Attacking End-to-End Visual Navigation Model: How Weak Existing Learning-Based Approaches Can Be?

Hongye Wang,Kefan Jin,Hesheng Wang
DOI: https://doi.org/10.1109/robio54168.2021.9739418
2021-12-27
Abstract:Learning-based self-driving techniques and vehicle navigation approaches are the most hot topics in recent years. However, existing approaches typically assume the attack-free sensor data, the safety issue under large disturbance or external attack have not been well-solved. In this article, we build a simple FGSM-based attack method designed by minimizing the maximum value of the extracted visual features in order to greatly decrease the performance of the popular learning model for vehicle navigation and even make it totally fail. The proposed min-max operation based feature space attack method solves the problems of branch activation uncertainties and the lack of labels. Furthermore, we also provide a general adversarial training framework which can be used to overcome the proposed feature space attack. Simulational experiments in CARLA platform demonstrate the effectiveness and practical applicability of our attacking approach and defence strategy.
What problem does this paper attempt to address?