Multi-Source Adversarial Sample Attack on Autonomous Vehicles

Multi-Source Adversarial Sample Attack on Autonomous Vehicles
复制标题

DOI:
10.1109/tvt.2021.3061065
复制
发表时间:
2021-03
影响因子:
6.8
通讯作者:
Zuobin Xiong;Honghui Xu;Wei Li;Zhipeng Cai
Zuobin Xiong;Honghui Xu;Wei Li;Zhipeng Cai
中科院分区:
计算机科学2区
文献类型:
--
作者:
Zuobin Xiong;Honghui Xu;Wei Li;Zhipeng Cai

文献摘要

相似文献

深度学习在自动驾驶汽车的物体检测和分类方面表现出色。然而,深度学习模型在对抗性样本面前的脆弱性使得自动驾驶汽车面临着严重的安全问题。虽然已经有许多研究对抗样本的著作,但其中只有少数被指定用于自动驾驶汽车的场景。此外,最先进的攻击模型只关注单一数据源,而没有考虑多个数据源之间的相关性。为了填补这一空白,我们提出了两种多源对抗样本攻击模型,包括并行攻击模型和融合攻击模型,以同时攻击自动驾驶汽车中的图像和激光雷达感知系统。在并行攻击模型中,对抗样本分别从原始图像和激光雷达数据中生成。在融合攻击模型中,通过充分挖掘数据融合和对抗样本生成的数据相关性,可以从一个低维向量中同时生成图像和激光雷达的对抗样本。通过全面的真实数据实验,我们验证了与最先进的技术相比,我们提出的模型在破解自动驾驶汽车的感知系统方面更强大、更高效。此外,我们还模拟了车载 Ad hoc 网络(VANET)中可能出现的攻击场景,以评估我们提出的方法的攻击性能。
Deep learning has an impressive performance of object detection and classification for autonomous vehicles. Nevertheless, the essential vulnerability of deep learning models to adversarial samples makes the autonomous vehicles suffer severe security and safety issues. Although a number of works have been proposed to study adversarial samples, only a few of them are designated for the scenario of autonomous vehicles. Moreover, the state-of-the-art attack models only focus on a single data source without considering the correlation among multiple data sources. To fill this blank, we propose two multi-source adversarial sample attack models, including the parallel attack model and the fusion attack model to simultaneously attack the image and LiDAR perception systems in the autonomous vehicles. In the parallel attack model, adversarial samples are generated from the original image and LiDAR data separately. In the fusion attack model, the adversarial samples of image and LiDAR can be generated from a low-dimension vector at the same time by fully exploring data correlation for data fusion and adversarial sample generation. Through comprehensive real-data experiments, we validate that our proposed models are more powerful and efficient to break down the perception systems of autonomous vehicles compared with the state-of-the-art. Furthermore, we simulate possible attack scenarios in Vehicular Ad hoc Networks (VANETs) to evaluate the attack performance of our proposed methods.