VisionGuard: Secure and Robust Visual Perception of Autonomous Vehicles in Practice
Xingshuo Han, Haozhao Wang, Kangqiao Zhao, Gelei Deng, Yuan Xu, Hangcheng Liu, Han Qiu, Tianwei Zhang
Abstract
Modern Autonomous Vehicles (AVs) implement the Visual Perception Module (VPM) to perceive their surroundings. This VPM adopts various Deep Neural Network (DNN) models to process the data collected from cameras and LiDAR. Prior studies have shown that these models are vulnerable to physical adversarial examples (PAEs), which pose a critical safety risk to the autonomous driving task. While a few defense methods have been proposed to safeguard AVs, most of them only target a limited set of attack types and specific scenarios, making them impractical for real-world protection. In this paper, we introduce VisionGuard, a novel and practical methodology to comprehensively detect and mitigate various types of PAEs to the VPM. The key of VisionGuard is to leverage the spatiotemporal inconsistency property of PAEs to detect anomalies. It predicts the motion states from historical ones and compares them with the current driving states to identify any motion inconsistency caused by physical attacks. We evaluate 9 state-of-the-art PAEs against both camera and camera-LiDAR fusion-based object classification & detection models. Experimental results in both simulation and physical world validate the effectiveness and robustness of VisionGuard. Codes, demo videos and appendix can be found on our anonymous website: https: //sites.google.com/view/visionguard . CCS Concepts • Security and privacy → Systems security.
Ask about this paper
Your agent reads all of it.
Lune indexed this paper to the last equation, along with the top-tier papers that cite it. Ask a question and the answer quotes them.
Your agent calls
Luneget_paper_fulltext
Free to start. No credit card required.
Terminal
Install the CLIlune papers fulltext 86fc00a7-eeeb-4ab6-868a-7264edb76d68Cited by top-tier papers3
- FlyTrap: Physical Distance-Pulling Attack Towards Camera-based Autonomous Target Tracking SystemsShaoyuan Xie, Mohamad Habib Fakih, Junchi Lu, Fayzah Alshammari et al.NDSS 2026 · 5 citations
- ControlLoc: Physical-World Hijacking Attack on Camera-based Perception in Autonomous DrivingChen Ma, Ningfei Wang, Zhengyu Zhao, Qian Wang et al.CCS 2025
- Targeted Physical Evasion Attacks in the Near-Infrared DomainPascal Zimmer, Simon Lachnit, Alexander Jan Zielinski, Ghassan KarameNDSS 2026
Builds on42
- Adversarial Sensor Attack on LiDAR-based Perception in Autonomous DrivingYulong Cao, Chaowei Xiao, Benjamin Cyr, Yimeng Zhou et al.CCS 2019 · 626 citations
- VOS: Learning What You Don't Know by Virtual Outlier SynthesisXuefeng Du, Zhaoning Wang, Mu Cai, Yixuan LiICLR 2022 · 417 citations
- TransWeather: Transformer-based Restoration of Images Degraded by Adverse Weather ConditionsJeya Maria Jose Valanarasu, Rajeev Yasarla, Vishal M. PatelCVPR 2022 · 350 citations
- Invisible for both Camera and LiDAR: Security of Multi-Sensor Fusion based Perception in Autonomous Driving Under Physical-World AttacksYulong Cao, Ningfei Wang, Chaowei Xiao, Dawei Yang et al.S&P 2021 · 309 citations
- DCdetector: Dual Attention Contrastive Representation Learning for Time Series Anomaly DetectionYiyuan Yang, Chaoli Zhang, Tian Zhou, Qingsong Wen et al.KDD 2023 · 244 citations
Related papers
- Towards Real-Time Defense against Object-Based LiDAR Attacks in Autonomous DrivingYan Zhang, Zihao Liu, Yi Zhu, Chenglin MiaoCCS 2025
- That Person Moves Like A Car: Misclassification Attack Detection for Autonomous Systems Using Spatiotemporal ConsistencyYanmao Man, Raymond Muller, Ming Li, Z. Berkay Celik et al.USENIX Security 2023
- PhyScout: Detecting Sensor Spoofing Attacks via Spatio-temporal ConsistencyYuan Xu, Gelei Deng, Xingshuo Han, Guanlin Li et al.CCS 2024 · 2 citations
- Physical Backdoor Attacks to Lane Detection Systems in Autonomous DrivingXingshuo Han, Guowen Xu, Yuan Zhou, Xuehuan Yang et al.ACM MM 2022 · 48 citations
- Can We Use Arbitrary Objects to Attack LiDAR Perception in Autonomous Driving?Yi Zhu, Chenglin Miao, Tianhang Zheng, Foad Hajiaghajani et al.CCS 2021 · 65 citations
