SlowTrack: Increasing the Latency of Camera-Based Perception in Autonomous Driving Using Adversarial Examples
Chen Ma, Ningfei Wang, Qi Alfred Chen, Chao Shen
Abstract
In Autonomous Driving (AD), real-time perception is a critical component responsible for detecting surrounding objects to ensure safe driving. While researchers have extensively explored the integrity of AD perception due to its safety and security implications, the aspect of availability (real-time performance) or latency has received limited attention. Existing works on latency-based attack have focused mainly on object detection, i.e., a component in camera-based AD perception, overlooking the entire camera-based AD perception, which hinders them to achieve effective system-level effects, such as vehicle crashes. In this paper, we propose SlowTrack, a novel framework for generating adversarial attacks to increase the execution time of camera-based AD perception. We propose a novel two-stage attack strategy along with the three new loss function designs. Our evaluation is conducted on four popular camera-based AD perception pipelines, and the results demonstrate that SlowTrack significantly outperforms existing latency-based attacks while maintaining comparable imperceptibility levels. Furthermore, we perform the evaluation on Baidu Apollo, an industry-grade full-stack AD system, and LGSVL, a production-grade AD simulator, with two scenarios to compare the system-level effects of Slow-Track and existing attacks. Our evaluation results show that the system-level effects can be significantly improved, i.e., the vehicle crash rate of SlowTrack is around 95% on average while existing works only have around 30%.
Ask about this paper
Your agent reads all of it.
Lune indexed this paper to the last equation, along with the top-tier papers that cite it. Ask a question and the answer quotes them.
Your agent calls
Luneget_paper_fulltext
Free to start. No credit card required.
Terminal
Install the CLIlune papers fulltext c3dc756f-f737-4847-b06e-fef41533e870Cited by top-tier papers17
- Physical 3D Adversarial Attacks against Monocular Depth Estimation in Autonomous DrivingJunhao Zheng, Chenhao Lin, Jiahao Sun, Zhengyu Zhao et al.CVPR 2024 · 36 citations
- ThinkTrap: Denial-of-Service Attacks against Black-box LLM Services via Infinite ThinkingYunzhe Li, Jianan Wang, Hongzi Zhu, James Lin et al.NDSS 2026 · 26 citations
- A First Physical-World Trajectory Prediction Attack via LiDAR-induced Deceptions in Autonomous DrivingYang Lou, Yi Zhu, Qun Song, Rui Tan et al.USENIX Security 2024 · 11 citations
- SlowPerception: Physical-World Latency Attack against Camera-based Perception in Autonomous DrivingChen Ma, Ningfei Wang, Zhengyu Zhao, Qian Wang et al.CCS 2026 · 5 citations
- Revisiting Adversarial Patch Defenses on Object Detectors: Unified Evaluation, Large-Scale Dataset, and New InsightsJunhao Zheng, Jiahao Sun, Chenhao Lin, Zhengyu Zhao et al.ICCV 2025 · 4 citations
Builds on10
- Towards Evaluating the Robustness of Neural NetworksNicholas Carlini, David A. WagnerS&P 2017 · 9,786 citations
- Invisible for both Camera and LiDAR: Security of Multi-Sensor Fusion based Perception in Autonomous Driving Under Physical-World AttacksYulong Cao, Ningfei Wang, Chaowei Xiao, Dawei Yang et al.S&P 2021 · 309 citations
- Fooling Detection Alone is Not Enough: Adversarial Attack against Multiple Object TrackingYunhan Jia, Yantao Lu, Junjie Shen, Qi Alfred Chen et al.ICLR 2020 · 113 citations
- A Panda? No, It's a Sloth: Slowdown Attacks on Adaptive Multi-Exit Neural Network InferenceSanghyun Hong, Yigitcan Kaya, Ionut-Vlad Modoranu, Tudor DumitrasICLR 2021 · 85 citations
- Does Physical Adversarial Example Really Matter to Autonomous Driving? Towards System-Level Effect of Adversarial Object Evasion AttackNingfei Wang, Yunpeng Luo, Takami Sato, Kaidi Xu et al.ICCV 2023 · 65 citations
Related papers
- SlowLiDAR: Increasing the Latency of LiDAR-Based Detection Using Adversarial ExamplesHan Liu, Yuhao Wu, Zhiyuan Yu, Yevgeniy Vorobeychik et al.CVPR 2023
- Investigating Physical Latency Attacks Against Camera-Based PerceptionRaymond Muller, Ruoyu Song, Chenyi Wang, Yuxia Zhan et al.S&P 2025
- Overload: Latency Attacks on Object Detection for Edge DevicesErh-Chung Chen, Pin-Yu Chen, I-Hsin Chung, Che-Rung LeeCVPR 2024
- ADPerf: Investigating and Testing Performance in Autonomous Driving SystemsTri Minh-Triet Pham, Diego Elias Costa, Weiyi Shang, Jinqiu YangASE 2025
- CP-FREEZER: Latency Attacks Against Vehicular Cooperative PerceptionChenyi Wang, Ruoyu Song, Raymond Muller, Jean-Philippe Monteuuis et al.AAAI 2026
