Bait and Switch: Online Training Data Poisoning of Autonomous Driving Systems

11/08/2020
by   Naman Patel, et al.
10

We show that by controlling parts of a physical environment in which a pre-trained deep neural network (DNN) is being fine-tuned online, an adversary can launch subtle data poisoning attacks that degrade the performance of the system. While the attack can be applied in general to any perception task, we consider a DNN based traffic light classifier for an autonomous car that has been trained in one city and is being fine-tuned online in another city. We show that by injecting environmental perturbations that do not modify the traffic lights themselves or ground-truth labels, the adversary can cause the deep network to learn spurious concepts during the online learning phase. The attacker can leverage the introduced spurious concepts in the environment to cause the model's accuracy to degrade during operation; therefore, causing the system to malfunction.

READ FULL TEXT

page 3

page 4

research
12/12/2022

Implementing Deep Learning-Based Approaches for Article Summarization in Indian Languages

The research on text summarization for low-resource Indian languages has...
research
10/23/2022

On the Transformation of Latent Space in Fine-Tuned NLP Models

We study the evolution of latent space in fine-tuned NLP models. Differe...
research
07/28/2021

Robust and Active Learning for Deep Neural Network Regression

We describe a gradient-based method to discover local error maximizers o...
research
08/09/2019

Februus: Input Purification Defence Against Trojan Attacks on Deep Neural Network Systems

We propose Februus; a novel idea to neutralize insidous and highly poten...
research
09/28/2022

Learning Deep Representations via Contrastive Learning for Instance Retrieval

Instance-level Image Retrieval (IIR), or simply Instance Retrieval, deal...
research
10/14/2019

Federated Transfer Reinforcement Learning for Autonomous Driving

Reinforcement learning (RL) is widely used in autonomous driving tasks a...
research
06/03/2023

Mitigating Backdoor Attack Via Prerequisite Transformation

In recent years, with the successful application of DNN in fields such a...

Please sign up or login with your details

Forgot password? Click here to reset