Sequential Attacks on Kalman Filter-based Forward Collision Warning Systems
Yuzhe Ma, Jon A. Sharp, Ruizhe Wang, Earlence Fernandes, Xiaojin Zhu
Abstract
Kalman Filter (KF) is widely used in various domains to perform sequential learning or variable estimation. In the context of autonomous vehicles, KF constitutes the core component of many Advanced Driver Assistance Systems (ADAS), such as Forward Collision Warning (FCW). It tracks the states (distance, velocity etc.) of relevant traffic objects based on sensor measurements. The tracking output of KF is often fed into downstream logic to produce alerts, which will then be used by human drivers to make driving decisions in near-collision scenarios. In this paper, we study adversarial attacks on KF as part of the more complex machine-human hybrid system of Forward Collision Warning. Our attack goal is to negatively affect human braking decisions by causing KF to output incorrect state estimations that lead to false or delayed alerts. We accomplish this by sequentially manipulating measure ments fed into the KF, and propose a novel Model Predictive Control (MPC) approach to compute the optimal manipulation. Via experiments conducted in a simulated driving environment, we show that the attacker is able to successfully change FCW alert signals through planned manipulation over measurements prior to the desired target time. These results demonstrate that our attack can stealthily mislead a distracted human driver and cause vehicle collisions.
Ask about this paper
Your agent reads all of it.
Lune indexed this paper to the last equation, along with the top-tier papers that cite it. Ask a question and the answer quotes them.
Your agent calls
Luneget_paper_fulltext
Free to start. No credit card required.
Terminal
Install the CLIlune papers fulltext a08301ba-1017-480c-a7a8-44c8dbf19d60Cited by top-tier papers3
- Detecting multi-sensor fusion errors in advanced driver-assistance systemsZiyuan Zhong, Zhisheng Hu, Shengjian Guo, Xinyang Zhang et al.ISSTA 2022 · 28 citations
- Physical Hijacking Attacks against Object TrackersRaymond Muller, Yanmao Man, Z. Berkay Celik, Ming Li et al.CCS 2022 · 12 citations
- That Person Moves Like A Car: Misclassification Attack Detection for Autonomous Systems Using Spatiotemporal ConsistencyYanmao Man, Raymond Muller, Ming Li, Z. Berkay Celik et al.USENIX Security 2023
Builds on5
- Towards Evaluating the Robustness of Neural NetworksNicholas Carlini, David A. WagnerS&P 2017 · 9,786 citations
- Accessorize to a Crime: Real and Stealthy Attacks on State-of-the-Art Face RecognitionMahmood Sharif, Sruti Bhagavatula, Lujo Bauer, Michael K. ReiterCCS 2016 · 1,765 citations
- Adaptive Reward-Poisoning Attacks against Reinforcement LearningXuezhou Zhang, Yuzhe Ma, Adish Singla, Xiaojin ZhuICML 2020 · 154 citations
- Fooling Detection Alone is Not Enough: Adversarial Attack against Multiple Object TrackingYunhan Jia, Yantao Lu, Junjie Shen, Qi Alfred Chen et al.ICLR 2020 · 113 citations
- Optimal Attack against Autoregressive Models by Manipulating the EnvironmentYiding Chen, Xiaojin ZhuAAAI 2020 · 11 citations
Related papers
- AnA: An Attentive Autonomous Driving SystemWonkyo Choe, Rongxiang Wang, Felix Xiaozhu LinASPLOS 2025
- MadRadar: A Black-Box Physical Layer Attack Framework on mmWave Automotive FMCW RadarsDavid Hunt, Kristen Angell, Zhenzhou Qi, Tingjun Chen et al.NDSS 2024
- Invisible for both Camera and LiDAR: Security of Multi-Sensor Fusion based Perception in Autonomous Driving Under Physical-World AttacksYulong Cao, Ningfei Wang, Chaowei Xiao, Dawei Yang et al.S&P 2021 · 309 citations
- ControlLoc: Physical-World Hijacking Attack on Camera-based Perception in Autonomous DrivingChen Ma, Ningfei Wang, Zhengyu Zhao, Qian Wang et al.CCS 2025
- From Stealthy Data Fabrication to Unsafe Driving: Realistic Scenario Attacks on Collaborative PerceptionQingzhao Zhang, Runting Zhang, Z. Morley MaoCCS 2026 · 2 citations
