Can We Use Arbitrary Objects to Attack LiDAR Perception in Autonomous Driving?

Can We Use Arbitrary Objects to Attack LiDAR Perception in Autonomous Driving?
复制标题

DOI:
10.1145/3460120.3485377
复制
发表时间:
2021-11
期刊:
Proceedings of the 2021 ACM SIGSAC Conference on Computer and Communications Security
影响因子:
--
通讯作者:
Yi Zhu;Chenglin Miao;T. Zheng;Foad Hajiaghajani;Lu Su;Chunming Qiao
Yi Zhu;Chenglin Miao;T. Zheng;Foad Hajiaghajani;Lu Su;Chunming Qiao
中科院分区:
其他
文献类型:
--
作者:
Yi Zhu;Chenglin Miao;T. Zheng;Foad Hajiaghajani;Lu Su;Chunming Qiao

文献摘要

被引文献

相似文献

作为获取驾驶环境准确信息的有效方式,激光雷达感知已广泛应用于自动驾驶中。最先进的LiDAR感知系统主要依靠深度神经网络(DNN)来实现良好的性能。然而,DNN已经被证明容易受到对抗性攻击。虽然有一些研究针对LiDAR感知系统的对抗性攻击的工作,但这些攻击在现实场景中执行时在可行性,灵活性和隐蔽性方面存在一些限制。在本文中,我们研究了一种更简单的方法来执行有效的对抗性攻击,具有高度的灵活性和良好的隐蔽性,以对抗自动驾驶中的LiDAR感知。具体来说,我们提出了一种新的攻击框架,基于此攻击者可以识别物理空间中的一些敌对位置。通过在这些位置周围放置具有反射表面的任意物体,攻击者可以很容易地欺骗LiDAR感知系统。大量的实验进行了评估所提出的攻击的性能,结果表明,我们提出的攻击可以达到90%以上的成功率。此外,我们的真实世界研究表明,仅使用两架商用无人机就可以轻松执行拟议的攻击。据我们所知,本文首次研究了对抗位置对LiDAR感知模型行为的影响,首次研究了如何使用具有反射表面的任意物体攻击LiDAR感知系统,以及首次使用物理世界中的商用无人机攻击LiDAR感知系统。还讨论了潜在的防御策略,以减轻拟议的攻击。
As an effective way to acquire accurate information about the driving environment, LiDAR perception has been widely adopted in autonomous driving. The state-of-the-art LiDAR perception systems mainly rely on deep neural networks (DNNs) to achieve good performance. However, DNNs have been demonstrated vulnerable to adversarial attacks. Although there are a few works that study adversarial attacks against LiDAR perception systems, these attacks have some limitations in feasibility, flexibility, and stealthiness when being performed in real-world scenarios. In this paper, we investigate an easier way to perform effective adversarial attacks with high flexibility and good stealthiness against LiDAR perception in autonomous driving. Specifically, we propose a novel attack framework based on which the attacker can identify a few adversarial locations in the physical space. By placing arbitrary objects with reflective surface around these locations, the attacker can easily fool the LiDAR perception systems. Extensive experiments are conducted to evaluate the performance of the proposed attack, and the results show that our proposed attack can achieve more than 90% success rate. In addition, our real-world study demonstrates that the proposed attack can be easily performed using only two commercial drones. To the best of our knowledge, this paper presents the first study on the effect of adversarial locations on LiDAR perception models' behaviors, the first investigation on how to attack LiDAR perception systems using arbitrary objects with reflective surface, and the first attack against LiDAR perception systems using commercial drones in physical world. Potential defense strategies are also discussed to mitigate the proposed attacks.