about
Adversarial Objects Against Lidar-Based Autonomous Driving Systems (arxiv.org)
2 points by cracker_jacks on Jul 12, 2019 | hide | past | pdf | discuss on HN

In plain words: They shaped 3D objects to slip past the laser-based obstacle detection self-driving cars use, which sticker tricks on signs cannot fool. The objects evaded a real driving system and still worked when 3D-printed and tested physically.

Abstract · Adversarial Objects Against LiDAR-Based Autonomous Driving Systems

Deep neural networks (DNNs) are found to be vulnerable against adversarial examples, which are carefully crafted inputs with a small magnitude of perturbation aiming to induce arbitrarily incorrect predictions. Recent studies show that adversarial examples can pose a threat to real-world security-critical applications: a "physical adversarial Stop Sign" can be synthesized such that the autonomous driving cars will misrecognize it as others (e.g., a speed limit sign). However, these image-space adversarial examples cannot easily alter 3D scans of widely equipped LiDAR or radar on autonomous vehicles. In this paper, we reveal the potential vulnerabilities of LiDAR-based autonomous driving detection systems, by proposing an optimization based approach LiDAR-Adv to generate adversarial objects that can evade the LiDAR-based detection system under various conditions. We first show the vulnerabilities using a blackbox evolution-based algorithm, and then explore how much a strong adversary can do, using our gradient-based approach LiDAR-Adv. We test the generated adversarial objects on the Baidu Apollo autonomous driving platform and show that such physical systems are indeed vulnerable to the proposed attacks. We also 3D-print our adversarial objects and perform physical experiments to illustrate that such vulnerability exists in the real world. Please find more visualizations and results on the anonymous website: https://sites.google.com/view/lidar-adv.

Yulong Cao, Chaowei Xiao, Dawei Yang, Jing Fang, Ruigang Yang, Mingyan Liu, Bo Li
arXiv:1907.05418 · cs.CR, cs.CV, cs.LG, stat.ML · submitted Jul 11, 2019
abstract · pdf · html

add comment on HN
Also discussed: Jul 2019 (1 point, 0 comments) · Jul 2019 (3 points, 0 comments)