SlowTrack: Increasing the Latency of Camera-Based Perception in Autonomous Driving Using Adversarial Examples

Type: Article

Publication Date: 2024-03-24

Citations: 4

DOI: https://doi.org/10.1609/aaai.v38i5.28200

Abstract

In Autonomous Driving (AD), real-time perception is a critical component responsible for detecting surrounding objects to ensure safe driving. While researchers have extensively explored the integrity of AD perception due to its safety and security implications, the aspect of availability (real-time performance) or latency has received limited attention. Existing works on latency-based attack have focused mainly on object detection, i.e., a component in camera-based AD perception, overlooking the entire camera-based AD perception, which hinders them to achieve effective system-level effects, such as vehicle crashes. In this paper, we propose SlowTrack, a novel framework for generating adversarial attacks to increase the execution time of camera-based AD perception. We propose a novel two-stage attack strategy along with the three new loss function designs. Our evaluation is conducted on four popular camera-based AD perception pipelines, and the results demonstrate that SlowTrack significantly outperforms existing latency-based attacks while maintaining comparable imperceptibility levels. Furthermore, we perform the evaluation on Baidu Apollo, an industry-grade full-stack AD system, and LGSVL, a production-grade AD simulator, with two scenarios to compare the system-level effects of SlowTrack and existing attacks. Our evaluation results show that the system-level effects can be significantly improved, i.e., the vehicle crash rate of SlowTrack is around 95% on average while existing works only have around 30%.

Locations

  • Proceedings of the AAAI Conference on Artificial Intelligence - View - PDF
  • arXiv (Cornell University) - View - PDF

Similar Works

Action Title Year Authors
+ PDF Chat SlowPerception: Physical-World Latency Attack against Visual Perception in Autonomous Driving 2024 Chen Ma
Ningfei Wang
Zhengyu Zhao
Qi Alfred Chen
Chao Shen
+ PDF Chat Adversarial Attack and Defense of YOLO Detectors in Autonomous Driving Scenarios 2022 Jung Im Choi
Qing Tian
+ TPatch: A Triggered Physical Adversarial Patch 2024 Wenjun Zhu
Xiaoyu Ji
Yushi Cheng
Shibo Zhang
Wenyuan Xu
+ Adversarial Attacks on Multi-task Visual Perception for Autonomous Driving 2021 Ibrahim Sobh
A. Hamed
Varun Kumar
Senthil Yogamani
+ Adversarial Attacks on Multi-task Visual Perception for Autonomous Driving 2021 Ibrahim Sobh
Ahmed Abdeen Hamed
Varun Ravi Kumar
Senthil Yogamani
+ Fooling Detection Alone is Not Enough: Adversarial Attack against Multiple Object Tracking 2020 Yunhan Jia
Yantao Lu
Junjie Shen
Qi Alfred Chen
Hao Chen
Zhenyu Zhong
Tao Wei
+ Fooling Detection Alone is Not Enough: First Adversarial Attack against Multiple Object Tracking 2019 Yunhan Jia
Yantao Lu
Junjie Shen
Qi Alfred Chen
Zhenyu Zhong
Tao Wei
+ PDF Chat A Real-Time Defense Against Object Vanishing Adversarial Patch Attacks for Object Detection in Autonomous Vehicles 2024 Jaden Mu
+ PDF Chat Evaluating the Adversarial Robustness of Detection Transformers 2024 Amirhossein Nazeri
Chunheng Zhao
Pierluigi Pisu
+ Physical Attack on Monocular Depth Estimation with Optimal Adversarial Patches 2022 Zhiyuan Cheng
James Liang
Hongjun Choi
Guanhong Tao
Zhiwen Cao
Dongfang Liu
Xiangyu Zhang
+ PDF Chat Weighted Average Precision: Adversarial Example Detection for Visual Perception Of Autonomous Vehicles 2021 Weiheng Chai
Yantao Lu
Senem Velipasalar
+ A Man-in-the-Middle Attack against Object Detection Systems 2022 Han Wu
Sareh Rowlands
Johan Wahlström
+ Runtime Stealthy Perception Attacks against DNN-based Adaptive Cruise Control Systems 2023 Xugui Zhou
Anqi Chen
Maxfield Kouzel
Haotian Ren
Morgan McCarty
Cristina Nita-Rotaru
Homa Alemzadeh
+ PDF Chat Physical Backdoor Attacks to Lane Detection Systems in Autonomous Driving 2022 Xingshuo Han
Guowen Xu
Yuan Zhou
Xuehuan Yang
Jiwei Li
Tianwei Zhang
+ PDF Chat Invisible for both Camera and LiDAR: Security of Multi-Sensor Fusion based Perception in Autonomous Driving Under Physical-World Attacks 2021 Yulong Cao
Ningfei Wang
Chaowei Xiao
Dawei Yang
Fang Jin
Ruigang Yang
Qi Alfred Chen
Mingyan Liu
Bo Li
+ Adversarial Driving: Attacking End-to-End Autonomous Driving 2021 Han Wu
Syed Yunas
Sareh Rowlands
Wenjie Ruan
Johan Wahlström
+ PDF Chat Adversarial Driving: Attacking End-to-End Autonomous Driving 2023 Han Wu
Syed Yunas
Sareh Rowlands
Wenjie Ruan
Johan Wahlström
+ Weighted Average Precision: Adversarial Example Detection in the Visual Perception of Autonomous Vehicles 2020 Yilan Li
Senem Velipasalar
+ Moving Target Defense for Deep Visual Sensing against Adversarial Examples 2019 Qun Song
Zhenyu Yan
Rui Tan
+ Adversarial Driving: Attacking End-to-End Autonomous Driving Systems. 2021 Han Wu
Wenjie Ruan

Works Cited by This (23)

Action Title Year Authors
+ PDF Chat Simple online and realtime tracking 2016 Alex Bewley
Zongyuan Ge
Lionel Ott
Fábio Ramos
Ben Upcroft
+ MOT16: A Benchmark for Multi-Object Tracking 2016 Anton Milan
Laura Leal-Taixé
Ian Reid
Stefan Roth
Konrad Schindler
+ Synthesizing Robust Adversarial Examples 2017 Anish Athalye
Logan Engstrom
Andrew Ilyas
Kevin Kwok
+ PDF Chat Towards Evaluating the Robustness of Neural Networks 2017 Nicholas Carlini
David Wagner
+ Fooling Detection Alone is Not Enough: Adversarial Attack against Multiple Object Tracking 2020 Yunhan Jia
Yantao Lu
Junjie Shen
Qi Alfred Chen
Hao Chen
Zhenyu Zhong
Tao Wei
+ Security of Deep Learning based Lane Keeping System under Physical-World Adversarial Attack 2020 Takami Sato
Junjie Shen
Ningfei Wang
Yunhan Jia
Xue Lin
Qi Alfred Chen
+ Interpretable Deep Learning under Fire 2018 Xinyang Zhang
Ningfei Wang
Hua Shen
Shouling Ji
Xiapu Luo
Ting Wang
+ A Panda? No, It's a Sloth: Slowdown Attacks on Adaptive Multi-Exit Neural Network Inference 2020 Sanghyun Hong
Yiğitcan Kaya
Ionuț-Vlad Modoranu
Tudor Dumitraş
+ PDF Chat LGSVL Simulator: A High Fidelity Simulator for Autonomous Driving 2020 Guodong Rong
Byung Hyun Shin
Hadi Tabatabaee
Qiang Lu
Steve Lemke
Mārtiņš Možeiko
Eric Boise
Geehoon Uhm
Mark Gerow
Shalin Mehta
+ PDF Chat Daedalus: Breaking Nonmaximum Suppression in Object Detection via Adversarial Examples 2021 Derui Wang
Chaoran Li
Sheng Wen
Qing‐Long Han
‪Surya Nepal‬
Xiangyu Zhang
Yang Xiang