Adversarial Attack Detection for Deep Learning Driving Maneuver Classifiers in Connected Autonomous Vehicles
Tanmoy Sen, Haiying Shen · 2024
Connected and autonomous vehicles (CAVs) will be equipped with onboard deep neural network (DNN) models for processing the data from different sensors and communication units in CAVs and on the roads. In the CAV scenario, each vehicle receives time-series driving signals (e.g., speed, brake status) from nearby vehicles, uses its onboard DNN model for driving maneuver prediction for the nearby vehicles, and then takes corresponding actions for safe and efficient driving. Several black-box adversarial attacks for DNN maneuver classifiers in the CAV scenario have been proposed, in which an attacker deliberately sends false driving signals (i.e., add minimum perturbation to the predicted input) to its nearby vehicle to fool its onboard DNN model to output a wrong class label and cause unwanted traffic incidents or congestion. Though previous research proposed adversarial attack detection methods, the methods are for general DNN models rather than specifically for the time-series driving maneuver classification. To detect such adversarial attacks on the DNN maneuver classifiers in the CAV scenario, in this paper, we analyze the adversarial attacks and propose four different approaches comprised of both statistical and machine learning (ML) based methods. Our trace-driven and real experiments show the combination of all four approaches performs 14% better in accuracy rate and 12% better in precision rate compared to the state-of-the-art statistical and ML-based methods. These improvements are critical for driving safety in CAV scenarios.