Invisible for both Camera and LiDAR: Security of Multi-Sensor Fusion based Perception in Autonomous Driving Under Physical-World Attacks
Yulong Cao, Ningfei Wang, Chaowei Xiao, Dawei Yang, Jin Fang, Ruigang Yang, Qi Alfred Chen, Mingyan Liu, Bo Li
Abstract
In Autonomous Driving (AD) systems, perception is both security and safety critical. Despite various prior studies on its security issues, all of them only consider attacks on camera-or LiDAR-based AD perception alone. However, production AD systems today predominantly adopt a Multi-Sensor Fusion (MSF) based design, which in principle can be more robust against these attacks under the assumption that not all fusion sources are (or can be) attacked at the same time. In this paper, we present the first study of security issues of MSF-based perception in AD systems. We directly challenge the basic MSF design assumption above by exploring the possibility of attacking all fusion sources simultaneously. This allows us for the first time to understand how much security guarantee MSF can fundamentally provide as a general defense strategy for AD perception.We formulate the attack as an optimization problem to generate a physically-realizable, adversarial 3D-printed object that misleads an AD system to fail in detecting it and thus crash into it. To systematically generate such a physical-world attack, we propose a novel attack pipeline that addresses two main design challenges: (1) non-differentiable target camera and LiDAR sensing systems, and (2) non-differentiable cell-level aggregated features popularly used in LiDAR-based AD perception. We evaluate our attack on MSF algorithms included in representative open-source industry-grade AD systems in real-world driving scenarios. Our results show that the attack achieves over 90% success rate across different object types and MSF algorithms. Our attack is also found stealthy, robust to victim positions, transferable across MSF algorithms, and physical-world realizable after being 3D-printed and captured by LiDAR and camera devices. To concretely assess the end-to-end safety impact, we further perform simulation evaluation and show that it can cause a 100% vehicle collision rate for an industry-grade AD system. We also evaluate and discuss defense strategies.
Ask about this paper
Your agent reads all of it.
Lune indexed this paper to the last equation, along with the top-tier papers that cite it. Ask a question and the answer quotes them.
Your agent calls
Luneget_paper_fulltext
Free to start. No credit card required.
Terminal
Install the CLIlune papers fulltext bae97b07-49b3-4743-8a0d-252bcba45a08Cited by top-tier papers90
- Robo3D: Towards Robust and Reliable 3D Perception against CorruptionsLingdong Kong, Youquan Liu, Xin Li, Runnan Chen et al.ICCV 2023 · 151 citations
- Robust Classification via a Single Diffusion ModelHuanran Chen, Yinpeng Dong, Zhengyi Wang, Xiao Yang et al.ICML 2024 · 94 citations
- Shape-invariant 3D Adversarial Point CloudsQidong Huang, Xiaoyi Dong, Dongdong Chen, Hang Zhou et al.CVPR 2022 · 88 citations
- Infrared Invisible Clothing: Hiding from Infrared Detectors at Multiple Angles in Real WorldXiaopei Zhu, Zhanhao Hu, Siyuan Huang, Jianmin Li et al.CVPR 2022 · 67 citations
- DiffAttack: Evasion Attacks Against Diffusion-Based Adversarial PurificationMintong Kang, Dawn Song, Bo LiNeurIPS 2023 · 66 citations
Builds on19
- Towards Evaluating the Robustness of Neural NetworksNicholas Carlini, David A. WagnerS&P 2017 · 9,786 citations
- Feature Squeezing: Detecting Adversarial Examples in Deep Neural NetworksWeilin Xu, David Evans, Yanjun QiNDSS 2018 · 1,633 citations
- Fast is better than free: Revisiting adversarial trainingEric Wong, Leslie Rice, J. Zico KolterICLR 2020 · 1,352 citations
- MagNet: A Two-Pronged Defense against Adversarial ExamplesDongyu Meng, Hao ChenCCS 2017 · 1,295 citations
- Certified Robustness to Adversarial Examples with Differential PrivacyMathias Lécuyer, Vaggelis Atlidakis, Roxana Geambasu, Daniel Hsu et al.S&P 2019 · 1,022 citations
Related papers
- Unity is Strength? Benchmarking the Robustness of Fusion-based 3D Object Detection against Physical Sensor AttackZizhi Jin, Xuancun Lu, Bo Yang, Yushi Cheng et al.WWW 2024 · 7 citations
- Fusion Is Not Enough: Single Modal Attacks on Fusion Models for 3D Object DetectionZhiyuan Cheng, Hongjun Choi, Shiwei Feng, James Chenhao Liang et al.ICLR 2024 · 32 citations
- Malicious Attacks against Multi-Sensor Fusion in Autonomous DrivingYi Zhu, Chenglin Miao, Hongfei Xue, Yunnan Yu et al.MobiCom 2024 · 28 citations
- Multi-view Correlation based Black-box Adversarial Attack for 3D Object DetectionBingyu Liu, Yuhong Guo, Jianan Jiang, Jian Tang et al.KDD 2021 · 10 citations
- Towards Real-Time Defense against Object-Based LiDAR Attacks in Autonomous DrivingYan Zhang, Zihao Liu, Yi Zhu, Chenglin MiaoCCS 2025
