Play the Imitation Game: Model Extraction Attack against Autonomous Driving Localization

被引:2
|
作者
Zhang, Qifan [1 ]
Shen, Junjie [1 ]
Tan, Mingtian [2 ]
Zhou, Zhe [2 ]
Li, Zhou [1 ]
Chen, Qi Alfred [1 ]
Zhang, Haipeng [3 ]
机构
[1] Univ Calif Irvine, Irvine, CA 92717 USA
[2] Fudan Univ, Shanghai, Peoples R China
[3] ShanghaiTech Univ, Shanghai, Peoples R China
关键词
autonomous driving; localization; model extraction; KALMAN FILTER; IDENTIFICATION;
D O I
10.1145/3564625.3567977
中图分类号
TP [自动化技术、计算机技术];
学科分类号
0812 ;
摘要
The security of the Autonomous Driving (AD) system has been gaining researchers' and public's attention recently. Given that AD companies have invested a huge amount of resources in developing their AD models, e.g., localization models, these models, especially their parameters, are important intellectual property and deserve strong protection. In this work, we examine whether the confidentiality of production-grade Multi-Sensor Fusion (MSF) models, in particular, Error-State Kalman Filter (ESKF), can be stolen from an outside adversary. We propose a new model extraction attack called TaskMaster that can infer the secret ESKF parameters under black-box assumption. In essence, TaskMaster trains a substitutional ESKF model to recover the parameters, by observing the input and output to the targeted AD system. To precisely recover the parameters, we combine a set of techniques, like gradient-based optimization, search-space reduction and multi-stage optimization. The evaluation result on real-world vehicle sensor dataset shows that TaskMaster is practical. For example, with 25 seconds AD sensor data for training, the substitutional ESKF model reaches centimeter-level accuracy, comparing with the ground-truth model.
引用
收藏
页码:56 / 70
页数:15
相关论文
共 35 条
  • [32] Trajectory Following using Nonlinear Model Predictive Control and 3D Point-Cloud-based Localization for Autonomous Driving
    Babu, Ajish
    Yurtdas, Kerim Yener
    Koch, Christian Ernst Siegfried
    Yueksel, Mehmed
    2019 EUROPEAN CONFERENCE ON MOBILE ROBOTS (ECMR), 2019,
  • [33] SwiftTheft: A Time-Efficient Model Extraction Attack Framework Against Cloud-Based Deep Neural Networks
    Yang, Wenbin
    Gong, Xueluan
    Chen, Yanjiao
    Wang, Qian
    Dong, Jianshuo
    CHINESE JOURNAL OF ELECTRONICS, 2024, 33 (01) : 90 - 100
  • [34] SwiftTheft: A Time-Efficient Model Extraction Attack Framework Against Cloud-Based Deep Neural Networks
    Wenbin YANG
    Xueluan GONG
    Yanjiao CHEN
    Qian WANG
    Jianshuo DONG
    Chinese Journal of Electronics, 2024, 33 (01) : 90 - 100
  • [35] Human-like decision making for autonomous lane change driving: a hybrid inverse reinforcement learning with a game-theoretical vehicle interaction model
    Jiang, Yalan
    Wu, Xuncheng
    Zhang, Weiwei
    Guo, Wenfeng
    Yu, Wangpengfei
    Li, Jun
    BULLETIN OF THE POLISH ACADEMY OF SCIENCES-TECHNICAL SCIENCES, 2025, 73 (01)