arXiv:2605.14396cs.CVcs.CR2026-05被引 1

用扩散模型发现真实环境中的语义攻击,让自动驾驶地图出错却难被防御。

Systematic Discovery of Semantic Attacks in Online Map Construction through Conditional Diffusion

论文配图:Systematic Discovery of Semantic Attacks in Online Map Construction through Conditional Diffusion
图 1 · 摘自论文原文
  • 基于扩散模型潜空间搜索合法环境变异,生成误导地图的语义扰动。
  • 攻击使车道检测率下降57.7%,96%路径规划被破坏,且能注入虚假边界。
  • 生成内容真实度高(80%-84%通过评估),现有防御手段无效,适合安全研究者参考。

自动驾驶依赖在线高精地图感知车道线、分隔带和人行横道等关键道路元素,直接影响运动规划安全。现有像素级扰动攻击可被标准对抗防御抵消。本文提出MIRAGE框架,系统性发现可绕过防御的语义攻击,通过寻找与真实场景拓扑一致但语义变异的合理环境变化(如阴影、湿滑路面)来干扰地图生成。MIRAGE利用扩散模型学习的真实世界数据潜流形,搜索邻近真实场景的语义扰动样本,使地图预测错误。在nuScenes数据集上验证,实现两种攻击:(1) 边界移除,使检测率下降57.7%,96%轨迹被污染;(2) 边界注入,唯一成功引入虚构边界的方案,而像素级PGD和AdvPatch完全失败。两种攻击在多种对抗防御下仍有效。通过两个独立的VLM判别器评估真实性,MIRAGE生成结果80–84%被判定为真实(对比干净nuScenes的97–99%),而AdvPatch仅0–9%。研究揭示当前对抗防御存在根本性缺口:以合法环境变化形式出现的语义扰动远比像素级扰动更难防御。

原文摘要 · Abstract (English)

Autonomous vehicles depend on online HD map construction to perceive lane boundaries, dividers, and pedestrian crossings -- safety-critical road elements that directly govern motion planning. While existing pixel perturbation attacks can disrupt the mapping, they can be neutralized by standard adversarial defenses. We present MIRAGE, a framework for systematic discovery of semantic attacks that bypass adversarial defenses and degrade mapping predictions by finding plausible environmental variation (e.g. shadows, wet roads). MIRAGE exploits the latent manifold of real-world data learned by diffusion models, and searches for semantically mutated scenes neighboring the ground truth with the same road topology yet mislead the mapping predictions. We evaluate MIRAGE on nuScenes and demonstrate two attacks: (1) boundary removal, suppressing 57.7% of detections and corrupting 96% of planned trajectories; and (2) boundary injection, the only method that successfully injects fictitious boundaries, while pixel PGD and AdvPatch fail entirely. Both attacks remain potent under various adversarial defenses. We use two independent VLM judges to quantify realism, where MIRAGE passes as realistic 80--84% of the time (vs. 97--99% for clean nuScenes), while AdvPatch only 0--9%. Our findings expose a categorical gap in current adversarial defenses: semantic-level perturbations that manifest as legitimate environmental variation are substantially harder to mitigate than pixel-level perturbations.

自动驾驶语义攻击扩散模型地图安全

Thank you to arXiv for use of its open access interoperability. PaperDance 不是 arXiv 官方产品;中文卡片由大模型生成,请以原文为准。