Adversarial Robustness of Deep Sensor Fusion Models
We experimentally study the robustness of deep camera-LiDAR fusion architectures for 2D object detection in autonomous driving. First, we find that the fusion model is usually both more accurate, and more robust against single-source attacks than single-sensor deep neural networks. Furthermore, we show that without adversarial training, early fusion is more robust than late fusion, whereas the two perform similarly after adversarial training. However, we note that single-channel adversarial training of deep fusion is often detrimental even to robustness. Moreover, we observe cross-channel externalities, where single-channel adversarial training reduces robustness to attacks on the other channel. Additionally, we observe that the choice of adversarial model in adversarial training is critical: using attacks restricted to cars' bounding boxes is more effective in adversarial training and exhibits less significant cross-channel externalities. Finally, we find that joint-channel adversarial training helps mitigate many of the issues above, but does not significantly boost adversarial robustness.
Code (0)
등록된 구현이 없습니다.
Tasks
2D Object DetectionAdversarial RobustnessAutonomous DrivingGeneral Classificationobject-detectionObject DetectionSensor FusionSimilar Papers 제목 키워드 기반
Sensor Adversarial Traits: Analyzing Robustness of 3D Object Detection Sensor Fusion Models
A critical aspect of autonomous vehicles (AVs) is the object detection stage, which is increasingly being performed with sensor fusion models: multimodal 3D object detection models which utilize both 2D RGB image data an…
3D Object DetectionAutonomous VehiclesObjectobject-detection+2Exploring Adversarial Robustness of LiDAR-Camera Fusion Model in Autonomous Driving
Our study assesses the adversarial robustness of LiDAR-camera fusion models in 3D object detection. We introduce an attack technique that, by simply adding a limited number of physically constrained adversarial points ab…
3D Object DetectionAdversarial RobustnessAutonomous Drivingobject-detection+1Investigating Vulnerability to Adversarial Examples on Multimodal Data Fusion in Deep Learning
The success of multimodal data fusion in deep learning appears to be attributed to the use of complementary in-formation between multiple input data. Compared to their predictive performance, relatively less attention ha…
Adversarial AttackAdversarial RobustnessSemantic SegmentationCOMMIT: Certifying Robustness of Multi-Sensor Fusion Systems against Semantic Attacks
Multi-sensor fusion systems (MSFs) play a vital role as the perception module in modern autonomous vehicles (AVs). Therefore, ensuring their robustness against common and realistic adversarial semantic transformations, s…
Autonomous Vehiclesobject-detectionObject DetectionSensor FusionExploring Adversarial Robustness of Multi-Sensor Perception Systems in Self Driving
Modern self-driving perception systems have been shown to improve upon processing complementary inputs such as LiDAR with images. In isolation, 2D images have been found to be extremely vulnerable to adversarial attacks.…
Adversarial RobustnessDenoisingSensor Fusion