Adaptive Adversarial Videos on Roadside Billboards: Dynamically Modifying Trajectories of Autonomous Vehicles

Adaptive Adversarial Videos on Roadside Billboards: Dynamically Modifying Trajectories of Autonomous Vehicles
复制标题

DOI:
10.1109/iros40897.2019.8968267
复制
发表时间:
2019-11
期刊:
2019 IEEE/RSJ International Conference on Intelligent Robots and Systems (IROS)
影响因子:
--
通讯作者:
Naman Patel;P. Krishnamurthy;S. Garg;F. Khorrami
Naman Patel;P. Krishnamurthy;S. Garg;F. Khorrami
中科院分区:
其他
文献类型:
--
作者:
Naman Patel;P. Krishnamurthy;S. Garg;F. Khorrami

文献摘要

相似文献

深度神经网络(DNN)正在被纳入各种自动驾驶系统,如自动驾驶汽车和机器人。然而,人们越来越担心这些系统的鲁棒性,因为它们容易受到DNN上的对抗性攻击。过去的研究已经确定,用于分类和对象检测的DNN容易受到攻击,导致有针对性的错误分类。在本文中,我们展示了对抗性动态攻击对控制自动驾驶汽车的端到端训练DNN的有效性。我们通过在路边安装广告牌并向接近的车辆显示视频来发起攻击,以使车辆中的DNN控制器生成转向命令,从而导致例如意外的车道变化或偏离道路的运动导致事故。该广告牌有一个集成的摄像头,估计即将到来的车辆的姿态。该方法使动态对抗扰动,适应车辆的相对姿态,并使用车辆的动态转向它沿着对手选择的轨迹,同时是鲁棒的视图,照明和天气的变化。我们在高保真模拟器CARLA(CAR Learning to Act)中展示了对最近发布的基于端到端学习的自主导航系统的攻击的有效性。所提出的方法也可以应用于由端到端训练网络驱动的其他系统。
Deep neural networks (DNNs) are being incorporated into various autonomous systems like self-driving cars and robots. However, there is a rising concern about the robustness of these systems because of their susceptibility to adversarial attacks on DNNs. Past research has established that DNNs used for classification and object detection are prone to attacks causing targeted misclassification. In this paper, we show the effectiveness of an adversarial dynamic attack on an end-to-end trained DNN controlling an autonomous vehicle. We launch the attack by installing a billboard on the roadside and displaying videos to approaching vehicles to cause the DNN controller in the vehicle to generate steering commands that cause, for example, unintended lane changes or motion off the road causing accidents. The billboard has an integrated camera estimating the pose of the on-coming vehicle. The approach enables dynamic adversarial perturbation that adapts to the relative pose of the vehicle and uses the dynamics of the vehicle to steer it along adversary-chosen trajectories while being robust to variations in view, lighting, and weather. We demonstrate the effectiveness of the attack on a recently published off-the-shelf end-to-end learning-based autonomous navigation system in a high-fidelity simulator, CARLA (CAR Learning to Act). The proposed approach may also be applied to other systems driven by an end-to-end trained network.