通过高阶动态证据编码,精准识别自动驾驶中渐进式欺骗攻击。
High-Order Liquid Evidence Encoding for Gradual GNSS Spoofing Detection in Autonomous Driving

- 构建物理引导的定位差异残差,捕捉欺骗信号演化过程。
- 在真实数据集上达到最高F1分数0.9777,四步内检测到攻击切换。
- 适合对车载定位安全有高要求的自动驾驶系统研发人员。
高精度全球导航卫星系统(GNSS)定位对自动驾驶的安全可靠至关重要。然而,欺骗攻击可篡改车辆位置估计。连续且细微的攻击尤为难以检测,因为单个GNSS观测值可能仍合理,但GNSS推断位移与车载运动之间的不一致性会逐渐累积。现有方法通常依赖静态车辆行为特征或单一残差信号,未显式建模该演化过程。为此,本文提出一种因果高阶液体证据框架用于GNSS欺骗检测。首先,通过对比GNSS推断位移与车载运动推断位移,构建物理引导的不一致残差。随后,分别生成残差水平及其一阶、二阶离散变化的证据流,并根据证据阶数选择相关上下文线索。每一流由独立自适应液体编码器处理,其时序状态分层耦合,仅使用当前及历史观测预测窗口终点是否存在欺骗。在AV-GPS数据集三个子集上的实验表明,所提方法在Dataset~1和Dataset~3上取得最高F1得分,分别为0.9535和0.9777。在Dataset~3上,能于四次采样步内检测出标注的正常到攻击过渡。代码与数据集已公开:https://github.com/pangjunbiao/GNSS_Spoofing.git。
原文摘要 · Abstract (English)
Accurate Global Navigation Satellite System (GNSS)-based localization is essential for safe and reliable autonomous driving. However, spoofing attacks can manipulate vehicle position estimates. Continuous and subtle attacks are particularly difficult to detect because individual GNSS observations may remain plausible while the inconsistency between GNSS-implied displacement and onboard vehicle motion gradually increases. Existing methods often rely on static vehicle-behavior features or a single residual signal and do not explicitly model this evolution. To address this problem, we propose a causal high-order liquid evidence framework for GNSS spoofing detection. The method first constructs a physics-guided GNSS--motion inconsistency residual by comparing GNSS-implied displacement with onboard-motion-derived displacement. It then forms separate evidence streams for the residual level and its first- and second-order discrete variations, with relevant contextual cues selected according to the evidence order. Each stream is processed by a separate adaptive liquid encoder, and the resulting temporal states are hierarchically coupled to predict spoofing at the window endpoint using only current and past observations. Experiments on three subsets of the real-world AV-GPS dataset show that the proposed method achieves the highest F1-scores among the evaluated temporal models on Dataset~1 and Dataset~3, reaching 0.9535 and 0.9777, respectively. On Dataset~3, it detects both labeled normal-to-attack transitions within four sampling steps. Code and datasets are publicly available at: https://github.com/pangjunbiao/GNSS_Spoofing.git.
Thank you to arXiv for use of its open access interoperability. PaperDance 不是 arXiv 官方产品;中文卡片由大模型生成,请以原文为准。