Safety is paramount in autonomous vehicles (AVs). Auto manufacturers have spent millions of dollars and driven billions of miles to prove AVs are safe. However, this is ill-suited to answer: what happens to an AV if its data are adversarially compromised? We design a framework built on security-relevant metrics to benchmark AVs on longitudinal datasets. We establish the capabilities of a cyber-level attacker with only access to LiDAR datagrams and from them derive novel attacks on LiDAR. We demonstrate that even though the attacker has minimal knowledge and only access to raw datagrams, the attacks compromise perception and tracking in multi-sensor AVs and lead to objectively unsafe scenarios. To mitigate vulnerabilities and advance secure architectures in AVs, we present two improvements for security-aware fusion -- a data-asymmetry monitor and a scalable track-to-track fusion of 3D LiDAR and monocular detections (T2T-3DLM); we demonstrate that the approaches significantly reduce the attack effectiveness.
翻译:安全性是自动驾驶车辆(AV)的核心要素。汽车制造商投入数百万美元并完成数十亿英里测试以证明其安全性,但这难以回答一个问题:当自动驾驶车辆数据遭受恶意篡改时会发生什么?我们设计了一个基于安全相关指标的评估框架,能够在纵向数据集上对自动驾驶车辆进行基准测试。我们确定了仅能访问LiDAR数据报的网络攻击者能力边界,并据此提出了针对LiDAR的新型攻击方法。研究表明,即使攻击者仅具备最低限度的知识且仅能访问原始数据报,仍可破坏多传感器自动驾驶车辆中的感知与跟踪功能,并导致客观上的不安全场景。为缓解此类漏洞并推动自动驾驶车辆安全架构发展,我们提出了两项面向安全感知的融合改进方案——数据不对称监测器以及可扩展的3D LiDAR与单目检测的轨迹-轨迹融合方法(T2T-3DLM);实验证明该方法可显著降低攻击有效性。