[论文解读] Who is in Control? Practical Physical Layer Attack and Defense for mmWave based Sensing in Autonomous Vehicles
本文针对自动驾驶汽车中的毫米波雷达提出了实用的物理层攻击与防御方案,证明了欺骗攻击可可靠地操控障碍物检测,从而引发危险驾驶决策。通过真实世界测试平台验证,攻击者可欺骗障碍物或改变其感知位置,导致致命碰撞场景;同时,利用射频指纹识别与单类SVM,实现了98.9%的欺骗检测准确率。
With the wide bandwidths in millimeter wave (mmWave) frequency band that results in unprecedented accuracy, mmWave sensing has become vital for many applications, especially in autonomous vehicles (AVs). In addition, mmWave sensing has superior reliability compared to other sensing counterparts such as camera and LiDAR, which is essential for safety-critical driving. Therefore, it is critical to understand the security vulnerabilities and improve the security and reliability of mmWave sensing in AVs. To this end, we perform the end-to-end security analysis of a mmWave-based sensing system in AVs, by designing and implementing practical physical layer attack and defense strategies in a state-of-the-art mmWave testbed and an AV testbed in real-world settings. Various strategies are developed to take control of the victim AV by spoofing its mmWave sensing module, including adding fake obstacles at arbitrary locations and faking the locations of existing obstacles. Five real-world attack scenarios are constructed to spoof the victim AV and force it to make dangerous driving decisions leading to a fatal crash. Field experiments are conducted to study the impact of the various attack scenarios using a Lincoln MKZ-based AV testbed, which validate that the attacker can indeed assume control of the victim AV to compromise its security and safety. To defend the attacks, we design and implement a challenge-response authentication scheme and a RF fingerprinting scheme to reliably detect aforementioned spoofing attacks.
研究动机与目标
- 探究在自动驾驶汽车(AVs)中,毫米波雷达的实用物理层攻击的可行性及其影响,此类攻击对安全关键感知至关重要。
- 评估欺骗攻击是否可在真实世界条件下操控AV决策,导致危险或致命的驾驶后果。
- 设计并实现高效的防御机制,利用射频指纹识别与机器学习技术,以高可靠性检测毫米波雷达欺骗攻击。
- 通过展示端到端的真实世界攻击与防御,弥补现有研究的空白,与以往依赖不切实际假设或低频段的研究形成对比。
提出的方法
- 设计并实现两种核心攻击策略:(1) 在任意位置注入虚假障碍物;(2) 通过操控毫米波chirp信号的往返延迟,伪造现有障碍物的位置。
- 使用软件定义无线电(SDR)和自研毫米波测试平台,生成具有精确时间延迟的欺骗信号,使其在24–28 GHz频段内与合法雷达信号保持一致。
- 开发一种挑战-响应认证机制,通过对比响应时间与信号结构来验证信号来源,检测欺骗行为。
- 采用统计特征(标准差、峰度、偏度)对接收信号的幅度与相位进行射频指纹识别,并通过均方根(RMS)归一化进行标准化处理。
- 应用单类支持向量机(SVM)仅基于合法信号进行训练,通过检测特征分布偏移来识别欺骗攻击。
- 在基于林肯MKZ的自动驾驶测试平台上开展实地实验,评估真实驾驶条件下攻击与防御性能。
实验结果
研究问题
- RQ1是否能够通过精确控制感知位置与距离,对自动驾驶汽车中的毫米波雷达传感器实施欺骗攻击?
- RQ2攻击者能否持续跟踪目标AV,并动态更新欺骗信号以长期维持欺骗,从而影响AV决策?
- RQ3能否设计欺骗攻击,使AV误判前方障碍物已移出危险区域,从而导致其撞上障碍物?
- RQ4仅使用合法信号进行训练且无需事先掌握攻击波形的情况下,射频指纹识别与单类SVM能否实现高精度欺骗检测?
- RQ5在真实驾驶场景中,欺骗攻击在多大程度上损害AV感知系统的安全性和可靠性?
主要发现
- 作者成功演示了五个真实世界攻击场景,通过操控毫米波雷达感知,导致AV做出危险决策,如未能对障碍物停车。
- 基于林肯MKZ的自动驾驶测试平台实地实验表明,攻击者可可靠地欺骗障碍物并改变其感知位置,诱发碰撞等危险行为。
- 所提出的挑战-响应认证机制通过验证信号时序与结构,有效检测欺骗行为,显著降低实时运行中的误报率。
- 基于RMS归一化信号特征(幅度与相位的标准差、峰度、偏度)的射频指纹识别技术,能有效区分合法与欺骗信号。
- 基于单类SVM的欺骗检测系统仅使用3,000个合法信号进行训练,3,000个欺骗信号进行测试,检测准确率达到98.9%。
- 合法与欺骗信号的统计特征分布明显分离,即使在不了解攻击波形的情况下,也能实现可靠检测。
更好的研究,从现在开始
从阅读论文到最终审阅,大幅缩短您的研究时间。
无需绑定信用卡
本解读由 AI 生成,并经人工编辑审核。