Attacking Vision-based Perception in End-to-End Autonomous Driving Models

10/02/2019
by   Adith Boloor, et al.
35

Recent advances in machine learning, especially techniques such as deep neural networks, are enabling a range of emerging applications. One such example is autonomous driving, which often relies on deep learning for perception. However, deep learning-based perception has been shown to be vulnerable to a host of subtle adversarial manipulations of images. Nevertheless, the vast majority of such demonstrations focus on perception that is disembodied from end-to-end control. We present novel end-to-end attacks on autonomous driving in simulation, using simple physically realizable attacks: the painting of black lines on the road. These attacks target deep neural network models for end-to-end autonomous driving control. A systematic investigation shows that such attacks are easy to engineer, and we describe scenarios (e.g., right turns) in which they are highly effective. We define several objective functions that quantify the success of an attack and develop techniques based on Bayesian Optimization to efficiently traverse the search space of higher dimensional attacks. Additionally, we define a novel class of hijacking attacks, where painted lines on the road cause the driver-less car to follow a target path. Through the use of network deconvolution, we provide insights into the successful attacks, which appear to work by mimicking activations of entirely different scenarios. Our code is available at https://github.com/xz-group/AdverseDrive

READ FULL TEXT

page 1

page 6

page 7

page 10

page 11

research
03/12/2019

Simple Physical Adversarial Examples against End-to-End Autonomous Driving Models

Recent advances in machine learning, especially techniques such as deep ...
research
03/16/2021

Adversarial Driving: Attacking End-to-End Autonomous Driving Systems

As the research in deep neural networks advances, deep convolutional net...
research
02/27/2021

End-to-end Uncertainty-based Mitigation of Adversarial Attacks to Automated Lane Centering

In the development of advanced driver-assistance systems (ADAS) and auto...
research
10/03/2022

CERBERUS: Simple and Effective All-In-One Automotive Perception Model with Multi Task Learning

Perceiving the surrounding environment is essential for enabling autonom...
research
01/21/2020

GhostImage: Perception Domain Attacks against Vision-based Object Classification Systems

In vision-based object classification systems, imaging sensors perceive ...
research
12/26/2020

Improving the Generalization of End-to-End Driving through Procedural Generation

Recently there is a growing interest in the end-to-end training of auton...
research
10/17/2020

Finding Physical Adversarial Examples for Autonomous Driving with Fast and Differentiable Image Compositing

There is considerable evidence that deep neural networks are vulnerable ...

Please sign up or login with your details

Forgot password? Click here to reset