arXiv:2605.22122cs.CRcs.AI2026-05

攻击者用真实但有误导性的物体,让正常车辆感知不一致,骗系统降低其信任度。

Adversarial Trust Poisoning in Vehicular Collaborative Perception

论文配图:Adversarial Trust Poisoning in Vehicular Collaborative Perception
图 1 · 摘自论文原文
  • 利用真实物体制造感知不一致,伪装成恶意行为
  • 使目标车辆信任分下降,87.7%情况下被排除协作
  • 适合研究车联网安全与对抗防御的学者

协同感知(CP)使联网自动驾驶汽车能够共享传感器数据并共同理解环境。为防御伪造或篡改共享数据的攻击,现有系统采用跨车辆不一致检测与信任评估机制,对与多数意见冲突的车辆进行惩罚。本文揭示,此类防御本身引入了新攻击面。我们提出TrustFlip攻击,利用基于一致性的防御机制,刻意毒化对正常车辆的信任评分。攻击者不注入虚假数据,而是部署物理对抗性物体,这些物体真实存在但引发正常车辆间感知不一致。防御系统错误地将不一致归因于目标车辆,导致其信任分下降,最终被降权或排除出协作。系统因此失去可靠感知节点,感知能力下降,可能引发安全事故。我们在多种协同感知架构与防御机制上评估了TrustFlip,结果表明:顶尖防御可被显著影响——攻击在高达87.7%的场景中移除目标车辆,并使平均精度(AP)下降最多13%。作为初步缓解方案,我们提出轻量级自反思机制TrustReflect,标记争议区域为不确定并从信任评估中剔除,使攻击成功率降低35%-100%。

原文摘要 · Abstract (English)

Collaborative perception (CP) enables connected and autonomous vehicles to share sensor data and jointly reason about their environment. To defend against adversaries that fabricate or manipulate shared data, existing systems employ cross-vehicle inconsistency detection and trust estimation, penalizing vehicles whose observations conflict with the majority. In this work, we show that these defenses themselves introduce a new attack surface. We present TrustFlip, a novel attack that weaponizes consistency-based defenses to poison the trust assigned to benign vehicles. Instead of injecting false data into the collaboration pipeline, it deploys physical adversarial objects that are genuine but induce inconsistent observations among benign vehicles. The resulting inconsistencies are misattributed by the defense to the targeted vehicle, causing its trust score to degrade and eventually leading to its downweighting or exclusion from collaboration. Consequently, the system loses reliable sensing contributors, degrading perception capability and potentially inducing safety-critical failures. We evaluate TrustFlip across multiple collaborative perception architectures and defense mechanisms. Our results show that state-of-the-art defenses can be significantly affected: the attack removes the targeted benign vehicle from collaboration in up to 87.7% of scenarios and drops Average Precision (AP) by up to 13%. As an initial mitigation, we introduce TrustReflect, a lightweight self-reflection mechanism that marks disputed regions as uncertain and excludes them from trust evaluation, reducing the attack success rate by 35-100%.

车联网对抗攻击信任机制

Thank you to arXiv for use of its open access interoperability. PaperDance 不是 arXiv 官方产品;中文卡片由大模型生成,请以原文为准。