Towards Backdoor Attacks against LiDAR Object Detection in Autonomous Driving

Towards Backdoor Attacks against LiDAR Object Detection in Autonomous Driving
复制标题

DOI:
10.1145/3560905.3568539
复制
发表时间:
2022-11
期刊:
Proceedings of the 20th ACM Conference on Embedded Networked Sensor Systems
影响因子:
--
通讯作者:
Yan Zhang;Yi Zhu;Zihao Liu;Cheng-yi Miao;Foad Hajiaghajani;Lu Su;Chunming Qiao
Yan Zhang;Yi Zhu;Zihao Liu;Cheng-yi Miao;Foad Hajiaghajani;Lu Su;Chunming Qiao
中科院分区:
其他
文献类型:
--
作者:
Yan Zhang;Yi Zhu;Zihao Liu;Cheng-yi Miao;Foad Hajiaghajani;Lu Su;Chunming Qiao

文献摘要

相似文献

由于LiDAR传感器在感知复杂驾驶环境方面的巨大优势,基于LiDAR的3D物体检测最近在自动驾驶中引起了极大的关注。尽管已经开发了许多先进的LiDAR对象检测模型,但它们的设计主要基于深度学习方法,这些方法通常需要大量数据,而且训练成本高昂。因此,对于一些LiDAR感知系统开发人员或自动驾驶汽车公司来说,从不同的来源收集训练数据是很常见的(例如,自动驾驶汽车用户)或将培训工作外包给第三方。然而,这些做法为后门攻击提供了机会,攻击者的目标是通过毒化其训练集将隐藏的触发模式注入受害者检测模型,并在触发出现在推理阶段时让模型无法检测到对象。虽然后门攻击已经引起了严重的安全问题,但LiDAR对象检测对此类攻击的脆弱性尚未得到研究。为了填补这一研究空白,本文首次研究了自动驾驶中针对LiDAR目标检测的后门攻击。具体而言,我们提出了一种新的后门攻击策略,基于该策略,攻击者可以通过中毒少量的点云样本来实现攻击目标。此外,所提出的攻击策略是物理可实现的,它允许攻击者容易地执行攻击使用一些常见的对象作为触发器。为了使中毒样本难以被检测到,我们还设计了一种隐形攻击策略,通过创建一些假的车辆点簇来隐藏点云中的注入点。我们的攻击所需的性能证明,通过模拟和现实世界的案例研究。
Due to the great advantage of LiDAR sensors in perceiving complex driving environments, LiDAR-based 3D object detection has recently drawn significant attention in autonomous driving. Although many advanced LiDAR object detection models have been developed, their designs are mainly based on deep learning approaches, which are usually data-hungry and expensive to train. Thus, it is common for some LiDAR perception system developers or self-driving car companies to collect training data from different sources (e.g., self-driving car users) or outsource the training work to a third party. However, these practices provide opportunities for backdoor attacks, where the attacker aims to inject a hidden trigger pattern into the victim detection model by poisoning its training set and let the model fail to detect objects when the trigger presents in the inference phase. Although backdoor attacks have posed serious security concerns, the vulnerability of LiDAR object detection to such attacks has not yet been studied. To fill the research gap, in this paper, we present the first study on backdoor attacks against LiDAR object detection in autonomous driving. Specifically, we propose a novel backdoor attack strategy based on which the attacker can achieve the attack goal by poisoning a small number of point cloud samples. In addition, the proposed attack strategy is physically realizable, and it allows the attacker to easily perform the attack using some common objects as the triggers. To make the poisoned samples difficult to be detected, we also design a stealthy attack strategy by creating some fake vehicle point clusters to hide the injected points in the point cloud. The desirable performance of our attacks is demonstrated through both simulation and real-world case study.