Simple Physical Adversarial Examples against End-to-End Autonomous Driving Models

Simple Physical Adversarial Examples against End-to-End Autonomous Driving Models
复制标题

DOI:
10.1109/icess.2019.8782514
复制
发表时间:
2019-03
期刊:
2019 IEEE International Conference on Embedded Software and Systems (ICESS)
影响因子:
--
通讯作者:
Adith Boloor;Xin He;C. Gill;Yevgeniy Vorobeychik;Xuan Zhang
Adith Boloor;Xin He;C. Gill;Yevgeniy Vorobeychik;Xuan Zhang
中科院分区:
其他
文献类型:
--
作者:
Adith Boloor;Xin He;C. Gill;Yevgeniy Vorobeychik;Xuan Zhang

文献摘要

被引文献

相似文献

机器学习的最新进展,特别是深度神经网络等技术,正在推动一系列高风险应用,包括自动驾驶,自动驾驶通常依赖于深度学习进行感知。虽然感知的深度学习已被证明容易受到许多微妙的对抗性图像操纵的影响,但成功攻击的端到端演示(操纵物理环境并导致物理后果)却很少。此外,攻击通常涉及在像素级别精心构建的对抗性示例。我们在模拟中展示了对自动驾驶的第一次端到端攻击,使用简单的物理可实现的攻击:在道路上画黑线。这些攻击针对的是用于端到端自动驾驶控制的深度神经网络模型。系统的调查表明,这种攻击是令人惊讶的容易工程师,我们描述的场景(例如,右转),其中它们是高度有效的,以及其他不太脆弱的(例如,直行)。此外,我们使用网络去卷积来证明攻击通过诱导类似于训练中使用的完全不同的场景的激活模式而成功。
Recent advances in machine learning, especially techniques such as deep neural networks, are promoting a range of high-stakes applications, including autonomous driving, which often relies on deep learning for perception. While deep learning for perception has been shown to be vulnerable to a host of subtle adversarial manipulations of images, end-to-end demonstrations of successful attacks, which manipulate the physical environment and result in physical consequences, are scarce. Moreover, attacks typically involve carefully constructed adversarial examples at the level of pixels. We demonstrate the first end-to-end attacks on autonomous driving in simulation, using simple physically realizable attacks: the painting of black lines on the road. These attacks target deep neural network models for end-to-end autonomous driving control. A systematic investigation shows that such attacks are surprisingly easy to engineer, and we describe scenarios (e.g., right turns) in which they are highly effective, and others that are less vulnerable (e.g., driving straight). Further, we use network deconvolution to demonstrate that the attacks succeed by inducing activation patterns similar to entirely different scenarios used in training.