Skip to main content
QUICK REVIEW

[论文解读] Emerging Threats in Deep Learning-Based Autonomous Driving: A Comprehensive Survey

Hui Cao, Wenlong Zou|arXiv (Cornell University)|Oct 19, 2022
Adversarial Robustness in Machine Learning被引用 5
一句话总结

本文全面调查了基于深度学习的自动驾驶系统中新兴的安全威胁,重点关注物理世界中的对抗样本、后门攻击和隐私攻击,以及在鲁棒性和多模态融合环境下的威胁。论文提出了一套可信人工智能框架,包含评估系统和架构原则,以增强自动驾驶汽车的安全性和可信度。

ABSTRACT

Since the 2004 DARPA Grand Challenge, the autonomous driving technology has witnessed nearly two decades of rapid development. Particularly, in recent years, with the application of new sensors and deep learning technologies extending to the autonomous field, the development of autonomous driving technology has continued to make breakthroughs. Thus, many carmakers and high-tech giants dedicated to research and system development of autonomous driving. However, as the foundation of autonomous driving, the deep learning technology faces many new security risks. The academic community has proposed deep learning countermeasures against the adversarial examples and AI backdoor, and has introduced them into the autonomous driving field for verification. Deep learning security matters to autonomous driving system security, and then matters to personal safety, which is an issue that deserves attention and research.This paper provides an summary of the concepts, developments and recent research in deep learning security technologies in autonomous driving. Firstly, we briefly introduce the deep learning framework and pipeline in the autonomous driving system, which mainly include the deep learning technologies and algorithms commonly used in this field. Moreover, we focus on the potential security threats of the deep learning based autonomous driving system in each functional layer in turn. We reviews the development of deep learning attack technologies to autonomous driving, investigates the State-of-the-Art algorithms, and reveals the potential risks. At last, we provides an outlook on deep learning security in the autonomous driving field and proposes recommendations for building a safe and trustworthy autonomous driving system.

研究动机与目标

  • 识别并分析针对基于深度学习的自动驾驶系统特有的新兴人工智能安全威胁。
  • 探讨物理世界攻击、环境变化下的鲁棒性以及多模态传感器融合带来的独特挑战。
  • 回顾专为自动驾驶设计的最先进对抗攻击与防御技术。
  • 提出一个全面的框架,用于构建自动驾驶中的可信人工智能,包括评估系统和架构原则。
  • 强调需要超越点对点解决方案的集成化安全措施,以确保安全性和公众信任。

提出的方法

  • 系统性地将自动驾驶中深度学习威胁按三个关键维度进行分类:物理世界适用性、环境变化下的鲁棒性,以及多模态融合的稳定性。
  • 回顾基础的对抗攻击方法,包括白盒攻击(如 FGSM、PGD、CW)、黑盒攻击(如基于迁移的攻击、梯度近似、基于得分的攻击、基于决策的攻击),以及基于优化的攻击。
  • 在自动驾驶数据和模型流程的背景下,分析模型反演、成员推断、数据 poisoning 和后门攻击。
  • 提出一种多层防御策略,基于对抗鲁棒性评估、跨域数据鲁棒性以及训练数据安全验证。
  • 提出一个可信人工智能架构框架,强调透明度、公平性、隐私保护、责任追究以及人工监督。
  • 评估车联网物联网中联邦学习与边缘计算的风险,包括拜占庭攻击和因车辆间数据相似性导致的隐私泄露。

实验结果

研究问题

  • RQ1基于深度学习的自动驾驶系统所面临的安全威胁,与一般人工智能应用相比有何独特之处?
  • RQ2对抗样本和后门在真实物理环境以及多模态传感器融合系统中如何表现?
  • RQ3在光照、天气和高速运动等变化条件下,如何确保人工智能模型的鲁棒性?
  • RQ4现有防御机制如何被适配或扩展,以应对自动驾驶系统复杂、多组件的架构?
  • RQ5构建自动驾驶车辆可信人工智能生态所需的系统性架构与评估框架是什么?

主要发现

  • 自动驾驶中的对抗攻击不仅限于数字模拟,还能在物理世界中成功实施,通过篡改的交通标志或传感器输入影响真实车辆。
  • 对抗样本的鲁棒性在环境变化下受到显著挑战,要求攻击与防御在不同光照、天气和视角下均保持稳定。
  • 多模态融合环境(如摄像头、激光雷达、雷达)引入了新的攻击面,对抗扰动可在不同模态间注入,并在融合输出中保持有效性。
  • 最先进的攻击方法,如 PGD、CW 和基于决策的攻击(如边界攻击),在将对抗样本迁移至真实自动驾驶系统方面表现出极高的成功率。
  • 车联网物联网中的联邦学习增加了拜占庭攻击和隐私泄露的风险,原因在于车辆间数据分布相似,且个别节点可能被攻破。
  • 一个完整的可信人工智能系统不仅需要抵御特定威胁,还需通过整合安全、透明度、公平性、隐私保护和责任追究的全生命周期架构,实现整体可信。

更好的研究,从现在开始

从阅读论文到最终审阅,大幅缩短您的研究时间。

无需绑定信用卡

本解读由 AI 生成,并经人工编辑审核。