Publishing Service

Polishing & Checking

Frontiers of Information Technology & Electronic Engineering

ISSN 2095-9184 (print), ISSN 2095-9230 (online)

A comprehensive survey of physical adversarial vulnerabilities in autonomous driving systems

Abstract: Autonomous driving systems (ADSs) have attracted wide attention in the machine learning communities. With the help of deep neural networks (DNNs), ADSs have shown both satisfactory performance under significant uncertainties in the environment and the ability to compensate for system failures without external intervention. However, the vulnerability of ADSs has raised concerns since DNNs have been proven vulnerable to adversarial attacks. In this paper, we present a comprehensive survey of current physical adversarial vulnerabilities in ADSs. We first divide the physical adversarial attack methods and defense methods by their restrictions of deployment into three scenarios: the real-world, simulator-based, and digital-world scenarios. Then, we consider the adversarial vulnerabilities that focus on various sensors in ADSs and separate them as camera-based, light detection and ranging (LiDAR) based, and multifusion-based attacks. Subsequently, we divide the attack tasks by traffic elements. For the physical defenses, we establish the taxonomy with reference to input image preprocessing, adversarial example detection, and model enhancement for the DNN models to achieve full coverage of the adversarial defenses. Based on the above survey, we finally discuss the challenges in this research field and provide further outlook on future directions.

Key words: Physical adversarial attacks; Physical adversarial defenses; Artificial intelligence safety; Deep learning; Autonomous driving system; Data-fusion; Adversarial vulnerability

Chinese Summary  <12> 面向自动驾驶系统的物理对抗脆弱性综述

赵帅1,2,3,张博渊1,2,石育澄1,2,翟洋1,2,3,韩亚洪1,2,胡清华1,2
1天津大学智能与计算学部,中国天津市,300072
2天津市机器学习重点实验室,中国天津市,300072
3中汽智联技术有限公司,中国天津市,300000
摘要:自动驾驶系统(ADS)在机器学习领域受到广泛关注。借助深度神经网络(DNN),这些系统在面对环境重大不确定性时不仅展现满意性能,还能在没有外部干预情况下纠正系统故障。然而,由于深度神经网络易受对抗样本攻击,自动驾驶系统的脆弱性成为研究焦点。本文详细调查了当前自动驾驶系统存在的物理对抗漏洞。首先,根据部署限制将物理对抗攻击和防御方法分为3类:现实世界、仿真世界及数字世界。分析自动驾驶系统中不同传感器的对抗攻击,将其分为基于摄像头的攻击、基于激光雷达(LiDAR)的攻击及基于多传感器融合的攻击。根据交通元素将攻击任务分类。对于物理防御,以图像预处理、对抗检测和模型增强防御为基础,为深度神经网络模型建立一个全面的防御体系。最终讨论了该研究领域面临的挑战,并展望未来发展方向。

关键词组:物理对抗攻击;物理对抗防御;人工智能安全;深度学习;自动驾驶系统;数据融合;对抗脆弱性


Share this article to: More

Go to Contents

References:

<Show All>

Open peer comments: Debate/Discuss/Question/Opinion

<1>

Please provide your name, email address and a comment





DOI:

10.1631/FITEE.2300867

CLC number:

TP391

Download Full Text:

Click Here

Downloaded:

973

Download summary:

<Click Here> 

Downloaded:

72

Clicked:

1381

Cited:

0

On-line Access:

2025-05-06

Received:

2023-12-25

Revision Accepted:

2024-04-07

Crosschecked:

2025-05-06

Journal of Zhejiang University-SCIENCE, 38 Zheda Road, Hangzhou 310027, China
Tel: +86-571-87952276; Fax: +86-571-87952331; E-mail: jzus@zju.edu.cn
Copyright © 2000~ Journal of Zhejiang University-SCIENCE