USENIX Security2023Top-tier venue
Discovering Adversarial Driving Maneuvers against Autonomous Vehicles
Ruoyu Song, Muslum Ozgur Ozmen, Hyungsub Kim, Raymond Muller, Z. Berkay Celik, Antonio Bianchi
Abstract
Over 33% of vehicles sold in 2021 had integrated autonomous driving (AD) systems. While many adversarial machine learning attacks have been studied against these systems, they all require an adversary to perform specific (and often unrealistic) actions, such as carefully modifying traffic signs or projecting malicious images, which may arouse suspicion if discovered. In this paper, we present Acero, a robustness-guided framework to discover adversarial maneuver attacks against autonomous vehicles (AVs). These maneuvers look innocent to the outside observer but force the victim vehicle to violate safety rules for AVs, causing physical consequences, e.g., crashing with pedestrians and other vehicles. To optimally find adversarial driving maneuvers, we formalize seven safety requirements for AD systems and use this formalization to guide our search. We also formalize seven physical constraints that ensure the adversary does not place themselves in danger or violate traffic laws while conducting the attack. Acero then leverages trajectory-similarity metrics to cluster successful attacks into unique groups, enabling AD developers to analyze the root cause of attacks and mitigate them. We evaluated Acero on two open-source AD software, openpilot and Autoware, running on the CARLA simulator. Acero discovered 219 attacks against openpilot and 122 attacks against Autoware. 73.3% of these attacks cause the victim to collide with a third-party vehicle, pedestrian, or static object.
Ask about this paper
Your agent reads all of it.
Lune indexed this paper to the last equation, along with the top-tier papers that cite it. Ask a question and the answer quotes them.
Your agent calls
Luneget_paper_fulltext
Free to start. No credit card required.
Terminal
Install the CLIlune papers fulltext d0a555f8-b976-4429-b573-2b9e4f583351Cited by top-tier papers12
- VioHawk: Detecting Traffic Violations of Autonomous Driving Systems through Criticality-Guided Simulation TestingZhongrui Li, Jiarun Dai, Zongan Huang, Nianhao You et al.ISSTA 2024 · 7 citations
- Dance of the ADS: Orchestrating Failures through Historically-Informed Scenario FuzzingTong Wang, Taotao Gu, Huan Deng, Hu Li et al.ISSTA 2024 · 6 citations
- On-Demand Scenario Generation for Testing Automated Driving SystemsSongyang Yan, Xiaodong Zhang, Kunkun Hao, Haojie Xin et al.FSE 2025 · 6 citations
- Temporal Logic-Based Multi-Vehicle Backdoor Attacks against Offline RL Agents in End-to-end Autonomous DrivingXuan Chen, Shiwei Feng, Zikang Xiong, Shengwei An et al.NeurIPS 2025 · 6 citations
- Peering Inside the Black-Box: Long-Range and Scalable Model Architecture Snooping via GPU Electromagnetic Side-ChannelRui Xiao, Sibo Feng, Soundarya Ramesh, Jun Han et al.NDSS 2026 · 3 citations
Builds on17
- Adversarial Sensor Attack on LiDAR-based Perception in Autonomous DrivingYulong Cao, Chaowei Xiao, Benjamin Cyr, Yimeng Zhou et al.CCS 2019 · 626 citations
- Invisible for both Camera and LiDAR: Security of Multi-Sensor Fusion based Perception in Autonomous Driving Under Physical-World AttacksYulong Cao, Ningfei Wang, Chaowei Xiao, Dawei Yang et al.S&P 2021 · 309 citations
- Seeing isn't Believing: Towards More Robust Adversarial Attack Against Real World Object DetectorsYue Zhao, Hong Zhu, Ruigang Liang, Qintao Shen et al.CCS 2019 · 239 citations
- Dirty Road Can Attack: Security of Deep Learning based Automated Lane Centering under Physical-World AttackTakami Sato, Junjie Shen, Ningfei Wang, Yunhan Jia et al.USENIX Security 2021 · 152 citations
- DeepBillboard: systematic physical-world testing of autonomous driving systemsHusheng Zhou, Wei Li, Zelun Kong, Junfeng Guo et al.ICSE 2020 · 150 citations
Related papers
- Fooling Detection Alone is Not Enough: Adversarial Attack against Multiple Object TrackingYunhan Jia, Yantao Lu, Junjie Shen, Qi Alfred Chen et al.ICLR 2020 · 113 citations
- AE-Morpher: Improve Physical Robustness of Adversarial Objects against LiDAR-based Detectors via Object ReconstructionShenchen Zhu, Yue Zhao, Kai Chen, Bo Wang et al.USENIX Security 2024 · 13 citations
- You Can't See Me: Physical Removal Attacks on LiDAR-based Autonomous Vehicles Driving FrameworksYulong Cao, S. Hrushikesh Bhupathiraju, Pirouz Naghavi, Takeshi Sugawara et al.USENIX Security 2023
- AdvSim: Generating Safety-Critical Scenarios for Self-Driving VehiclesJingkang Wang, Ava Pun, James Tu, Sivabalan Manivasagam et al.CVPR 2021
- Too Good to Be Safe: Tricking Lane Detection in Autonomous Driving with Crafted PerturbationsPengfei Jing, Qiyi Tang, Yuefeng Du, Lei Xue et al.USENIX Security 2021 · 79 citations
