Security Analysis of Camera-LiDAR Fusion Against Black-Box Attacks on Autonomous Vehicles

Security Analysis of Camera-LiDAR Fusion Against Black-Box Attacks on Autonomous Vehicles
复制标题

DOI:
--
复制
发表时间:
2021-06
期刊:
--
影响因子:
--
通讯作者:
R. S. Hallyburton;Yupei Liu;Yulong Cao;Z. Mao;Miroslav Pajic
R. S. Hallyburton;Yupei Liu;Yulong Cao;Z. Mao;Miroslav Pajic
中科院分区:
其他
文献类型:
--
作者:
R. S. Hallyburton;Yupei Liu;Yulong Cao;Z. Mao;Miroslav Pajic

文献摘要

被引文献

相似文献

为了实现安全可靠的决策,自动驾驶汽车(AV)将传感器数据提供给感知算法以了解环境。多帧跟踪的传感器融合在检测3D物体方面变得越来越流行。因此,在这项工作中,我们进行了分析的摄像头激光雷达融合,在AV的背景下,激光雷达欺骗攻击。最近,仅LiDAR感知被证明容易受到LiDAR欺骗攻击;然而,我们证明这些攻击无法破坏相机-LiDAR融合。然后,我们定义了一种新的上下文感知攻击:截头体攻击,并表明,在8种广泛使用的感知算法中-3种仅限LiDAR的架构和3种相机-LiDAR融合架构-都很容易受到截头体攻击。此外,我们还证明了截头体攻击对现有的激光雷达欺骗防御是隐形的,因为它保留了相机和激光雷达语义之间的关系。最后,我们表明,截头体攻击可以随着时间的推移,形成隐形的纵向攻击序列,损害跟踪模块,并创建端到端的AV控制的不利结果。
To enable safe and reliable decision-making, autonomous vehicles (AVs) feed sensor data to perception algorithms to understand the environment. Sensor fusion with multi-frame tracking is becoming increasingly popular for detecting 3D objects. Thus, in this work, we perform an analysis of camera-LiDAR fusion, in the AV context, under LiDAR spoofing attacks. Recently, LiDAR-only perception was shown vulnerable to LiDAR spoofing attacks; however, we demonstrate these attacks are not capable of disrupting camera-LiDAR fusion. We then define a novel, context-aware attack: frustum attack, and show that out of 8 widely used perception algorithms - across 3 architectures of LiDAR-only and 3 architectures of camera-LiDAR fusion - all are significantly vulnerable to the frustum attack. In addition, we demonstrate that the frustum attack is stealthy to existing defenses against LiDAR spoofing as it preserves consistencies between camera and LiDAR semantics. Finally, we show that the frustum attack can be exercised consistently over time to form stealthy longitudinal attack sequences, compromising the tracking module and creating adverse outcomes on end-to-end AV control.