi-view robustness or active intervention, our attack emerges from normal driving dynamics and is easy to deploy: a parked vehicle with a natural camouflage can induce hard braking in passing autonomous vehicles. We demonstrate the novel attack on nuScenes dataset, showing the effectiveness with an end-to-end success rate of up to 87.5%, measured by hard-braking events, and robustness across different scene backgrounds, victim vehicle speeds, and perception models.

对抗攻击自动驾驶轨迹欺骗伪装

Thank you to arXiv for use of its open access interoperability. PaperDance 不是 arXiv 官方产品;中文卡片由大模型生成,请以原文为准。