Exploring Adversarial Robustness of Multi-Sensor Perception Systems in Self Driving

Modern self-driving perception systems have been shown to improve upon\nprocessing complementary inputs such as LiDAR with images. In isolation, 2D\nimages have been found to be extremely vulnerable to adversarial attacks. Yet,\nthere have been limited studies on the adversarial robustness of multi-modal\nmodels that fuse LiDAR features with image features. Furthermore, existing\nworks do not consider physically realizable perturbations that are consistent\nacross the input modalities. In this paper, we showcase practical\nsusceptibilities of multi-sensor detection by placing an adversarial object on\ntop of a host vehicle. We focus on physically realizable and input-agnostic\nattacks as they are feasible to execute in practice, and show that a single\nuniversal adversary can hide different host vehicles from state-of-the-art\nmulti-modal detectors. Our experiments demonstrate that successful attacks are\nprimarily caused by easily corrupted image features. Furthermore, we find that\nin modern sensor fusion methods which project image features into 3D,\nadversarial attacks can exploit the projection process to generate false\npositives across distant regions in 3D. Towards more robust multi-modal\nperception systems, we show that adversarial training with feature denoising\ncan boost robustness to such attacks significantly. However, we find that\nstandard adversarial defenses still struggle to prevent false positives which\nare also caused by inaccurate associations between 3D LiDAR points and 2D\npixels.\n

Paper

Similar papers

© 2026 NYSGPT2525 LLC