Discovering New Shadow Patterns for Black-Box Attacks on Lane Detection of Autonomous Vehicles

Pedram MohajerAnsari,Alkim Domeke,Jan de Voor,Arkajyoti Mitra,Grace Johnson,Amir Salarpour,Habeeb Olufowobi,Mohammad Hamad,Mert D. Pesé
2024-09-27
Abstract:Ensuring autonomous vehicle (AV) security remains a critical concern. An area of paramount importance is the study of physical-world adversarial examples (AEs) aimed at exploiting vulnerabilities in perception systems. However, most of the prevailing research on AEs has neglected considerations of stealthiness and legality, resulting in scenarios where human drivers would promptly intervene or attackers would be swiftly detected and punished. These limitations hinder the applicability of such examples in real-life settings. In this paper, we introduce a novel approach to generate AEs using what we term negative shadows: deceptive patterns of light on the road created by strategically blocking sunlight, which then cast artificial lane-like patterns. These shadows are inconspicuous to a driver while deceiving AV perception systems, particularly those reliant on lane detection algorithms. By prioritizing the stealthy nature of attacks to minimize driver interventions and ensuring their legality from an attacker's standpoint, a more plausible range of scenarios is established. In multiple scenarios, including at low speeds, our method shows a high safety violation rate. Using a 20-meter negative shadow, it can direct a vehicle off-road with a 100% violation rate at speeds over 10 mph. Other attack scenarios, such as causing collisions, can be performed with at least 30 meters of negative shadow, achieving a 60-100% success rate. The attack also maintains an average stealthiness of 83.6% as measured through a human subject experiment, ensuring its efficacy in covert settings.
Cryptography and Security
What problem does this paper attempt to address?
### What problem does this paper attempt to solve? This paper aims to solve the problem of security vulnerabilities in the lane - detection systems of autonomous vehicles (AVs). Specifically, the authors focus on adversarial examples (AEs) in the physical world, which can deceive the perception systems of autonomous vehicles and cause abnormal behavior. However, most of the existing research ignores stealthiness and legality when designing adversarial examples, which makes these attacks difficult to carry out in real - world scenarios because human drivers may quickly intervene or attackers are easily detected and punished. To solve these problems, the authors propose a new method for generating adversarial examples, called "Negative Shadow Attack". This attack deceives the lane - detection algorithms of autonomous vehicles by taking advantage of a natural phenomenon in the environment - shadows, specifically by projecting artificially - created bright areas similar to lane markings on the road (i.e., negative shadows). These negative shadows are not easily noticeable to human drivers, so they can effectively deceive the perception systems of autonomous vehicles without attracting attention. ### Main contributions 1. **Negative Shadow Attack with stealthiness, practicality and legality**: The authors introduce a novel and stealthy method that uses objects placed on private property (such as awnings or fences) to project negative shadows. This method not only demonstrates the practicality of the attack but also emphasizes its stealthiness and confirms that performing this attack does not violate any laws or regulations. 2. **Exploiting common vulnerabilities in lane - detection algorithms**: To carry out the negative shadow attack, the authors take advantage of a widespread vulnerability in the pre - processing stage of lane - detection algorithms. This vulnerability allows the successful execution of the negative shadow attack without the need for in - depth knowledge of the autonomous driving system. System evaluations show that negative shadows can explore the influence of various parameters on the false detection of lane - detection algorithms, causing them to misidentify negative shadows as real lane markings. 3. **Evaluating the effectiveness and safety of the attack**: The authors evaluate the safety impact of the negative shadow attack in two ways: software - in - the - loop simulation and small - scale road tests using Openpilot. The results show that in multiple situations, even at low speeds, the negative shadow attack can lead to a high proportion of safety violation rates. For example, using a 20 - meter - long negative shadow can make the vehicle deviate from the road with a 100% success rate when the vehicle speed exceeds 10 miles per hour. Other attack scenarios, such as causing a collision, require at least a 30 - meter - long negative shadow, with a success rate of 60 - 100%. 4. **Evaluating stealthiness through human experiments**: The effectiveness of the negative shadow attack highly depends on its stealthiness. To this end, the authors conduct a human experiment to empirically evaluate the stealthiness of the negative shadow attack and the probability of it being ignored by drivers. The experimental results show that it is difficult for drivers to detect the existence of the negative shadow attack, highlighting its stealthiness and effectiveness in real - world scenarios. ### Summary In conclusion, this paper overcomes the limitations of ignoring stealthiness and legality in existing adversarial example research by introducing the negative shadow attack, providing a more stealthy and legal attack method, and thus being closer to attack scenarios that may occur in the real world. This helps to better understand the security vulnerabilities of autonomous vehicles and provides an important reference for future defense measures.