|
Frontiers of Information Technology & Electronic Engineering
ISSN 2095-9184 (print), ISSN 2095-9230 (online)
2025 Vol.26 No.4 P.510-533
A comprehensive survey of physical adversarial vulnerabilities in autonomous driving systems
Abstract: Autonomous driving systems (ADSs) have attracted wide attention in the machine learning communities. With the help of deep neural networks (DNNs), ADSs have shown both satisfactory performance under significant uncertainties in the environment and the ability to compensate for system failures without external intervention. However, the vulnerability of ADSs has raised concerns since DNNs have been proven vulnerable to adversarial attacks. In this paper, we present a comprehensive survey of current physical adversarial vulnerabilities in ADSs. We first divide the physical adversarial attack methods and defense methods by their restrictions of deployment into three scenarios: the real-world, simulator-based, and digital-world scenarios. Then, we consider the adversarial vulnerabilities that focus on various sensors in ADSs and separate them as camera-based, light detection and ranging (LiDAR) based, and multifusion-based attacks. Subsequently, we divide the attack tasks by traffic elements. For the physical defenses, we establish the taxonomy with reference to input image preprocessing, adversarial example detection, and model enhancement for the DNN models to achieve full coverage of the adversarial defenses. Based on the above survey, we finally discuss the challenges in this research field and provide further outlook on future directions.
Key words: Physical adversarial attacks; Physical adversarial defenses; Artificial intelligence safety; Deep learning; Autonomous driving system; Data-fusion; Adversarial vulnerability
1天津大学智能与计算学部,中国天津市,300072
2天津市机器学习重点实验室,中国天津市,300072
3中汽智联技术有限公司,中国天津市,300000
摘要:自动驾驶系统(ADS)在机器学习领域受到广泛关注。借助深度神经网络(DNN),这些系统在面对环境重大不确定性时不仅展现满意性能,还能在没有外部干预情况下纠正系统故障。然而,由于深度神经网络易受对抗样本攻击,自动驾驶系统的脆弱性成为研究焦点。本文详细调查了当前自动驾驶系统存在的物理对抗漏洞。首先,根据部署限制将物理对抗攻击和防御方法分为3类:现实世界、仿真世界及数字世界。分析自动驾驶系统中不同传感器的对抗攻击,将其分为基于摄像头的攻击、基于激光雷达(LiDAR)的攻击及基于多传感器融合的攻击。根据交通元素将攻击任务分类。对于物理防御,以图像预处理、对抗检测和模型增强防御为基础,为深度神经网络模型建立一个全面的防御体系。最终讨论了该研究领域面临的挑战,并展望未来发展方向。
关键词组:
References:
Open peer comments: Debate/Discuss/Question/Opinion
<1>
DOI:
10.1631/FITEE.2300867
CLC number:
TP391
Download Full Text:
Downloaded:
974
Download summary:
<Click Here>Downloaded:
72Clicked:
1382
Cited:
0
On-line Access:
2025-05-06
Received:
2023-12-25
Revision Accepted:
2024-04-07
Crosschecked:
2025-05-06