Autonomous Driving (AD) systems rely on AI components to make safety and correct driving decisions. Unfortunately, today's AI algorithms are known to be generally vulnerable to adversarial attacks. However, for such AI component-level vulnerabilities to be semantically impactful at the system level, it needs to address non-trivial semantic gaps both (1) from the system-level attack input spaces to those at AI component level, and (2) from AI component-level attack impacts to those at the system level. In this paper, we define such research space as semantic AI security as opposed to generic AI security. Over the past 5 years, increasingly more research works are performed to tackle such semantic AI security challenges in AD context, which has started to show an exponential growth trend. In this paper, we perform the first systematization of knowledge of such growing semantic AD AI security research space. In total, we collect and analyze 53 such papers, and systematically taxonomize them based on research aspects critical for the security field. We summarize 6 most substantial scientific gaps observed based on quantitative comparisons both vertically among existing AD AI security works and horizontally with security works from closely-related domains. With these, we are able to provide insights and potential future directions not only at the design level, but also at the research goal, methodology, and community levels. To address the most critical scientific methodology-level gap, we take the initiative to develop an open-source, uniform, and extensible system-driven evaluation platform, named PASS, for the semantic AD AI security research community. We also use our implemented platform prototype to showcase the capabilities and benefits of such a platform using representative semantic AD AI attacks.
翻译:自动驾驶系统依赖AI组件做出安全且正确的驾驶决策。然而,当前AI算法普遍易受对抗性攻击。要使这类AI组件层面的漏洞在系统层面产生语义层面的影响,需克服两个非平凡的语义鸿沟:(1)从系统级攻击输入空间到AI组件级攻击输入空间的转换;(2)从AI组件级攻击影响至系统级攻击影响的映射。本文将此类研究空间定义为"语义AI安全",以区别于通用AI安全。过去五年间,针对自动驾驶领域语义AI安全挑战的研究工作日益增多,已呈现指数级增长趋势。本文首次对该领域不断发展的自动驾驶语义AI安全研究空间进行知识系统化梳理。我们共收集并分析了53篇相关论文,基于安全领域关键研究维度进行系统分类。通过纵向对比现有自动驾驶AI安全研究成果与横向对比紧密相关领域的安全研究,总结出六个最重大的科学空白。基于这些发现,我们不仅在设计层面,更在研究目标、方法论及社区层面提供了见解与潜在未来方向。针对最为关键的科学方法论级空白,我们率先开发了名为PASS的开源、统一、可扩展的系统驱动评估平台,专为自动驾驶语义AI安全研究社区设计。同时利用所实现的平台原型,通过典型自动驾驶语义AI攻击实例展示了此类平台的能力与优势。