首次系统评估激光雷达3D检测模型抗干扰能力,发现新模型同样脆弱。
Comprehensive Robustness Analysis of LiDAR-based 3D Object Detection in Autonomous Driving

- 设计针对激光雷达的对抗攻击,从点云密度与定位等结构因素评估鲁棒性
- 高容量体素检测器对坐标扰动更敏感,无锚框模型鲁棒性差
- 强调需改进评测标准,兼顾精度与对抗鲁棒性
近年来,仅使用激光雷达的3D目标检测在基准数据集上取得了显著的检测精度提升。然而,这些模型的对抗鲁棒性尚未得到充分检验。现有针对激光雷达仅3D检测的对抗鲁棒性研究极少,且大多局限于旧模型。此外,现有评估框架仅依赖mAP,忽略了结构和预测层面的其他关键因素。为此,本文提出一个综合评估框架,通过两个结构性因素(点云密度、点云定位)和三个预测性因素(误分类、定位误差、距离自车距离)来评估对抗鲁棒性。基于此框架,我们对近期及经典先进模型进行了实证研究与批判性分析,采用专为激光雷达模型设计的对抗攻击。关键发现表明:高容量的体素基检测器比柱状基检测器更易受结构化坐标扰动影响;无锚框检测器表现出较差的对抗鲁棒性,提示需重新思考模型训练方法。总体而言,我们的结果表明,近期模型与早期模型一样容易受到对抗攻击。因此,我们认为有必要改进3D目标检测的评估基准,不仅奖励架构改进带来的精度提升,还应评估其是否增强了对抗鲁棒性。
原文摘要 · Abstract (English)
Recent advancements in LiDAR-only 3D object detection have demonstrated improved detection accuracy over benchmark datasets. However, the adversarial robustness of these models remains untested. Very few adversarial robustness studies exist for LiDAR-only 3D object detection and unfortunately, even they are limited to legacy models. Moreover, there is a systemic gap in the existing evaluation frameworks that rely simply on mAP ignoring other structural and predictive factors. To fill this gap, we propose a holistic framework that evaluates adversarial robustness using two structural factors (point cloud density and point cloud localization) and three predictive factors (misclassification, localization error, distance from ego). Using this framework, we perform an empirical study and critical analysis on recent and legacy state-of-the-art models using adversarial attacks specifically designed for LiDAR-based models. Our key finding is that high-capacity, voxel-based detectors are more susceptible to structured coordinate perturbations than pillar-based detectors. Additionally, non-anchor-based detectors demonstrate poor adversarial robustness, which necessitates rethinking model training techniques. Overall, our results demonstrate that recent models are as vulnerable to adversarial attacks as their predecessors. Therefore, we argue that there is a need to improve the evaluation benchmarks for 3D object detection that not only reward architectural modifications for improving detection accuracy, but also evaluate whether the design choices improve adversarial robustness.
Thank you to arXiv for use of its open access interoperability. PaperDance 不是 arXiv 官方产品;中文卡片由大模型生成,请以原文为准。