发表机构
Nanyang Technological University; City University of Hong Kong(南洋理工大学; 香港城市大学)
机构由 AI 辅助整理,请以论文原文为准。AI 中文总结
AdROD是面向自动驾驶的嵌入式随机集成防御软件,采用低秩超网络与功能多样性机制,设两种服务模式,经多类评估优于基线防御,可在对抗场景下保持实时安全停车。
AI 中文摘要
基于相机的目标检测器易受旨在抑制检测的物理对抗攻击。尽管对抗训练和输入净化能提供一定防护,但它们常过拟合于特定攻击分布,在自适应攻击者面前失效。本文提出AdROD,一种面向自动驾驶的嵌入式随机集成防御软件。AdROD采用低秩超网络,其参数占用仅为标准超网络的1.6%,可逐帧生成多样化检测器,使攻击者无法及时获取部署的检测器。为进一步提升对抗鲁棒性,AdROD引入了一种新颖的功能多样性机制,该机制将随机权重更新与独特的输入空间变换相结合。我们设计了AdROD的两种服务模式,在鲁棒性与运行时开销之间实现不同权衡:AdROD-I是连续保护模式,用于实现最大弹性,利用检测器间的分歧恢复受损检测;AdROD-II是按需模式,由目标跟踪中的运动学不连续性触发。通过使用合成基准、物理部署的对抗补丁以及OpenCDA协同仿真器中的端到端安全测试进行全面评估,AdROD的性能优于五种基线防御方法,且与所评估的对抗训练基线相比表现出更优的泛化能力,同时保持实时性能,可在装有对抗补丁的停车标志处安全停车。
英文摘要
Camera-based object detectors are vulnerable to physical adversarial attacks designed to suppress detections. While adversarial training and input purification offer some protection, they often overfit to specific attack distributions and fail on adaptive adversaries. This paper presents AdROD, an embedded, stochastic ensemble defense software designed for autonomous driving. AdROD employs {\em low-rank HyperNetworks}, which require only 1.6\% of the parameter footprint of standard HyperNetworks, to generate diverse detectors at a per-frame rate, making it impractical for attackers to obtain the deployed detectors in time. To further improve adversarial robustness, AdROD incorporates a novel \emph{functional diversity} mechanism, which couples stochastic weight updates with unique input-space transformations. We design two serving modes of AdROD that strike different trade-offs between robustness and runtime overhead: AdROD-I, a continuous protection mode for maximum resilience that leverages inter-detector disagreement to recover compromised detections, and AdROD-II, an on-demand mode triggered by kinematic discontinuities in object tracking. Through comprehensive evaluation with synthetic benchmarks, physically deployed adversarial patches, and end-to-end safety tests in the OpenCDA co-simulator, AdROD outperforms five baseline defenses and exhibits superior generalizability compared with the evaluated adversarial-training baselines, while maintaining real-time performance for safely stopping the vehicle at a stop sign instrumented with adversarial patches.