Does Physical Adversarial Example Really Matter to Autonomous Driving? Towards System-Level Effect of Adversarial Object Evasion Attack

Does Physical Adversarial Example Really Matter to Autonomous Driving? Towards System-Level Effect of Adversarial Object Evasion Attack
复制标题

DOI:
10.1109/iccv51070.2023.00407
复制
发表时间:
2023-08
期刊:
2023 IEEE/CVF International Conference on Computer Vision (ICCV)
影响因子:
--
通讯作者:
Ningfei Wang;Y. Luo;Takami Sato;Kaidi Xu;Qi Alfred Chen
Ningfei Wang;Y. Luo;Takami Sato;Kaidi Xu;Qi Alfred Chen
中科院分区:
其他
文献类型:
--
作者:
Ningfei Wang;Y. Luo;Takami Sato;Kaidi Xu;Qi Alfred Chen

文献摘要

被引文献

相似文献

在自动驾驶(AD)中,准确的感知是实现安全驾驶的必要条件。由于AD感知的安全临界性,其安全性得到了广泛的研究。在针对AD感知的各种攻击中,物理对抗对象规避攻击尤为严重。然而,我们发现所有现有文献仅在目标AI组件级别评估其攻击效果,而不是在系统级别,即整个系统语义和上下文(如完整的AD管道)评估其攻击效果。因此,这就提出了一个关键的研究问题:这些现有的研究能否在真实的AD环境中有效地实现系统级的攻击效果(例如,违反交通规则)?在这项工作中,我们对现有设计是否以及如何有效地导致系统级效应进行了首次测量研究,特别是对于由于其流行和严重程度而导致的STOP标志逃避攻击。我们的评价结果表明,所有具有代表性的前期工作都没有达到任何系统级的效果。我们在之前的工作中观察到两个设计局限性:1)物理模型-像素采样中对象尺寸分布不一致;2)缺乏车厂模型和AD系统模型的考虑。然后,我们在AD环境下提出了一种新的系统驱动攻击设计SysAdv,我们的评估结果表明,系统级效果可以得到显著改善,即违规率提高了70%左右。
In autonomous driving (AD), accurate perception is indispensable to achieving safe and secure driving. Due to its safety-criticality, the security of AD perception has been widely studied. Among different attacks on AD perception, the physical adversarial object evasion attacks are especially severe. However, we find that all existing literature only evaluates their attack effect at the targeted AI component level but not at the system level, i.e., with the entire system semantics and context such as the full AD pipeline. Thereby, this raises a critical research question: can these existing researches effectively achieve system-level attack effects (e.g., traffic rule violations) in the real-world AD context? In this work, we conduct the first measurement study on whether and how effectively the existing designs can lead to system-level effects, especially for the STOP sign-evasion attacks due to their popularity and severity. Our evaluation results show that all the representative prior works cannot achieve any system-level effects. We observe two design limitations in the prior works: 1) physical model-inconsistent object size distribution in pixel sampling and 2) lack of vehicle plant model and AD system model consideration. Then, we propose SysAdv, a novel system-driven attack design in the AD context and our evaluation results show that the system-level effects can be significantly improved, i.e., the violation rate increases by around 70%.