Exploration of Machine Learning Attacks in Automotive Systems Using Physical and Mixed Reality Platforms
Venkata Sai Gireesh Chamarthi, Xiangru Chen, Bhagawat Baanav Yedla Ravi, Sandip Kumar Ray · 2023 IEEE International Conference on Consumer Electronics (ICCE) · 2023
Adversarial attacks on Deep Neural Networks represent a critical challenge in the adoption of DNNs in critical applications. However, - and in spite of its great need, - there is significant mystery surrounding attacks on DNNs. One reason for this is the lack of a platform that enables users to get a hands-on, intuitive understanding of the attacks. In this paper, we address this problem by designing an extensible, configurable exploration platform for studying various attacks on DNNs. Our platform specifically focuses on DNNs deployed in Computer Vision modules of automotive systems. Using the platform, the user can perform various adversarial machine learning attacks, such as evasion attacks and image-perturbation attacks, and comprehend their adversarial effects on autonomous vehicles. The platform can be used to plug and play with various neural network models developed for Traffic Sign Recognition systems in autonomous vehicles. The infrastructure includes both physical and mixed-reality variants, and we demonstrate the usage of the platform on two traffic sign recognition models with different adversarial attacks.