arXiv:2608.28778cs.ROcs.CV2026-08

用一张对抗海报破坏自动驾驶车辆的摄像头与激光雷达校准,导致系统误判。

Adversarial Calibration Attack on Autonomous Vehicles

论文配图:Adversarial Calibration Attack on Autonomous Vehicles
图 1 · 摘自论文原文
  • 通过对抗海报欺骗校准检测器并诱导错误校准
  • 在真实车辆上实现最高33.9度的旋转误差
  • 适用于研究自动驾驶安全漏洞的学者与工程师

自动驾驶车辆依赖精准的相机-激光雷达校准实现多模态传感器融合。实际中,振动、温差或传感器微移会导致校准漂移,因此需在线校准算法在运行时检测并修正偏移,无需返厂。现有攻击多假设校准正确,本文首次将在线校准视为新攻击面。恶意校准更新会持续影响后续融合,引发感知到规划控制的系统性错误。提出对抗校准攻击(ACA),首个针对相机-激光雷达在线校准的物理攻击。利用单张对抗海报,先诱骗校准检测器触发校准流程,再引导校准估计器趋向错误变换。统一优化联合设计海报的几何与纹理以达成双重目标。在KITTI、nuScenes等基准数据集、CARLA仿真及真实Husky机器人上评估:在数据集上引发最高33.9度平均旋转误差,严重降低目标检测性能;仿真中导致碰撞;实物实验成功复现校准误差。结果表明,在线校准是自动驾驶车辆可被利用且危及安全的攻击面。

原文摘要 · Abstract (English)

Autonomous vehicles (AVs) rely on accurate camera-LiDAR calibration for multimodal sensor fusion. In practice, calibration can drift due to vibration, temperature variation, or minor sensor displacement, motivating online calibration algorithms that detect and correct misalignment at runtime while allowing the vehicle to continue operating without a factory visit. Existing AV attacks largely assume correct calibration. We instead identify online sensor calibration as a new attack plane. A corrupted calibration update can persist across subsequent fusion operations, causing system-wide errors that propagate from perception to planning and control. We present Adversarial Calibration Attack (ACA), the first physical attack against camera-LiDAR online calibration. Using a single adversarial poster, ACA first spoofs the miscalibration detector to trigger the calibration process and then steers the calibration estimator toward an incorrect transformation. A unified optimization jointly designs the poster's geometry and texture for both objectives. We evaluate ACA across benchmark datasets, simulation, and physical experiments. On benchmark datasets such as KITTI and nuScenes, ACA induces up to 33.9 degrees mean rotational calibration error, thereby severely degrading object detection. In the CARLA simulator, the attack causes a collision when the corrupted calibration is accepted in vulnerable scenarios crafted by the attacker. On a real Husky robot, a printed adversarial poster successfully reproduces the calibration error. These results demonstrate that online calibration is a practical and safety-critical attack surface for AVs.

自动驾驶对抗攻击传感器校准物理攻击

Thank you to arXiv for use of its open access interoperability. PaperDance 不是 arXiv 官方产品;中文卡片由大模型生成,请以原文为准。