Dirty Road Can Attack: Security of Deep Learning based Automated Lane Centering under Physical-World Attack

Dirty Road Can Attack: Security of Deep Learning based Automated Lane Centering under Physical-World Attack
复制标题

DOI:
--
复制
发表时间:
2020-09
期刊:
--
影响因子:
--
通讯作者:
Takami Sato;Junjie Shen;Ningfei Wang;Yunhan Jia;Xue Lin;Qi Alfred Chen
Takami Sato;Junjie Shen;Ningfei Wang;Yunhan Jia;Xue Lin;Qi Alfred Chen
中科院分区:
其他
文献类型:
--
作者:
Takami Sato;Junjie Shen;Ningfei Wang;Yunhan Jia;Xue Lin;Qi Alfred Chen

文献摘要

被引文献

相似文献

自动车道对中(ALC)系统如今非常方便且广泛部署,但也具有高度的安全性和安全性。在这项工作中,我们是第一个系统地研究最先进的基于深度学习的ALC系统在物理世界对抗性攻击下在其设计的操作域中的安全性的人。我们制定了一个安全关键的攻击目标的问题,和一个新的和特定领域的攻击向量:肮脏的道路补丁。为了系统地生成攻击,我们采用了基于优化的方法,并克服了特定领域的设计挑战,例如由于攻击影响的车辆控制而导致的相机帧相互依赖性,以及车道检测模型缺乏目标函数设计。我们使用来自真实驾驶轨迹的80个场景来评估对生产ALC的攻击。结果表明,我们的攻击是非常有效的,超过97.5%的成功率和不到0.903秒的平均成功时间,这是大大低于平均司机的反应时间。这种攻击也被发现(1)对各种现实因素(如照明条件和视角)具有鲁棒性,(2)对不同的模型设计具有通用性,以及(3)从驾驶员的角度来看是隐形的。为了了解安全影响,我们进行了实验,使用软件在环仿真和攻击痕迹注入在真实的车辆。结果表明,我们的攻击在不同的场景下可以导致100%的碰撞率,包括在使用自动紧急制动等常见安全功能进行测试时。我们还评估和讨论防御。
Automated Lane Centering (ALC) systems are convenient and widely deployed today, but also highly security and safety critical. In this work, we are the first to systematically study the security of state-of-the-art deep learning based ALC systems in their designed operational domains under physical-world adversarial attacks. We formulate the problem with a safety-critical attack goal, and a novel and domain-specific attack vector: dirty road patches. To systematically generate the attack, we adopt an optimization-based approach and overcome domain-specific design challenges such as camera frame inter-dependencies due to attack-influenced vehicle control, and the lack of objective function design for lane detection models. We evaluate our attack on a production ALC using 80 scenarios from real-world driving traces. The results show that our attack is highly effective with over 97.5% success rates and less than 0.903 sec average success time, which is substantially lower than the average driver reaction time. This attack is also found (1) robust to various real-world factors such as lighting conditions and view angles, (2) general to different model designs, and (3) stealthy from the driver's view. To understand the safety impacts, we conduct experiments using software-in-the-loop simulation and attack trace injection in a real vehicle. The results show that our attack can cause a 100% collision rate in different scenarios, including when tested with common safety features such as automatic emergency braking. We also evaluate and discuss defenses.