COMMIT: Certifying Robustness of Multi-Sensor Fusion Systems Against Semantic Attacks
Zijian Huang, Wenda Chu, Linyi Li, Chejian Xu, Bo Li
Abstract
Multi-sensor fusion systems (MSFs) play a vital role as the perception module in modern autonomous vehicles (AVs). Therefore, ensuring their robustness against common and realistic adversarial semantic transformations, such as rotation and shifting in the physical world, is crucial for the safety of AVs. While empirical evidence suggests that MSFs exhibit improved robustness compared to single-modal models, they are still vulnerable to adversarial semantic transformations. In addition, although many empirical defenses have been proposed, several works show that these defenses can be further attacked by new adaptive attacks. So far, there is no certified defense proposed for MSFs. In this work, we propose the first robustness certification framework COMMIT to certify the robustness of multi-sensor fusion systems against semantic attacks. In particular, we propose a practical anisotropic noise mechanism that leverages randomized smoothing on multi-modal data and performs a grid-based splitting method to characterize complex semantic transformations. We also propose efficient algorithms to compute the certification in terms of object detection accuracy and IoU for large-scale MSF models. Empirically, we evaluate the efficacy of COMMIT in different settings and provide a comprehensive benchmark of certified robustness for different MSF models using the CARLA simulation platform. We show that the certification for MSF models is at most 48.39% higher than that of single-modal models, which validates the advantages of MSF models. We believe our certification framework and benchmark will contribute an important step towards certifiably robust AVs in practice.
Ask about this paper
Your agent reads all of it.
Lune indexed this paper to the last equation, along with the top-tier papers that cite it. Ask a question and the answer quotes them.
Your agent calls
Luneget_paper_fulltext
Free to start. No credit card required.
Terminal
Install the CLIlune papers fulltext 8ddca7ec-afd3-49ca-abd6-43e4e603f93fCited by top-tier papers2
- LipNeXt: Scaling up Lipschitz-based Certified Robustness to Billion-parameter ModelsKai Hu, Haoqi Hu, Matt FredriksonICLR 2026 · 3 citations
- Certified Robustness under Heterogeneous Perturbations via Hybrid Randomized SmoothingBlaise Delattre, Hengyu WU, Paul Caillon, Wei Yang Bryan Lim et al.ICML 2026
Builds on22
- Towards Evaluating the Robustness of Neural NetworksNicholas Carlini, David A. WagnerS&P 2017 · 9,786 citations
- Invisible for both Camera and LiDAR: Security of Multi-Sensor Fusion based Perception in Autonomous Driving Under Physical-World AttacksYulong Cao, Ningfei Wang, Chaowei Xiao, Dawei Yang et al.S&P 2021 · 309 citations
- Focal Sparse Convolutional Networks for 3D Object DetectionYukang Chen, Yanwei Li, Xiangyu Zhang, Jian Sun et al.CVPR 2022 · 293 citations
- Randomized Smoothing of All Shapes and SizesGreg Yang, Tony Duan, J. Edward Hu, Hadi Salman et al.ICML 2020 · 237 citations
- Learning Auxiliary Monocular Contexts Helps Monocular 3D Object DetectionXianpeng Liu, Nan Xue, Tianfu WuAAAI 2022 · 181 citations
Related papers
- TPC: Transformation-Specific Smoothing for Point Cloud ModelsWenda Chu, Linyi Li, Bo LiICML 2022 · 14 citations
- Fusion Is Not Enough: Single Modal Attacks on Fusion Models for 3D Object DetectionZhiyuan Cheng, Hongjun Choi, Shiwei Feng, James Chenhao Liang et al.ICLR 2024 · 32 citations
- The Latent Guardian: Defending Collaborative Perception via Feature-Level Consistency VerificationZhuangzhuang Zhang, MingXin Li, Libing Wu, Wei-Bin Lee et al.ICML 2026
- Unity is Strength? Benchmarking the Robustness of Fusion-based 3D Object Detection against Physical Sensor AttackZizhi Jin, Xuancun Lu, Bo Yang, Yushi Cheng et al.WWW 2024 · 7 citations
- MMCert: Provable Defense Against Adversarial Attacks to Multi-Modal ModelsYanting Wang, Hongye Fu, Wei Zou, Jinyuan JiaCVPR 2024 · 4 citations
