WIP: On Robustness of Lane Detection Models to Physical-World Adversarial Attacks

Takami Sato, Qi Alfred Chen · 2022

the effectiveness of attacks on other lane detection methods and the security properties of these lane detection models against adversarial attacks have not been well studied.In this paper, We first taxonomize state-of-the-art DNNbased lane detection models into 4 major categories ( §II-A) We then introduce state-of-the-art physical-world adversarial attacks against ALC systems ( §II-B).In §III, we construct a methodology to fairly evaluate the robustness of the 4 major types of lane detection models in the end-to-end evaluation.To simulate end-to-end scenarios, we develop a bridge between lane detection methods and the vehicle lateral control implemented in OpenPilot [7], an open-source production ALC system.In §IV, we evaluate the robustness of 4 major types of lane detection approaches against 3 types of physicalworld adversarial attacks by answering 3 research questions.Throughout this study, we find that each type of lane detection model has different security properties against adversarial attacks: several models are even vulnerable to a naive attack which just draws a white line on the road.Surprisingly, but probably not coincidentally, popular production ALC systems, Tesla Model S and OpenPilot [7], properly select the lane detection approach which shows higher resilience to the drawinglane-line attack.We then discuss the conclusion and further directions of our study in §VI. II. BACKGROUND A. DNN-based Lane DetectionWe taxonomize state-of-the-art DNN-based lane detection methods into 4 approaches.Similar taxonomy is also adopted in prior works [8], [9].Segmentation approach.Segmentation approach handles lane detection as a segmentation task, which classifies whether each pixel is on a lane line or not.Since this approach achieved the state-of-the-art performance in the 2017 TuSimple Lane Detection Challenge [2] (all top-3 winners adopt the segmentation approach [10], [11], [12]), it has been applied in many recent lane detection methods [13], [14], [15]. This segmentation approach is also used in the industry.A reverseengineering study reveals that Tesla Model S adopts this segmentation-based approach [6].The major drawback of this approach is its higher computational and memory cost than the other approaches.Due to the nature of the segmentation approach, it needs to predict the classification results for every pixel, the majority of which is just background.Additionally, this approach requires a postprocessing step to extract the lane line curves from the pixel-wise classification result.Abstract-Deep Neural Network (DNN)-based lane detection is widely utilized in autonomous driving technologies.At the same time, recent studies demonstrate that adversarial attacks on lane detection can cause serious consequences on particular production-grade autonomous driving systems.However, the generality of the attacks, especially their effectiveness against other state-of-the-art lane detection approaches, has not been well studied.In this work, we report our progress on conducting the first large-scale empirical study to evaluate the robustness of 4 major types of lane detection methods under 3 types of physical-world adversarial attacks in end-to-end driving scenarios.We find that each lane detection method has different security characteristics, and in particular, some models are highly vulnerable to certain types of attack.Surprisingly, but probably not coincidentally, popular production lane centering systems properly select the lane detection approach which shows higher resistance to such attacks.In the near future, more and more automakers will include autonomous driving features in their products.We hope that our research will help as many automakers as possible to recognize the risks in choosing lane detection algorithms.

Read the paper · More papers on PaperTik