Counteracting Adversarial Attacks in Autonomous Driving (Invited Talk)

被引:18
|
作者
Sun, Qi [1 ]
Rao, Arjun Ashok [1 ]
Yao, Xufeng [1 ]
Yu, Bei [1 ]
Hu, Shiyan [2 ]
机构
[1] Chinese Univ Hong Kong, Hong Kong, Peoples R China
[2] Univ Southampton, Southampton, Hants, England
关键词
Robust Stereo Vision; Autonomous System; Adversarial Defense; Local Smoothness;
D O I
10.1145/3400302.3415758
中图分类号
TP3 [计算技术、计算机技术];
学科分类号
0812 ;
摘要
In this paper, we focus on studying robust deep stereo vision of autonomous driving systems and counteracting adversarial attacks against it. Autonomous system operation requires real-time processing of measurement data which often contain significant uncertainties and noise. Adversarial attacks have been widely studied to simulate these perturbations in recent years. To counteract these attacks in autonomous systems, a novel defense method is proposed in this paper. A stereo-regularizer is proposed to guide the model to learn the implicit relationship between the left and right images of the stereo-vision system. Univariate and multivariate functions are adopted to characterize the relationships between the two input images and the object detection model. The regularizer is then relaxed to its upper bound to improve adversarial robustness. Furthermore, the upper bound is approximated by the remainder of its Taylor expansion to improve the local smoothness of the loss surface. The model parameters are trained via adversarial training with the novel regularization term. Our method exploits basic knowledge from the physical world, i.e., the mutual constraints of the two images in the stereo-based system. As such, outliers can be detected and defended with high accuracy and efficiency. Numerical experiments demonstrate that the proposed method offers superior performance when compared with traditional adversarial training methods in state-of-the-art stereo-based 3D object detection models for autonomous vehicles.
引用
收藏
页数:7
相关论文
共 50 条
  • [21] Condition Invariance for Autonomous Driving by Adversarial Learning
    Teixeira e Silva, Diana
    Cruz, Ricardo P. M.
    PROGRESS IN PATTERN RECOGNITION, IMAGE ANALYSIS, COMPUTER VISION, AND APPLICATIONS, CIARP 2023, PT I, 2024, 14469 : 552 - 563
  • [22] Randomized Adversarial Imitation Learning for Autonomous Driving
    Shin, MyungJae
    Kim, Joongheon
    PROCEEDINGS OF THE TWENTY-EIGHTH INTERNATIONAL JOINT CONFERENCE ON ARTIFICIAL INTELLIGENCE, 2019, : 4590 - 4596
  • [23] Quantum communication attacks on classical cryptographic protocols: (invited talk)
    Damgård, Ivan
    Lecture Notes in Computer Science (including subseries Lecture Notes in Artificial Intelligence and Lecture Notes in Bioinformatics), 2011, 6673 LNCS
  • [24] SR-Adv: Salient Region Adversarial Attacks on 3D Point Clouds for Autonomous Driving
    Zheng, Shijun
    Liu, Weiquan
    Guo, Yu
    Zang, Yu
    Shen, Siqi
    Wen, Chenglu
    Cheng, Ming
    Zhong, Ping
    Wang, Cheng
    IEEE TRANSACTIONS ON INTELLIGENT TRANSPORTATION SYSTEMS, 2024, : 1 - 12
  • [25] Adversarial Attacks and Defense Technologies on Autonomous Vehicles: A Review
    Mahima, K. T. Y.
    Ayoob, Mohamed
    Poravi, Guhanathan
    APPLIED COMPUTER SYSTEMS, 2021, 26 (02) : 96 - 106
  • [26] SADA: Semantic Adversarial Diagnostic Attacks for Autonomous Applications
    Hamdi, Abdullah
    Muller, Matthias
    Ghanem, Bernard
    THIRTY-FOURTH AAAI CONFERENCE ON ARTIFICIAL INTELLIGENCE, THE THIRTY-SECOND INNOVATIVE APPLICATIONS OF ARTIFICIAL INTELLIGENCE CONFERENCE AND THE TENTH AAAI SYMPOSIUM ON EDUCATIONAL ADVANCES IN ARTIFICIAL INTELLIGENCE, 2020, 34 : 10901 - 10908
  • [27] Attacks and Defenses for Autonomous Driving Intelligence Models
    Ma C.
    Shen C.
    Lin C.-H.
    Li Q.
    Wang Q.
    Li Q.
    Guan X.-H.
    Jisuanji Xuebao/Chinese Journal of Computers, 2024, 47 (06): : 1431 - 1452
  • [28] Towards Autonomous Driving Model Resistant to Adversarial Attack
    Shibly, Kabid Hassan
    Hossain, Md Delwar
    Inoue, Hiroyuki
    Taenaka, Yuzo
    Kadobayashi, Youki
    APPLIED ARTIFICIAL INTELLIGENCE, 2023, 37 (01)
  • [29] Discovering Adversarial Driving Maneuvers against Autonomous Vehicles
    Song, Ruoyu
    Ozmen, Muslum Ozgur
    Kim, Hyungsub
    Mueller, Raymond
    Celik, Z. Berkay
    Bianchi, Antonio
    PROCEEDINGS OF THE 32ND USENIX SECURITY SYMPOSIUM, 2023, : 2957 - 2974
  • [30] Adversarial Attacks and Countermeasures on Image Classification-based Deep Learning Models in Autonomous Driving Systems: A Systematic Review
    Badjie, Bakary
    Cecílio, José
    Casimiro, Antonio
    ACM Computing Surveys, 2024, 57 (01)