Towards Autonomous Driving Model Resistant to Adversarial Attack

Towards Autonomous Driving Model Resistant to Adversarial Attack
复制标题

DOI:
10.1080/08839514.2023.2193461
复制
发表时间:
2023-03
影响因子:
2.8
通讯作者:
Kabid Hassan Shibly;Md. Delwar Hossain;Hiroyuki Inoue;Yuzo Taenaka;Y. Kadobayashi
Kabid Hassan Shibly;Md. Delwar Hossain;Hiroyuki Inoue;Yuzo Taenaka;Y. Kadobayashi
中科院分区:
计算机科学4区
文献类型:
--
作者:
Kabid Hassan Shibly;Md. Delwar Hossain;Hiroyuki Inoue;Yuzo Taenaka;Y. Kadobayashi

文献摘要

相似文献

摘要互联和自动驾驶汽车(CAV)通过创新的嵌入式设备提供更高的效率和便利性。然而,这些技术的发展往往忽视了安全措施,导致漏洞可以被黑客利用。承认CAV系统受到损害,它可能导致不安全的驾驶条件,并对人类安全构成威胁。在CAV的开发中优先考虑安全措施和功能增强,对于确保其安全性和可靠性并增强消费者对该技术的信任至关重要。CAV使用人工智能来控制其驾驶行为,这很容易受到模型中微小变化的影响,这些变化可能会严重影响并可能误导系统。为了解决这个问题,本研究提出了一种防御机制,该机制使用自动编码器和压缩内存模块来存储正常图像特征,并防止对抗性输入的意外泛化。针对Nvidia Dave-2驾驶模型,使用FGSM和AdvGAN研究了所提出的解决方案以对抗劫持、消失、制造和错误标记攻击,并发现该解决方案是有效的,在白盒设置中的成功率为93.8%和91.2%,在FGSM和AdvGAN的黑盒设置中,分别为74.1%和64.4%。这将白盒设置中的结果提高了24.7\% 24.7%黑盒设置中的结果提高了21.5\% 21.5%。
ABSTRACT Connected and Autonomous Vehicles (CAVs) offer improved efficiency and convenience through innovative embedded devices. However, the development of these technologies has often neglected security measures, leading to vulnerabilities that can be exploited by hackers. Conceding that a CAV system is compromised, it can result in unsafe driving conditions and pose a threat to human safety. Prioritizing both security measures and functional enhancements on development of CAVs is essential to ensure their safety and reliability and enhance consumer trust in the technology. CAVs use artificial intelligence to control their driving behavior, which can be easily influenced by small changes in the model that can significantly impact and potentially mislead the system. To address this issue, this study proposed a defense mechanism that uses an autoencoder and a compressive memory module to store normal image features and prevent unexpected generalization on adversarial inputs. The proposed solution was studied against Hijacking, Vanishing, Fabrication, and Mislabeling attacks using FGSM and AdvGAN against the Nvidia Dave-2 driving model, and was found to be effective, with success rates of $$93.8\% $$93.8% and $$91.2\% $$91.2% in a Whitebox setup, and $$74.1\% $$74.1% and $$64.4\% $$64.4% in a Blackbox setup for FGSM and AdvGAN, respectively. That improves the results by $$24.7\% $$24.7% in Whitebox setup $$21.5\% $$21.5% in Blackbox setup.