Autonomous driving (AD) systems are often built and tested in a modular fashion, where the performance of different modules is measured using task-specific metrics. These metrics should be chosen so as to capture the downstream impact of each module and the performance of the system as a whole. For example, high perception quality should enable prediction and planning to be performed safely. Even though this is true in general, we show here that it is possible to construct planner inputs that score very highly on various perception quality metrics but still lead to planning failures. In an analogy to adversarial attacks on image classifiers, we call such inputs \textbf{adversarial perception errors} and show they can be systematically constructed using a simple boundary-attack algorithm. We demonstrate the effectiveness of this algorithm by finding attacks for two different black-box planners in several urban and highway driving scenarios using the CARLA simulator. Finally, we analyse the properties of these attacks and show that they are isolated in the input space of the planner, and discuss their implications for AD system deployment and testing.
翻译:自动驾驶系统通常以模块化的方式构建和测试,其中不同模块的性能通过任务特定指标进行评估。这些指标应能反映每个模块对下游的影响以及系统的整体性能。例如,高感知质量应能确保预测和规划安全执行。尽管这一点在一般情况下成立,但本文证明,可以构造出在多种感知质量指标上得分极高但仍导致规划失败的规划器输入。类比于图像分类器的对抗攻击,我们将此类输入称为**对抗感知误差**,并证明可通过一种简单的边界攻击算法系统性地构造它们。我们利用CARLA模拟器,在多个城市和高速公路驾驶场景中针对两种不同黑盒规划器进行攻击实验,验证了该算法的有效性。最后,我们分析了这些攻击的特性,证明它们在规划器输入空间中具有孤立性,并讨论了其对自动驾驶系统部署与测试的启示。