That Person Moves Like A Car: Misclassification Attack Detection for Autonomous Systems Using Spatiotemporal Consistency

That Person Moves Like A Car: Misclassification Attack Detection for Autonomous Systems Using Spatiotemporal Consistency
复制标题

DOI:
--
复制
发表时间:
2023
期刊:
--
影响因子:
--
通讯作者:
Yanmao Man;Raymond Muller;Ming Li;Z. B. Celik;Ryan M. Gerdes
Yanmao Man;Raymond Muller;Ming Li;Z. B. Celik;Ryan M. Gerdes
中科院分区:
其他
文献类型:
--
作者:
Yanmao Man;Raymond Muller;Ming Li;Z. B. Celik;Ryan M. Gerdes

文献摘要

相似文献

自主系统通常依靠物体检测和跟踪(ODT)来感知环境并预测周围物体的轨迹,以实现规划目的。ODT的输出包含传统上独立预测的对象类和轨道。最近的研究表明,ODT的输出可以被各种精心制作的噪声感知攻击伪造,但现有的防御仅限于特定的噪声注入方法,因此无法推广。在这项工作中,我们提出了PercepGuard来检测针对感知模块的错误分类攻击,而不管攻击方法如何。PercepGuard利用被检测对象的时空属性(固有的轨迹),并交叉检查轨迹和类别预测之间的一致性。为了提高对抗防御感知(自适应)攻击的鲁棒性,我们还考虑上下文数据(如自我车辆速度)进行上下文一致性验证,这大大增加了攻击难度。使用真实世界和模拟数据集进行评估,针对自适应攻击的FPR为5%,TPR为99%。基线比较证实了利用时间特性的优势。现实世界中显示和投影的对抗补丁的实验表明,PercepGuard平均检测到96%的攻击。
Autonomous systems commonly rely on object detection and tracking (ODT) to perceive the environment and predict the trajectory of surrounding objects for planning purposes. An ODT’s output contains object classes and tracks that are traditionally predicted independently. Recent studies have shown that ODT’s output can be falsified by various perception attacks with well-crafted noise, but existing defenses are limited to specific noise injection methods and thus fail to generalize. In this work we propose PercepGuard for the detection of misclassification attacks against perception modules regardless of attack methodologies. PercepGuard exploits the spatiotemporal properties of a detected object (inherent in the tracks), and cross-checks the consistency between the track and class predictions. To improve adversarial robustness against defense-aware (adaptive) attacks, we additionally consider context data (such as ego-vehicle velocity) for contextual consistency verification, which dramatically increases the attack difficulty. Evaluations with both real-world and simulated datasets produce a FPR of 5% and a TPR of 99% against adaptive attacks. A baseline comparison confirms the advantage of leveraging temporal features. Real-world experiments with displayed and projected adversarial patches show that PercepGuard detects 96% of the attacks on average.