AI 中文总结
研究针对置信驱动的V2X协同感知的安全问题,提出伪装良性攻击利用空间置信机制降低检测性能。发现现有基于信任的防御弱点,进而提出GLST通过多视角评估协作者可靠性,实验表明其在多攻击者场景下鲁棒性强,对多种攻击有效。
AI 中文摘要
协同感知(CP)通过使联网车辆通过V2X交换中间特征来改善自动驾驶感知。置信驱动的稀疏通信仅传输感知关键的空间区域,从而减少带宽,但带来安全风险:一旦协作者被攻破,高置信度或自我不确定区域中的恶意特征在融合过程中可能被优先选择和放大。以Where2comm为代表框架,我们表明所提出的伪装良性攻击通过向不确定但感知关键区域注入隐秘扰动来利用其空间置信机制,在保留类似良性特征的同时大幅降低3D目标检测性能。除了这种攻击框架对,我们还发现现有基于信任的防御存在更广泛的弱点:它们主要依赖单个一致性信号,当多个攻击者形成使信任估计产生偏差的伪共识时容易受到攻击。因此,我们提出了全局-局部结构信任(GLST),一种轻量级防御,通过三个互补视角评估协作者可靠性:全局特征一致性、多尺度局部残差一致性以及与自身语义拓扑的结构一致性。由此产生的信任分数指导特征融合以抑制不可靠的协作者。在OPV2V上的实验表明,GLST在对抗单攻击者伪装良性攻击时具有竞争力的性能,在多攻击者设置中具有更强的鲁棒性。在四攻击者伪装良性攻击下,GLST保持0.69 AP@0.3,而现有的单信号防御则严重退化。GLST对基于梯度的攻击如PGD也仍然有效,表明多级信任建模对于确保置信驱动的CP至关重要。
英文摘要
Collaborative perception (CP) improves autonomous-driving perception by enabling connected vehicles to exchange intermediate features via V2X. Confidence-driven sparse communication reduces bandwidth by transmitting only perception-critical spatial regions, but creates a security risk: once a collaborator is compromised, malicious features in high-confidence or ego-uncertain regions may be preferentially selected and amplified during fusion. Using Where2comm as a representative framework, we show that the proposed Pretend Benign attack exploits its spatial-confidence mechanism by injecting stealthy perturbations into uncertain yet perception-critical regions, substantially degrading 3D object detection while preserving benign-like feature characteristics. Beyond this attack-framework pair, we identify a broader weakness of existing trust-based defenses: their reliance primarily on a single consistency signal leaves them vulnerable when multiple attackers form a pseudo-consensus that biases trust estimation. We therefore propose Global-Local Structural Trust (GLST), a lightweight defense that assesses collaborator reliability through three complementary perspectives: global feature consistency, multi-scale local residual consistency, and structural consistency with ego-side semantic topology. The resulting trust scores guide feature fusion to suppress unreliable collaborators. Experiments on OPV2V show that GLST achieves competitive performance against single-attacker Pretend Benign attacks and substantially stronger robustness in multi-attacker settings. Under a four-attacker Pretend Benign attack, GLST maintains 0.69 AP@0.3, whereas existing single-signal defenses degrade severely. GLST also remains effective against gradient-based attacks such as PGD, indicating that multi-level trust modeling is essential for securing confidence-driven CP.