arXivDaily arXiv每日学术速递 周一至周五更新
arXiv周末暂无论文更新,休息一下吧,周末愉快~~
arXiv 2609.17856cs.CVcs.CRcs.MAcs.RO

探究异构协同感知的对抗鲁棒性

Investigating Adversarial Robustness of Heterogeneous Cooperative Perception

Chenyi Wang, Yutong Liu, Qingzhao Zhang, Ming F. Li

首次发表
浏览论文内容

中文总结 AI 辅助

本研究证明异构协同感知并非天然对抗攻击,提出HetPoison实现高效无标签攻击,并设计HetShield轻量信任层恢复83-95%的准确率。

中文摘要 AI 辅助

异构协同感知(CP)使具有不同传感器配置的网联车辆能够通过紧凑的特征图共享空间感知,其中接收方使用学习到的转换模块来协调这些特征图以进行融合和推理。先前针对同构环境下CP的攻击表明,数据交换引入了一个关键的攻击面:单个恶意智能体可以传输精心构造的特征,从邻居的融合场景中抹去真实物体。然而,人们普遍假设异构性天然地防御这些攻击,因为攻击者缺乏对受害者检测器的了解,且转换模块会扰乱对抗梯度。我们证明这种保护在很大程度上是一种错觉。使用匹配目标框架来标准化扰动预算、目标和前向路径,我们表明适当调整的迭代攻击能够缩小或逆转表观鲁棒性差距。然而,这些基于优化的攻击需要真实标签和迭代反向传播,这意味着它们并不构成实时运行的实战威胁。为弥合这一差距,我们引入了HetPoison,一种学习型生成器,能够在单次无标签前向传播中构造移除扰动。HetPoison无需访问受害者检测器即可跨主要异构设计迁移,其效果达到或超过昂贵的基于优化器的攻击。由于异构性本身并非防御手段,我们提出了HetShield,一种轻量级信任层,用于验证跨特征的空时一致性,恢复了被攻击降低的83%至95%的准确率,优于先前技术。

英文摘要

Heterogeneous cooperative perception (CP) enables connected vehicles with diverse sensor setups to share spatial awareness via compact feature maps, where receivers reconcile these maps using learned translation modules for fusion and inference. Prior attacks against CP in a homogeneous setting reveal that the data exchange introduces a critical attack surface: a single malicious agent can transmit crafted features that erase real objects from a neighbor's fused scene. Yet, it is widely hypothesized that heterogeneity naturally defends against these attacks, as the attacker lacks knowledge of the victim's detector and the translation module scrambles adversarial gradients. We demonstrate that this protection is largely an illusion. Using a matched-objective harness to standardize the perturbation budget, objective, and forward path, we show that properly tuned iterative attacks close or reverse the apparent robustness gap. However, these optimization-based attacks require ground-truth labels and iterative backpropagation, meaning they do not represent a practical field threat running in real-time. To bridge this gap, we introduce HetPoison, a learned generator that crafts a removal perturbation in a single, label-free forward pass. HetPoison transfers across major heterogeneous designs without requiring access to the victim's detector, matching or exceeding the effectiveness of expensive optimizer-based attacks. Since heterogeneity itself is not a defense, we propose HetShield, a lightweight trust layer that validates the spatiotemporal consistency across features, recovering 83--95% of the accuracy degraded by attacks, outperforming prior art.

发表机构

  • University of Arizona(亚利桑那大学)

机构由 AI 辅助整理,请以论文原文为准。

↑