Skip to main navigation Skip to search Skip to main content

ATTA: Adversarial Task-transferable Attacks on Autonomous Driving Systems

  • Tsinghua University
  • Beijing University of Posts and Telecommunications
  • Nanyang Technological University

Research output: Chapter in Book/Report/Conference proceedingConference contributionpeer-review

6 Citations (Scopus)

Abstract

Deep learning (DL) based perception models have enabled the possibility of current autonomous driving systems (ADS). However, various studies have pointed out that the DL models inside the ADS perception modules are vulnerable to adversarial attacks which can easily manipulate these DL models' predictions. In this paper, we propose a more practical adversarial attack against the ADS perception module. Particularly, instead of targeting one of the DL models inside the ADS perception module, we propose to use one universal patch to mislead multiple DL models inside the ADS perception module simultaneously which leads to a higher chance of system-wide malfunction. We achieve such a goal by attacking the attention of DL models as a higher level of feature representation rather than traditional gradient-based attacks. We successfully generate a universal patch containing malicious perturbations that can attract multiple victim DL models' attention to further induce their prediction errors. We verify our attack with extensive experiments on a typical ADS perception module structure with five famous datasets and also physical world scenes11We release our code at https://github.com/qingjiesjtu/ATTA

Original languageEnglish
Title of host publicationProceedings - 23rd IEEE International Conference on Data Mining, ICDM 2023
EditorsGuihai Chen, Latifur Khan, Xiaofeng Gao, Meikang Qiu, Witold Pedrycz, Xindong Wu
PublisherInstitute of Electrical and Electronics Engineers Inc.
Pages798-807
Number of pages10
ISBN (Electronic)9798350307887
DOIs
Publication statusPublished - 1 Jan 2023
Event23rd IEEE International Conference on Data Mining, ICDM 2023 - Hybrid, Shanghai, China
Duration: 1 Dec 20234 Dec 2023

Publication series

NameProceedings - IEEE International Conference on Data Mining, ICDM
ISSN (Electronic)2374-8486

Conference

Conference23rd IEEE International Conference on Data Mining, ICDM 2023
Country/TerritoryChina
CityHybrid, Shanghai
Period1/12/234/12/23

Keywords

  • Deep learning
  • adversarial attack
  • autonomous driving system
  • computer vision

Fingerprint

Dive into the research topics of 'ATTA: Adversarial Task-transferable Attacks on Autonomous Driving Systems'. Together they form a unique fingerprint.

Cite this