arXiv:2606.02924cs.CV2026-06

首个针对激光雷达感知的对抗性攻击评测基准,揭示模型在真实攻击下的脆弱性差异。

ATLAS: A Large-Scale Evaluation Benchmark for Adversarial LiDAR Perception

论文配图:ATLAS: A Large-Scale Evaluation Benchmark for Adversarial LiDAR Perception
图 1 · 摘自论文原文
  • 构建物理可实现的点云注入与移除攻击,覆盖真实驾驶场景
  • 发现强模型在移除攻击下更鲁棒,但对注入攻击更易受攻击
  • 揭示训练数据增强导致的通用脆弱性,适合自动驾驶安全研究者

自动驾驶感知通常在干净基准数据上评估,但实际部署需应对罕见、结构化且可能具有对抗性的传感器异常。这一差距对激光雷达尤为关键,因外部实体可物理操控传感过程,在不访问模型的情况下诱导黑盒感知失败。现有激光雷达基准难以揭示此类失效模式。此前对抗激光雷达研究多集中于攻击硬件、几何与算法防御及早期检测器,未涵盖现代感知系统的鲁棒性。为此,我们提出ATLAS(对抗性时间激光雷达攻击套件),首个大规模、基于物理的真实场景评测基准,模拟点云注入与移除两种主要攻击模式,覆盖真实驾驶序列。评估多种前沿激光雷达感知模型后发现:标准基准表现越强的模型,越能抵御移除攻击,却反而更易受注入攻击。我们归因于标准目标数据库采样增强,揭示当前训练方式引发的架构无关鲁棒性缺陷,并探索两类攻击的缓解方向。我们开源ATLAS生成代码,支持可扩展、可复现的评估,推动未来激光雷达感知开发中将黑盒传感器鲁棒性纳入考量。

原文摘要 · Abstract (English)

Autonomous driving perception is typically evaluated on clean benchmark data, yet real-world deployment requires robustness to rare, structured, and potentially adversarial sensor anomalies. This gap is especially critical for LiDAR, where external actors can physically manipulate the sensing process to induce black-box perception failures without accessing the model. Existing LiDAR benchmarks provide little visibility into this failure mode. Prior adversarial LiDAR studies have largely centered on attack hardware, geometric and algorithmic defenses, and early-generation detectors, leaving the robustness of modern perception systems unexplored. To address this evaluation gap, we introduce ATLAS (Adversarial Temporal LiDAR Attack Suite), the first large-scale, physically grounded evaluation benchmark for LiDAR perception models under black-box sensor attacks, simulating the two primary attack modes -- point injection and point removal -- across real driving sequences. Evaluating a broad cross-section of current state-of-the-art LiDAR perception models, ATLAS reveals a surprising robustness asymmetry: models with stronger performance on standard benchmarks tend to better withstand removal attacks, yet are actually more vulnerable to injection attacks than weaker models. We trace this vulnerability to standard object database sampling augmentations, revealing how current training practices can induce architecture-agnostic robustness failures, and study initial directions for mitigating both attack modes. We release the ATLAS generation code to support extensible, reproducible evaluations as attack capabilities evolve, helping make black-box sensor robustness an explicit consideration in future LiDAR perception development.

激光雷达对抗攻击自动驾驶评测基准

Thank you to arXiv for use of its open access interoperability. PaperDance 不是 arXiv 官方产品;中文卡片由大模型生成,请以原文为准。