Towards Robust LiDAR-based Perception in Autonomous Driving: General Black-box Adversarial Sensor Attack and Countermeasures

被引:0
|
作者
Sun, Jiachen [1 ]
Cao, Yulong [1 ]
Chen, Qi Alfred [2 ]
Mao, Z. Morley [1 ]
机构
[1] Univ Michigan, Ann Arbor, MI 48109 USA
[2] UC Irvine, Irvine, CA USA
关键词
ARCHITECTURE;
D O I
暂无
中图分类号
TP [自动化技术、计算机技术];
学科分类号
0812 ;
摘要
Perception plays a pivotal role in autonomous driving systems, which utilizes onboard sensors like cameras and LiDARs (Light Detection and Ranging) to assess surroundings. Recent studies have demonstrated that LiDAR-based perception is vulnerable to spoofing attacks, in which adversaries spoof a fake vehicle in front of a victim self-driving car by strategically transmitting laser signals to the victim's LiDAR sensor. However, existing attacks suffer from effectiveness and generality limitations. In this work, we perform the first study to explore the general vulnerability of current LiDAR-based perception architectures and discover that the ignored occlusion patterns in LiDAR point clouds make self-driving cars vulnerable to spoofing attacks. We construct the first black-box spoofing attack based on our identified vulnerability, which universally achieves around 80% mean success rates on all target models. We perform the first defense study, proposing CARLO to mitigate LiDAR spoofing attacks. CARLO detects spoofed data by treating ignored occlusion patterns as invariant physical features, which reduces the mean attack success rate to 5.5%. Meanwhile, we take the first step towards exploring a general architecture for robust LiDAR-based perception, and propose SVF that embeds the neglected physical features into end-to-end learning. SVF further reduces the mean attack success rate to around 2.3%.
引用
收藏
页码:877 / 894
页数:18
相关论文
共 50 条
  • [1] Adversarial Sensor Attack on LiDAR-based Perception in Autonomous Driving
    Cao, Yulong
    Xiao, Chaowei
    Cyr, Benjamin
    Zhou, Yimeng
    Park, Won
    Rampazzi, Sara
    Chen, Qi Alfred
    Fu, Kevin
    Mao, Z. Morley
    [J]. PROCEEDINGS OF THE 2019 ACM SIGSAC CONFERENCE ON COMPUTER AND COMMUNICATIONS SECURITY (CCS'19), 2019, : 2267 - 2281
  • [2] Practical black-box adversarial attack on open-set recognition: Towards robust autonomous driving
    Yanfei Wang
    Kai Zhang
    Kejie Lu
    Yun Xiong
    Mi Wen
    [J]. Peer-to-Peer Networking and Applications, 2023, 16 : 295 - 311
  • [3] Practical black-box adversarial attack on open-set recognition: Towards robust autonomous driving
    Wang, Yanfei
    Zhang, Kai
    Lu, Kejie
    Xiong, Yun
    Wen, Mi
    [J]. PEER-TO-PEER NETWORKING AND APPLICATIONS, 2023, 16 (01) : 295 - 311
  • [4] Saliency Attack: Towards Imperceptible Black-box Adversarial Attack
    Dai, Zeyu
    Liu, Shengcai
    Li, Qing
    Tang, Ke
    [J]. ACM TRANSACTIONS ON INTELLIGENT SYSTEMS AND TECHNOLOGY, 2023, 14 (03)
  • [5] Towards Efficient Data Free Black-box Adversarial Attack
    Zhang, Jie
    Li, Bo
    Xu, Jianghe
    Wu, Shuang
    Ding, Shouhong
    Zhang, Lei
    Wu, Chao
    [J]. 2022 IEEE/CVF CONFERENCE ON COMPUTER VISION AND PATTERN RECOGNITION (CVPR 2022), 2022, : 15094 - 15104
  • [6] An Advanced Black-Box Adversarial Attack for Deep Driving Maneuver Classification Models
    Sarker, Ankur
    Shen, Haiying
    Sen, Tanmoy
    Uehara, Hua
    [J]. 2020 IEEE 17TH INTERNATIONAL CONFERENCE ON MOBILE AD HOC AND SMART SYSTEMS (MASS 2020), 2020, : 184 - 192
  • [7] Robust LiDAR-Based Vehicle Detection for On-Road Autonomous Driving
    Jin, Xianjian
    Yang, Hang
    He, Xiongkui
    Liu, Guohua
    Yan, Zeyuan
    Wang, Qikang
    [J]. REMOTE SENSING, 2023, 15 (12)
  • [8] IoU Attack: Towards Temporally Coherent Black-Box Adversarial Attack for Visual Object Tracking
    Jia, Shuai
    Song, Yibing
    Ma, Chao
    Yang, Xiaokang
    [J]. 2021 IEEE/CVF CONFERENCE ON COMPUTER VISION AND PATTERN RECOGNITION, CVPR 2021, 2021, : 6705 - 6714
  • [9] A low-query black-box adversarial attack based on transferability
    Ding, Kangyi
    Liu, Xiaolei
    Niu, Weina
    Hu, Teng
    Wang, Yanping
    Zhang, Xiaosong
    [J]. KNOWLEDGE-BASED SYSTEMS, 2021, 226
  • [10] An adversarial attack on DNN-based black-box object detectors
    Wang, Yajie
    Tan, Yu-an
    Zhang, Wenjiao
    Zhao, Yuhang
    Kuang, Xiaohui
    [J]. JOURNAL OF NETWORK AND COMPUTER APPLICATIONS, 2020, 161