Invisible for both Camera and LiDAR: Security of Multi-Sensor Fusion based Perception in Autonomous Driving Under Physical-World Attacks

Invisible for both Camera and LiDAR: Security of Multi-Sensor Fusion based Perception in Autonomous Driving Under Physical-World Attacks
复制标题

DOI:
10.1109/sp40001.2021.00076
复制
发表时间:
2021-05
期刊:
2021 IEEE Symposium on Security and Privacy (SP)
影响因子:
--
通讯作者:
Yulong Cao;Ningfei Wang;Chaowei Xiao;Dawei Yang;Jin Fang;Ruigang Yang;Qi Alfred Chen;Mingyan Liu-Min
Yulong Cao;Ningfei Wang;Chaowei Xiao;Dawei Yang;Jin Fang;Ruigang Yang;Qi Alfred Chen;Mingyan Liu-Min
中科院分区:
其他
文献类型:
--
作者:
Yulong Cao;Ningfei Wang;Chaowei Xiao;Dawei Yang;Jin Fang;Ruigang Yang;Qi Alfred Chen;Mingyan Liu-Min

文献摘要

被引文献

相似文献

在自动驾驶(AD)系统中,感知是安全和安全的关键。尽管之前对其安全问题进行了各种研究,但所有这些研究都只考虑了对基于摄像头或LiDAR的AD感知的攻击。然而,当今的生产AD系统主要采用基于多传感器融合(MSF)的设计,在假设并非所有融合源都(或可以)同时受到攻击的情况下,该设计原则上可以更鲁棒地抵抗这些攻击。在本文中,我们提出了第一个研究的安全问题,基于MSF-AD系统的感知。我们通过探索同时攻击所有聚变源的可能性,直接挑战上述基本的MSF设计假设。这让我们第一次了解MSF作为AD感知的一般防御策略可以从根本上提供多少安全保障。我们将攻击描述为一个优化问题,以生成一个物理可实现的对抗性3D打印对象,误导AD系统无法检测到它,从而撞上它。为了系统地生成这样的物理世界攻击,我们提出了一种新颖的攻击流水线,其解决了两个主要的设计挑战:(1)不可区分的目标相机和LiDAR感测系统,以及(2)在基于LiDAR的AD感知中普遍使用的不可区分的单元级聚合特征。我们评估我们的攻击MSF算法包括在代表性的开源行业级AD系统在现实世界中的驾驶场景。我们的结果表明,该攻击在不同对象类型和MSF算法上的成功率超过90%。我们的攻击也被发现是隐形的,对受害者位置的鲁棒性,可在MSF算法中转移,并且在3D打印并被LiDAR和相机设备捕获后,物理世界是可实现的。为了具体评估端到端的安全影响,我们进一步进行了模拟评估,结果表明,对于工业级AD系统,它可以导致100%的车辆碰撞率。我们还评估和讨论防御策略。
In Autonomous Driving (AD) systems, perception is both security and safety critical. Despite various prior studies on its security issues, all of them only consider attacks on camera-or LiDAR-based AD perception alone. However, production AD systems today predominantly adopt a Multi-Sensor Fusion (MSF) based design, which in principle can be more robust against these attacks under the assumption that not all fusion sources are (or can be) attacked at the same time. In this paper, we present the first study of security issues of MSF-based perception in AD systems. We directly challenge the basic MSF design assumption above by exploring the possibility of attacking all fusion sources simultaneously. This allows us for the first time to understand how much security guarantee MSF can fundamentally provide as a general defense strategy for AD perception.We formulate the attack as an optimization problem to generate a physically-realizable, adversarial 3D-printed object that misleads an AD system to fail in detecting it and thus crash into it. To systematically generate such a physical-world attack, we propose a novel attack pipeline that addresses two main design challenges: (1) non-differentiable target camera and LiDAR sensing systems, and (2) non-differentiable cell-level aggregated features popularly used in LiDAR-based AD perception. We evaluate our attack on MSF algorithms included in representative open-source industry-grade AD systems in real-world driving scenarios. Our results show that the attack achieves over 90% success rate across different object types and MSF algorithms. Our attack is also found stealthy, robust to victim positions, transferable across MSF algorithms, and physical-world realizable after being 3D-printed and captured by LiDAR and camera devices. To concretely assess the end-to-end safety impact, we further perform simulation evaluation and show that it can cause a 100% vehicle collision rate for an industry-grade AD system. We also evaluate and discuss defense strategies.