BADControl: Backdoor Attacks Against Control Systems
Luis Burbano, Hampei Sasahara, Ruoyu Song, Z. Berkay Celik, Alvaro A. Cardenas
摘要
We introduce BADCONTROL, the first backdoor attack against low-level controllers that uses physical triggers. The attack poisons operational data to implant a vulnerability that can be activated by an exogenous signal from the environment, such as a specific driving maneuver or adversarial road patches within autonomous driving applications. BADCON-TROL solves a constrained optimization problem by using a projected gradient ascent to modify the data, maximizing the frequency response of the controlled system at a target frequency. This method differs from backdoor attacks against Deep Learning (DL) and Reinforcement Learning (RL) models, which manipulate high-dimensional model inputs or reward functions. We additionally propose two defenses: one based on regularization and one based on robust optimization, to limit the worst-case amplification of trigger signals. This is achieved by converting infinite poisoning scenarios into a single, tractable optimization problem via a specialized mathematical transformation. We evaluate BADCONTROL on Proportional-Integral-Derivative (PID) and Linear-Quadratic-Regulator (LQR) controllers through simulations and physical experiments. In the adaptive cruise control scenario, we achieve a 100% crash rate, while in lane-keeping control, the backdoor causes the victim vehicle to steer 62% into the opposing lane, compared to 0% in both cases without a backdoor. By contrast, a state-of-the-art falsification framework for autonomous vehicles identifies only a single crash instance over 30 trials, underscoring its stealthiness.
问问这篇 Paper
智能体会读完全文。
Lune 把这篇 Paper 索引到了最后一个公式,引用它的顶会 Paper 也一样。你提问,回答直接引用原文。
它引用的顶会 Paper18
- Certified Robustness to Adversarial Examples with Differential PrivacyMathias Lécuyer, Vaggelis Atlidakis, Roxana Geambasu, Daniel Hsu 等S&P 2019 · 被引用 1,022 次
- Efficient and Modular Implicit DifferentiationMathieu Blondel, Quentin Berthet, Marco Cuturi, Roy Frostig 等NeurIPS 2022 · 被引用 386 次
- Dirty Road Can Attack: Security of Deep Learning based Automated Lane Centering under Physical-World AttackTakami Sato, Junjie Shen, Ningfei Wang, Yunhan Jia 等USENIX Security 2021 · 被引用 152 次
- MM-BD: Post-Training Detection of Backdoor Attacks with Arbitrary Backdoor Pattern Types Using a Maximum Margin StatisticHang Wang, Zhen Xiang, David J. Miller, George KesidisS&P 2024 · 被引用 81 次
- TrojDRL: Evaluation of Backdoor Attacks on Deep Reinforcement LearningPanagiota Kiourti, Kacper Wardega, Susmit Jha, Wenchao LiDAC 2020 · 被引用 72 次
相关 Paper
- Towards Robust Physical-world Backdoor Attacks on Lane DetectionXinwei Zhang, Aishan Liu, Tianyuan Zhang, Siyuan Liang 等ACM MM 2024 · 被引用 7 次
- Adversarial Backdoor Attack by Naturalistic Data Poisoning on Trajectory Prediction in Autonomous DrivingMozhgan Pourkeshavarz, Mohammad Sabokrou, Amir RasouliCVPR 2024 · 被引用 14 次
- Towards Stealthy and Effective Backdoor Attacks on Lane Detection: A Naturalistic Data Poisoning ApproachYifan Liao, Yuxin Cao, Yedi Zhang, Wentao He 等CVPR 2026 · 被引用 5 次
- Physical Backdoor Attacks to Lane Detection Systems in Autonomous DrivingXingshuo Han, Guowen Xu, Yuan Zhou, Xuehuan Yang 等ACM MM 2022 · 被引用 48 次
- Temporal Logic-Based Multi-Vehicle Backdoor Attacks against Offline RL Agents in End-to-end Autonomous DrivingXuan Chen, Shiwei Feng, Zikang Xiong, Shengwei An 等NeurIPS 2025 · 被引用 6 次
