Investigating Adversarial Robustness of Heterogeneous Cooperative Perception

📅 2026-09-15
📈 Citations: 0
Influential: 0
📄 PDF
🤖 AI Summary
研究异构协同感知的对抗鲁棒性问题,通过HetPoison生成器和HetShield信任层方法提高系统安全性。
📝 Abstract
Heterogeneous cooperative perception (CP) enables connected vehicles with diverse sensor setups to share spatial awareness via compact feature maps, where receivers reconcile these maps using learned translation modules for fusion and inference. Prior attacks against CP in a homogeneous setting reveal that the data exchange introduces a critical attack surface: a single malicious agent can transmit crafted features that erase real objects from a neighbor's fused scene. Yet, it is widely hypothesized that heterogeneity naturally defends against these attacks, as the attacker lacks knowledge of the victim's detector and the translation module scrambles adversarial gradients. We demonstrate that this protection is largely an illusion. Using a matched-objective harness to standardize the perturbation budget, objective, and forward path, we show that properly tuned iterative attacks close or reverse the apparent robustness gap. However, these optimization-based attacks require ground-truth labels and iterative backpropagation, meaning they do not represent a practical field threat running in real-time. To bridge this gap, we introduce HetPoison, a learned generator that crafts a removal perturbation in a single, label-free forward pass. HetPoison transfers across major heterogeneous designs without requiring access to the victim's detector, matching or exceeding the effectiveness of expensive optimizer-based attacks. Since heterogeneity itself is not a defense, we propose HetShield, a lightweight trust layer that validates the spatiotemporal consistency across features, recovering 83--95% of the accuracy degraded by attacks, outperforming prior art.
Problem

Research questions and friction points this paper is trying to address.

Adversarial Robustness
Heterogeneous Cooperative Perception
Iterative Attacks
Innovation

Methods, ideas, or system contributions that make the work stand out.

HetPoison
HetShield
Adversarial Attacks
Heterogeneous Cooperative Perception
Spatiotemporal Consistency
🔎 Similar Papers
No similar papers found.
💼 Related Jobs
No related jobs found.
C
Chenyi Wang
School of Electrical, Computing, and Software Engineering, University of Arizona
Y
Yutong Liu
School of Electrical, Computing, and Software Engineering, University of Arizona
Qingzhao Zhang
Qingzhao Zhang
University of Arizona
system securitysoftware securityAI security
M
Ming F. Li
School of Electrical, Computing, and Software Engineering, University of Arizona