All Vehicles Can Lie: Efficient Adversarial Defense in Fully Untrusted-Vehicle Collaborative Perception via Pseudo-Random Bayesian Inference
Yi Yu, Libing Wu, Zhuangzhuang Zhang, Jing Qiu, Lijuan Huo, Jiaqi Feng
Abstract
Collaborative perception (CP) enables multiple vehicles to augment their individual perception capacities through the exchange of feature-level sensory data. However, this fusion mechanism is inherently vulnerable to adversarial attacks, especially in fully untrusted-vehicle environments. Existing defense approaches often assume a trusted ego vehicle as a reference or incorporate additional binary classifiers. These assumptions limit their practicality in real-world deployments due to the questionable trustworthiness of ego vehicles, the requirement for real-time detection, and the need for generalizability across diverse scenarios. To address these challenges, we propose a novel Pseudo-Random Bayesian Inference (PRBI) framework, a first efficient defense method tailored for fully untrusted-vehicle CP. PRBI detects adversarial behavior by leveraging temporal perceptual discrepancies, using the reliable perception from the preceding frame as a dynamic reference. Additionally, it employs a pseudo-random grouping strategy that requires only two verifications per frame, while applying Bayesian inference to estimate both the number and identities of malicious vehicles. Theoretical analysis has proven the convergence and stability of the proposed PRBI framework. Extensive experiments show that PRBI requires only 2.5 verifications per frame on average, outperforming existing methods significantly, and restores detection precision to between 79.4% and 86.9% of pre-attack levels.
Ask about this paper
Your agent reads all of it.
Lune indexed this paper to the last equation, along with the top-tier papers that cite it. Ask a question and the answer quotes them.
Your agent calls
Luneget_paper_fulltext
Free to start. No credit card required.
Terminal
Install the CLIlune papers fulltext 03b2c8a0-b535-45a2-a1be-974576a053f2Builds on19
- Towards Evaluating the Robustness of Neural NetworksNicholas Carlini, David A. WagnerS&P 2017 · 9,786 citations
- Learning Distilled Collaboration Graph for Multi-Agent PerceptionYiming Li, Shunli Ren, Pengxiang Wu, Siheng Chen et al.NeurIPS 2021 · 464 citations
- Robust Adversarial Objects against Deep Learning ModelsTzungyu Tsai, Kaichen Yang, Tsung-Yi Ho, Yier JinAAAI 2020 · 167 citations
- Adversarial Attacks On Multi-Agent CommunicationJames Tu, Tsun-Hsuan Wang, Jingkang Wang, Sivabalan Manivasagam et al.ICCV 2021 · 83 citations
- Among Us: Adversarially Robust Collaborative Perception by ConsensusYiming Li, Qi Fang, Jiamu Bai, Siheng Chen et al.ICCV 2023 · 49 citations
Related papers
- Learning Mutual View Information Graph for Adaptive Adversarial Collaborative PerceptionYihang Tao, Senkang Hu, Haonan An, Zhengru Fang et al.CVPR 2026 · 5 citations
- The Latent Guardian: Defending Collaborative Perception via Feature-Level Consistency VerificationZhuangzhuang Zhang, MingXin Li, Libing Wu, Wei-Bin Lee et al.ICML 2026
- From Threat to Trust: Exploiting Attention Mechanisms for Attacks and Defenses in Cooperative PerceptionChenyi Wang, Raymond Muller, Ruoyu Song, Jean-Philippe Monteuuis et al.USENIX Security 2025
- CP-Guard: Malicious Agent Detection and Defense in Collaborative Bird's Eye View PerceptionSenkang Hu, Yihang Tao, Guowen Xu, Yiqin Deng et al.AAAI 2025 · 1 citation
- Pretend Benign: A Stealthy Adversarial Attack by Exploiting Vulnerabilities in Cooperative PerceptionHongwei Lin, Dongyu Pan, Qiming Xia, Hai Wu et al.ICCV 2025 · 6 citations
