Counteracting Adversarial Attacks in Autonomous Driving (Invited Talk)

被引:18
|
作者
Sun, Qi [1 ]
Rao, Arjun Ashok [1 ]
Yao, Xufeng [1 ]
Yu, Bei [1 ]
Hu, Shiyan [2 ]
机构
[1] Chinese Univ Hong Kong, Hong Kong, Peoples R China
[2] Univ Southampton, Southampton, Hants, England
关键词
Robust Stereo Vision; Autonomous System; Adversarial Defense; Local Smoothness;
D O I
10.1145/3400302.3415758
中图分类号
TP3 [计算技术、计算机技术];
学科分类号
0812 ;
摘要
In this paper, we focus on studying robust deep stereo vision of autonomous driving systems and counteracting adversarial attacks against it. Autonomous system operation requires real-time processing of measurement data which often contain significant uncertainties and noise. Adversarial attacks have been widely studied to simulate these perturbations in recent years. To counteract these attacks in autonomous systems, a novel defense method is proposed in this paper. A stereo-regularizer is proposed to guide the model to learn the implicit relationship between the left and right images of the stereo-vision system. Univariate and multivariate functions are adopted to characterize the relationships between the two input images and the object detection model. The regularizer is then relaxed to its upper bound to improve adversarial robustness. Furthermore, the upper bound is approximated by the remainder of its Taylor expansion to improve the local smoothness of the loss surface. The model parameters are trained via adversarial training with the novel regularization term. Our method exploits basic knowledge from the physical world, i.e., the mutual constraints of the two images in the stereo-based system. As such, outliers can be detected and defended with high accuracy and efficiency. Numerical experiments demonstrate that the proposed method offers superior performance when compared with traditional adversarial training methods in state-of-the-art stereo-based 3D object detection models for autonomous vehicles.
引用
收藏
页数:7
相关论文
共 50 条
  • [31] Black-box Adversarial Attacks in Autonomous Vehicle Technology
    Kumar, K. Naveen
    Vishnu, C.
    Mitra, Reshmi
    Mohan, C. Krishna
    2020 IEEE APPLIED IMAGERY PATTERN RECOGNITION WORKSHOP (AIPR): TRUSTED COMPUTING, PRIVACY, AND SECURING MULTIMEDIA, 2020,
  • [32] Invited Talk: Software Engineering, AI and autonomous vehicles: Security assurance
    Zheng, James Xi
    2020 IEEE INTERNATIONAL CONFERENCE ON PERVASIVE COMPUTING AND COMMUNICATIONS WORKSHOPS (PERCOM WORKSHOPS), 2020,
  • [33] Overriding Autonomous Driving Systems Using Adaptive Adversarial Billboards
    Patel, Naman
    Krishnamurthy, Prashanth
    Garg, Siddharth
    Khorrami, Farshad
    IEEE TRANSACTIONS ON INTELLIGENT TRANSPORTATION SYSTEMS, 2022, 23 (08) : 11386 - 11396
  • [34] Autonomous Driving Model Defense Study on Hijacking Adversarial Attack
    Shibly, Kabid Hassan
    Hossain, Md Delwar
    Inoue, Hiroyuki
    Taenaka, Yuzo
    Kadobayashi, Youki
    ARTIFICIAL NEURAL NETWORKS AND MACHINE LEARNING - ICANN 2022, PT IV, 2022, 13532 : 546 - 557
  • [35] Interactive Planning for Autonomous Urban Driving in Adversarial Scenarios 2021
    Luo, Yuanfu
    Meghjani, Malika
    Ho, Qi Heng
    Hsu, David
    Rus, Daniela
    2021 IEEE INTERNATIONAL CONFERENCE ON ROBOTICS AND AUTOMATION (ICRA 2021), 2021, : 5261 - 5267
  • [36] Adversarial Testing with Reinforcement Learning: A Case Study on Autonomous Driving
    Doreste, Andrea
    Biagiola, Matteo
    Tonella, Paolo
    2024 IEEE CONFERENCE ON SOFTWARE TESTING, VERIFICATION AND VALIDATION, ICST 2024, 2024, : 293 - 304
  • [37] Adversarial Attack and Defense of YOLO Detectors in Autonomous Driving Scenarios
    Choi, Jung Im
    Tian, Qing
    2022 IEEE INTELLIGENT VEHICLES SYMPOSIUM (IV), 2022, : 1011 - 1017
  • [38] Exploring Adversarial Robustness of LiDAR Semantic Segmentation in Autonomous Driving
    Mahima, K. T. Yasas
    Perera, Asanka
    Anavatti, Sreenatha
    Garratt, Matt
    SENSORS, 2023, 23 (23)
  • [39] Fault Attacks at the System Level The Challenge of Securing Application Software (Invited Talk)
    Mangard, Stefan
    2015 WORKSHOP ON FAULT DIAGNOSIS AND TOLERANCE IN CRYPTOGRAPHY (FDTC), 2015, : 1 - 1
  • [40] Covert Attacks Through Adversarial Learning: Study of Lane Keeping Attacks on the Safety of Autonomous Vehicles
    Farivar, Faezeh
    Haghighi, Mohammad Sayad
    Jolfaei, Alireza
    Wen, Sheng
    IEEE-ASME TRANSACTIONS ON MECHATRONICS, 2021, 26 (03) : 1350 - 1357