In Autonomous Driving (AD), real-time perception is a critical component responsible for detecting surrounding objects to ensure safe driving. While researchers have extensively explored the integrity of AD perception due to its safety and security implications, the aspect of availability (real-time performance) or latency has received limited attention. Existing works on latency-based attack have focused mainly on object detection, i.e., a component in camera-based AD perception, overlooking the entire camera-based AD perception, which hinders them to achieve effective system-level effects, such as vehicle crashes. In this paper, we propose SlowTrack, a novel framework for generating adversarial attacks to increase the execution time of camera-based AD perception. We propose a novel two-stage attack strategy along with the three new loss function designs. Our evaluation is conducted on four popular camera-based AD perception pipelines, and the results demonstrate that SlowTrack significantly outperforms existing latency-based attacks while maintaining comparable imperceptibility levels. Furthermore, we perform the evaluation on Baidu Apollo, an industry-grade full-stack AD system, and LGSVL, a production-grade AD simulator, with two scenarios to compare the system-level effects of SlowTrack and existing attacks. Our evaluation results show that the system-level effects can be significantly improved, i.e., the vehicle crash rate of SlowTrack is around 95% on average while existing works only have around 30%.
翻译:在自动驾驶中,实时感知是负责检测周围物体以确保安全驾驶的关键组件。尽管研究人员已广泛探索了自动驾驶感知因安全与安保影响而具有的完整性,但其可用性(实时性能)或延迟方面受到的关注有限。现有基于延迟的攻击主要聚焦于目标检测(即基于摄像头的自动驾驶感知中的一个组件),忽视了整个基于摄像头的自动驾驶感知系统,这使它们难以实现有效的系统级效果(如车辆碰撞)。本文提出SlowTrack,一种新型的用于生成对抗攻击以增加基于摄像头的自动驾驶感知执行时间的框架。我们提出了一种新颖的两阶段攻击策略及三种新的损失函数设计。我们在四种流行的基于摄像头的自动驾驶感知流水线上进行了评估,结果表明,SlowTrack在保持可比拟的不可感知性水平的同时,显著优于现有的基于延迟的攻击。此外,我们在工业级全栈自动驾驶系统百度Apollo和生产级自动驾驶模拟器LGSVL上,通过两个场景进行了评估,以比较SlowTrack与现有攻击的系统级效果。我们的评估结果表明,系统级效果得到了显著改善:SlowTrack的车辆碰撞率平均约为95%,而现有工作仅为30%左右。