针对自动驾驶汽车的对抗性校准攻击
Adversarial Calibration Attack on Autonomous Vehicles
浏览论文内容
中文总结 AI 辅助
该研究提出针对自动驾驶汽车相机-激光雷达在线校准的对抗性校准攻击(ACA),通过对抗性海报可诱导校准误差,引发感知等系统错误,在仿真和物理实验中均验证了其有效性。
中文摘要 AI 辅助
自动驾驶汽车(AVs)依赖准确的相机-激光雷达校准来实现多模态传感器融合。实际应用中,校准可能因振动、温度变化或微小的传感器位移而发生漂移,这催生了在线校准算法,这类算法可在运行时检测并纠正校准错位,使车辆无需返回工厂即可继续运行。现有的AV攻击大多假设校准是正确的,而我们则将在线传感器校准识别为一个新的攻击面。被篡改的校准更新会在后续的融合操作中持续存在,引发从感知到规划和控制的全系统错误传播。我们提出了对抗性校准攻击(ACA),这是首个针对相机-激光雷达在线校准的物理攻击。利用一张对抗性海报,ACA首先欺骗校准检测器以触发校准过程,随后引导校准估计器朝向不正确的变换。我们通过统一优化共同设计海报的几何形状和纹理以实现这两个目标。我们在基准数据集、仿真和物理实验中对ACA进行了评估。在KITTI和nuScenes等基准数据集上,ACA可诱导高达33.9度的平均旋转校准误差,从而严重降低目标检测性能。在CARLA仿真器中,当攻击者精心设计的易受攻击场景接受被篡改的校准时,该攻击会导致碰撞。在真实的Husky机器人上,一张打印的对抗性海报成功再现了该校准误差。这些结果表明,在线校准是自动驾驶汽车一个实际且关乎安全的攻击面。
英文摘要
Autonomous vehicles (AVs) rely on accurate camera-LiDAR calibration for multimodal sensor fusion. In practice, calibration can drift due to vibration, temperature variation, or minor sensor displacement, motivating online calibration algorithms that detect and correct misalignment at runtime while allowing the vehicle to continue operating without a factory visit. Existing AV attacks largely assume correct calibration. We instead identify online sensor calibration as a new attack plane. A corrupted calibration update can persist across subsequent fusion operations, causing system-wide errors that propagate from perception to planning and control. We present Adversarial Calibration Attack (ACA), the first physical attack against camera-LiDAR online calibration. Using a single adversarial poster, ACA first spoofs the miscalibration detector to trigger the calibration process and then steers the calibration estimator toward an incorrect transformation. A unified optimization jointly designs the poster's geometry and texture for both objectives. We evaluate ACA across benchmark datasets, simulation, and physical experiments. On benchmark datasets such as KITTI and nuScenes, ACA induces up to 33.9 degrees mean rotational calibration error, thereby severely degrading object detection. In the CARLA simulator, the attack causes a collision when the corrupted calibration is accepted in vulnerable scenarios crafted by the attacker. On a real Husky robot, a printed adversarial poster successfully reproduces the calibration error. These results demonstrate that online calibration is a practical and safety-critical attack surface for AVs.
发表机构
- Texas Tech University(德克萨斯理工大学)
- University of Arizona(亚利桑那大学)
- University of Michigan(密歇根大学)
机构由 AI 辅助整理,请以论文原文为准。