Mitigation of Camouflaged Adversarial Attacks in Autonomous Vehicles--A Case Study Using CARLA Simulator
Autonomous vehicles (AVs) rely heavily on cameras and artificial intelligence (AI) to make safe and accurate driving decisions. However, since AI is the core enabling technology, this raises serious cyber threats that hinder the large-scale adoption of AVs. Therefore, it is crucial to analyze the resilience of AV security systems against sophisticated attacks that manipulate camera inputs and deceive AI models. In this paper, we develop camera-camouflaged adversarial attacks and asses their impact on traffic sign recognition (TSR) in AVs. Specifically, the camera-camouflaged attacks are initiated by modifying the texture of a stop sign to fool the AV’s object detection system, thereby affecting the AV actuators. The attacks’ effectiveness is tested using the CARLA AV simulator, and the results show that such attacks can delay the auto-braking response to the stop sign, resulting in potentially catastrophic situations. We conduct extensive experiments under various conditions and on different CARLA maps, confirming that the proposed attacks are effective and robust. Then, two defense strategies are presented to mitigate the effect of camera-camouflaged attacks on the stop sign recognition. The proposed attack and defense methods are applicable to other end-to-end trained autonomous cyber-physical systems.
Paper
References (19)
Scroll for more · 7 remaining