Exploring Adversarial Robustness of Multi-Sensor Perception Systems in Self Driving
arXiv:2101.06784
Abstract
Modern self-driving perception systems have been shown to improve upon processing complementary inputs such as LiDAR with images. In isolation, 2D images have been found to be extremely vulnerable to adversarial attacks. Yet, there have been limited studies on the adversarial robustness of multi-modal models that fuse LiDAR features with image features. Furthermore, existing works do not consider physically realizable perturbations that are consistent across the input modalities. In this paper, we showcase practical susceptibilities of multi-sensor detection by placing an adversarial object on top of a host vehicle. We focus on physically realizable and input-agnostic attacks as they are feasible to execute in practice, and show that a single universal adversary can hide different host vehicles from state-of-the-art multi-modal detectors. Our experiments demonstrate that successful attacks are primarily caused by easily corrupted image features. Furthermore, we find that in modern sensor fusion methods which project image features into 3D, adversarial attacks can exploit the projection process to generate false positives across distant regions in 3D. Towards more robust multi-modal perception systems, we show that adversarial training with feature denoising can boost robustness to such attacks significantly. However, we find that standard adversarial defenses still struggle to prevent false positives which are also caused by inaccurate associations between 3D LiDAR points and 2D pixels.
References in corpus (13)
- Rethinking Atrous Convolution for Semantic Image Segmentation
- On Evaluating Adversarial Robustness
- Deep Continuous Fusion for Multi-Sensor 3D Object Detection
- A study of the effect of JPG compression on adversarial images
- AdvPC: Transferable Adversarial Perturbations on 3D Point Clouds
- Differentiable Rendering: A Survey
- Adversarial Examples that Fool Detectors
- Towards Robust LiDAR-based Perception in Autonomous Driving: General Black-box Adversarial Sensor Attack and Countermeasures
- Adversarial Attack and Defense on Point Sets
- Unrestricted Adversarial Examples via Semantic Manipulation
- Adversarial Objects Against LiDAR-Based Autonomous Driving Systems
- Adversarial camera stickers: A physical camera-based attack on deep learning systems
- Investigating Vulnerability to Adversarial Examples on Multimodal Data Fusion in Deep Learning
Cited by in corpus (4)
- Security Analysis of Camera-LiDAR Fusion Against Black-Box Attacks on Autonomous Vehicles
- Neural Network Guided Evolutionary Fuzzing for Finding Traffic Violations of Autonomous Vehicles
- Towards Adversarially Robust and Domain Generalizable Stereo Matching by Rethinking DNN Feature Backbones
- Adversarial Robustness of Deep Sensor Fusion Models