发表机构
The University of Arizona(亚利桑那大学)
机构由 AI 辅助整理,请以论文原文为准。AI 中文总结
针对协同感知中隐蔽单对象攻击,提出选择性两级贝叶斯信任估计器SABER,通过累积和筛选与参考加权Beta状态,提升攻击检测并降低误报率。
AI 中文摘要
协同感知(CP)使互联车辆能够超越自身传感器进行感知,但同时也使其依赖于无法独立验证的消息。一个被攻破的协作方可以巧妙地隐藏单个安全关键对象,或注入一个不存在的对象,同时正确报告其他许多对象。现有的贝叶斯信任机制汇总跨对象的协议,虽然对明显的非定向攻击有效,但要么导致高误报率(FPR),要么允许不相关的正确报告稀释针对隐蔽的单对象攻击的持续攻击证据。为解决此问题,我们提出SABER,一种选择性的两级贝叶斯信任估计器。第一级维护广泛的智能体和对象信任,保留对良性但低质量贡献者降权的能力。累积和筛选选择具有持续遗漏或未支持报告的智能体-对象对,进行聚焦贝叶斯评估。第二级将这些对与其他智能体的证据进行核对,并为每个对维护一个独立的、参考加权的Beta状态。最低的对分数约束智能体信任,防止不相关的报告稀释针对性的攻击。我们建立了在固定阈值下,攻击者侧信任减少更强且良性误报有界的充分条件。与最先进的CP防御相比,SABER提高了攻击检测率,同时降低了良性FPR。在OPV2V上,SABER在晚期融合中相比MATE将防御ROC-AUC提高了最多0.427,在中间融合中提高了0.337。针对高级中间融合数据伪造攻击,它相比ROBOSAC和LUCIA将检测率分别提高了最多96.40和67.07个百分点,同时降低了FPR。
英文摘要
Collaborative perception (CP) enables connected vehicles to see beyond their own sensors but makes them dependent on messages they cannot independently verify. A compromised collaborator can surgically conceal a single safety-critical object or inject a non-existing one while correctly reporting many others. Existing Bayesian trust mechanisms pool agreement across objects, which, while effective against blatant untargeted attacks, either incurs high false-positive rates (FPR), or allows unrelated correct reports to dilute persistent attack evidence for stealthy single-object attackers. To address this problem, we propose SABER, a selective two-tier Bayesian trust estimator. The first tier maintains broad agent and object trust, preserving the ability to downweight benign but low-quality contributors. Cumulative-sum screening selects agent--object pairs with persistent omissions or unsupported reports for focused Bayesian assessment. The second tier checks these pairs against other agents' evidence and maintains a separate, reference-weighted Beta state for each. The lowest pair score constrains agent trust, preventing unrelated reports from diluting a targeted attack. We establish sufficient conditions for stronger attacker-side trust reductions with bounded additional benign false alarms at fixed thresholds. Compared with state-of-the-art CP defenses, SABER improves attack detection while reducing benign FPRs. On OPV2V, SABER improves defense ROC-AUC over MATE by up to 0.427 in late fusion and 0.337 in intermediate fusion. Against advanced intermediate-fusion data fabrication attacks, it increases detection rates over ROBOSAC and LUCIA by up to 96.40 and 67.07 percentage points, respectively, while reducing FPRs.