Pretend Benign: A Stealthy Adversarial Attack by Exploiting Vulnerabilities in Cooperative Perception
Hongwei Lin, Dongyu Pan, Qiming Xia, Hai Wu, Cheng Wang, Siqi Shen, Chenglu Wen
Abstract
Recently, learning-based multi-agent cooperative perception has garnered widespread attention. However, the inherent vulnerabilities of neural networks, combined with the risks posed by cooperative communication as a wideopen backdoor, render these systems highly susceptible to adversarial attacks. Existing attack methods lack stealth as they perturb transmitted information indiscriminately, producing numerous false positives that are readily detected by consensus-based defenses. This paper proposes Pretend Benign (PB), a novel stealthy adversarial attack method that exploits vulnerabilities in cooperative perception to enable the attacker to disguise as a benign cooperator. To achieve this, we first introduce the Attack Region Selection (ARS) module, which divides the perception area into subregions based on confidence levels to pinpoint optimal attack locations. Then, we propose Multi-target Adversarial Perturbation Generation (MAPG), which maintains consensus, gain the victim's trust, and thereby reverse the normal cooperative role of perception. To mitigate the latency in adversarial signal generation and communication, we further propose a real-time attack by predicting future information through historical feature flow. Extensive experiments on the OPV2V and V2XSet datasets demonstrate that PB effectively bypasses state-of-the-art defense methods, underscoring its stealth and efficacy.
Ask about this paper
Your agent reads all of it.
Lune indexed this paper to the last equation, along with the top-tier papers that cite it. Ask a question and the answer quotes them.
Your agent calls
Luneget_paper_fulltext
Free to start. No credit card required.
Terminal
Install the CLIlune papers fulltext f008a49a-b7ef-4fa6-94d7-693cc2bcd8f3Cited by top-tier papers1
Ask how each one uses itBuilds on22
- Swin Transformer: Hierarchical Vision Transformer using Shifted WindowsZe Liu, Yutong Lin, Yue Cao, Han Hu et al.ICCV 2021 · 31,683 citations
- Towards Evaluating the Robustness of Neural NetworksNicholas Carlini, David A. WagnerS&P 2017 · 9,786 citations
- Voxel R-CNN: Towards High Performance Voxel-based 3D Object DetectionJiajun Deng, Shaoshuai Shi, Peiwei Li, Wengang Zhou et al.AAAI 2021 · 1,128 citations
- Learning Distilled Collaboration Graph for Multi-Agent PerceptionYiming Li, Shunli Ren, Pengxiang Wu, Siheng Chen et al.NeurIPS 2021 · 464 citations
- How2comm: Communication-Efficient and Collaboration-Pragmatic Multi-Agent PerceptionDingkang Yang, Kun Yang, Yuzheng Wang, Jing Liu et al.NeurIPS 2023 · 160 citations
Related papers
- Learning Mutual View Information Graph for Adaptive Adversarial Collaborative PerceptionYihang Tao, Senkang Hu, Haonan An, Zhengru Fang et al.CVPR 2026 · 5 citations
- All Vehicles Can Lie: Efficient Adversarial Defense in Fully Untrusted-Vehicle Collaborative Perception via Pseudo-Random Bayesian InferenceYi Yu, Libing Wu, Zhuangzhuang Zhang, Jing Qiu et al.CVPR 2026 · 1 citation
- The Latent Guardian: Defending Collaborative Perception via Feature-Level Consistency VerificationZhuangzhuang Zhang, MingXin Li, Libing Wu, Wei-Bin Lee et al.ICML 2026
- CP-Guard: Malicious Agent Detection and Defense in Collaborative Bird's Eye View PerceptionSenkang Hu, Yihang Tao, Guowen Xu, Yiqin Deng et al.AAAI 2025 · 1 citation
- CP-FREEZER: Latency Attacks Against Vehicular Cooperative PerceptionChenyi Wang, Ruoyu Song, Raymond Muller, Jean-Philippe Monteuuis et al.AAAI 2026
