From Stealthy Data Fabrication to Unsafe Driving: Realistic Scenario Attacks on Collaborative Perception
Qingzhao Zhang, Runting Zhang, Z. Morley Mao
摘要
Collaborative perception allows connected and autonomous vehicles (CAVs) to improve perception by sharing sensory data, but it also introduces security risks from manipulated inputs. Prior work shows that attackers can spoof or remove objects by fabricating shared data, yet the practicality of such attacks in real-world driving remains unclear. Existing attacks are often detectable or evaluated in manually constructed scenarios, leaving open whether they can induce safety-critical outcomes in dynamic environments. To bridge this gap, we present a stealthy, scenario-realistic data fabrication attack that induces unsafe driving behaviors through end-to-end system effects. Instead of creating large, easily detectable anomalies, our attack subtly manipulates the poses of existing objects in shared perception results, keeping perturbations below detection thresholds. These small errors are then propagated through downstream modules, including object tracking and trajectory prediction, leading to significant deviations in predicted behaviors and ultimately unsafe driving decisions. We further design an online, scenario-aware attack framework that adapts to dynamic traffic conditions and optimizes attack strategies at runtime. Experiments on OPV2V and V2X-Real demonstrate that the attack achieves over 90% success in inducing detection errors and triggers safety-critical behaviors, such as unnecessary hard braking, in up to 50% of scenarios, while largely evading state-of-the-art defenses. We also propose a mitigation that focuses on detecting anomalies in localized, safety-critical regions, achieving an 80% detection rate on the small pose perturbation compared to 11% for the best existing methods.
问问这篇 Paper
智能体会读完全文。
Lune 把这篇 Paper 索引到了每一个公式,引用它的顶会 Paper 也一样。你提问,回答直接引用原文。
它引用的顶会 Paper24
- Invisible for both Camera and LiDAR: Security of Multi-Sensor Fusion based Perception in Autonomous Driving Under Physical-World AttacksYulong Cao, Ningfei Wang, Chaowei Xiao, Dawei Yang 等S&P 2021 · 被引用 309 次
- EMP: edge-assisted multi-vehicle perceptionXumiao Zhang, Anlan Zhang, Jiachen Sun, Xiao Zhu 等MobiCom 2021 · 被引用 137 次
- On Adversarial Robustness of Trajectory Prediction for Autonomous VehiclesQingzhao Zhang, Shengtuo Hu, Jiachen Sun, Qi Alfred Chen 等CVPR 2022 · 被引用 132 次
- VIPS: real-time perception fusion for infrastructure-assisted autonomous drivingShuyao Shi, Jiahe Cui, Zhehao Jiang, Zhenyu Yan 等MobiCom 2022 · 被引用 126 次
- An Extensible Framework for Open Heterogeneous Collaborative PerceptionYifan Lu, Yue Hu, Yiqi Zhong, Dequan Wang 等ICLR 2024 · 被引用 116 次
相关 Paper
- On Data Fabrication in Collaborative Vehicular Perception: Attacks and CountermeasuresQingzhao Zhang, Shuowei Jin, Ruiyang Zhu, Jiachen Sun 等USENIX Security 2024 · 被引用 25 次
- Learning Mutual View Information Graph for Adaptive Adversarial Collaborative PerceptionYihang Tao, Senkang Hu, Haonan An, Zhengru Fang 等CVPR 2026 · 被引用 5 次
- From Threat to Trust: Exploiting Attention Mechanisms for Attacks and Defenses in Cooperative PerceptionChenyi Wang, Raymond Muller, Ruoyu Song, Jean-Philippe Monteuuis 等USENIX Security 2025
- A First Physical-World Trajectory Prediction Attack via LiDAR-induced Deceptions in Autonomous DrivingYang Lou, Yi Zhu, Qun Song, Rui Tan 等USENIX Security 2024 · 被引用 11 次
- Pretend Benign: A Stealthy Adversarial Attack by Exploiting Vulnerabilities in Cooperative PerceptionHongwei Lin, Dongyu Pan, Qiming Xia, Hai Wu 等ICCV 2025 · 被引用 6 次
