Learning Mutual View Information Graph for Adaptive Adversarial Collaborative Perception
Yihang Tao, Senkang Hu, Haonan An, Zhengru Fang, Hangcheng Cao, Yuguang Fang
Abstract
Collaborative perception (CP) enables data sharing among connected and autonomous vehicles (CAVs) to enhance driving safety. However, CP systems are vulnerable to adversarial attacks where malicious agents forge false objects via feature-level perturbations. Current defensive systems use threshold-based consensus verification by comparing collaborative and ego detection results. Yet, these defenses remain vulnerable to more sophisticated attack strategies that could exploit two critical weaknesses: (i) lack of robustness against attacks with systematic timing and target region optimization, and (ii) inadvertent disclosure of vulnerability knowledge through implicit confidence information in shared collaboration data. In this paper, we propose MVIG attack, a novel adaptive adversarial CP framework learning to capture vulnerability knowledge disclosed by different defensive CP systems from a unified mutual view information graph (MVIG) representation. Our approach combines MVIG representation with temporal graph learning to generate evolving fabrication risk maps and employs entropy-aware vulnerability search to optimize attack location, timing and persistence, enabling adaptive attacks with generalizability across various defensive configurations. Extensive evaluations on OPV2V and Adv-OPV2V datasets demonstrate that MVIG attack reduces defense success rates by up to 62% against state-of-the-art defenses while achieving 47% lower detection for persistent attacks at 29.9 FPS, exposing critical security gaps in CP systems. Code will be released at https://github.com/yihangtao/MVIG.git
Ask about this paper
Your agent reads all of it.
Lune indexed this paper to the last equation, along with the top-tier papers that cite it. Ask a question and the answer quotes them.
Your agent calls
Luneget_paper_fulltext
Free to start. No credit card required.
Terminal
Install the CLIlune papers fulltext 8827cd2c-32cd-4811-84c6-32376955f89aBuilds on16
- Where2comm: Communication-Efficient Collaborative Perception via Spatial Confidence MapsYue Hu, Shaoheng Fang, Zixing Lei, Yiqi Zhong et al.NeurIPS 2022 · 537 citations
- Learning Distilled Collaboration Graph for Multi-Agent PerceptionYiming Li, Shunli Ren, Pengxiang Wu, Siheng Chen et al.NeurIPS 2021 · 464 citations
- Invisible for both Camera and LiDAR: Security of Multi-Sensor Fusion based Perception in Autonomous Driving Under Physical-World AttacksYulong Cao, Ningfei Wang, Chaowei Xiao, Dawei Yang et al.S&P 2021 · 309 citations
- Asynchrony-Robust Collaborative Perception via Bird's Eye View FlowSizhe Wei, Yuxi Wei, Yue Hu, Yifan Lu et al.NeurIPS 2023 · 102 citations
- Adversarial Attacks On Multi-Agent CommunicationJames Tu, Tsun-Hsuan Wang, Jingkang Wang, Sivabalan Manivasagam et al.ICCV 2021 · 83 citations
Related papers
- From Stealthy Data Fabrication to Unsafe Driving: Realistic Scenario Attacks on Collaborative PerceptionQingzhao Zhang, Runting Zhang, Z. Morley MaoCCS 2026 · 2 citations
- On Data Fabrication in Collaborative Vehicular Perception: Attacks and CountermeasuresQingzhao Zhang, Shuowei Jin, Ruiyang Zhu, Jiachen Sun et al.USENIX Security 2024 · 25 citations
- The Latent Guardian: Defending Collaborative Perception via Feature-Level Consistency VerificationZhuangzhuang Zhang, MingXin Li, Libing Wu, Wei-Bin Lee et al.ICML 2026
- All Vehicles Can Lie: Efficient Adversarial Defense in Fully Untrusted-Vehicle Collaborative Perception via Pseudo-Random Bayesian InferenceYi Yu, Libing Wu, Zhuangzhuang Zhang, Jing Qiu et al.CVPR 2026 · 1 citation
- Pretend Benign: A Stealthy Adversarial Attack by Exploiting Vulnerabilities in Cooperative PerceptionHongwei Lin, Dongyu Pan, Qiming Xia, Hai Wu et al.ICCV 2025 · 6 citations
