A Universal Adversarial Attack on Time-Series DNNs for Connected Autonomous Vehicles

Qichang Liu, Tanmoy Sen, Haiying Shen, Sai Manoj Pudukotai Dinakarrao · 2022 IEEE 19th International Conference on Mobile Ad Hoc and Smart Systems (MASS) · 2022

In the Connected Autonomous Vehicle (CAV) scenarios, each autonomous vehicle uses the Deep Neural Network (DNN) to process time-series driving signals (e.g., speed, steering wheel angle) sent by its nearby vehicle to output its driving maneuver. Though DNNs are effective in aiding the CAVs, DNNs are vulnerable to adversarial threats. To meet the time-efficiency requirements, a previous CAV black-box adversarial attack method creates an offline perturbation for each traffic context offline and searches the perturbation list for the current context to generate an adversarial attack online. However, searching a long list of traffic contexts consumes a significant amount of time. To further improve the time-efficiency performance, in this paper, we propose a method that generates one universal offline perturbation irrespective of the contexts in producing an untargeted adversarial attack. We first formulate finding the universal perturbation problem as an optimization problem. To solve this problem, we find the perturbation direction that mis-classifies the greatest number of input signals, and then apply a binary search to find the minimal perturbation amount along the chosen optimal direction. The Zeroth Order Adaptive Momentum Method (ZO-AdaMM) is applied to generate the offline universal perturbation. We evaluate the universal perturbation method on real driving dataset. The experiments show that the proposed universal perturbation method requires 52.8% smaller number of queries, 30.7% less perturbation amount and 42.02% less time than other existing universal methods while keeping a high success rate of 87.09%.

Read the paper · More papers on PaperTik