Urfei J, Smirnov F, Weichslgartner A, Wildermann S (2023)
Publication Language: English
Publication Type: Book chapter / Article in edited volumes
Publication year: 2023
Edited Volumes: Machine Learning and Optimization Techniques for Automotive Cyber-Physical Systems
Pages Range: 225 - 256
ISBN: 978-3-031-28015-3
URI: https://link.springer.com/chapter/10.1007/978-3-031-28016-0_7
DOI: 10.1007/978-3-031-28016-0_7
Light Detection and Ranging (LiDAR) plays a key role in the perception stacks of modern advanced driver assistance and autonomous driving systems. Neural networks are the state-of-the-art technique to classify 3D points from LiDAR sensors. However, neural networks have shown to be susceptible to adversarial attacks. In this article, we formalize these adversarial attacks on LiDAR semantic segmentation as generic multi-objective optimization and solve the resulting minimization problem with an Evolutionary Algorithms. Therefore, we can treat the neural network as a black box and do not rely on any intrinsic knowledge as estimating the gradients, etc. We present two ways to encode the problem for Evolutionary Algorithms. Our experiments with the real-world KITTI dataset and a state-of-the-art semantic segmentation neural network for LiDAR data show that Evolutionary Algorithms are suitable for solving the optimization problem. Further, our results confirm that targeting the attack by constraining the volume for manipulated LiDAR points leads to more effective attack patterns with lower perturbations than attack a set of arbitrary points from the scan.
APA:
Urfei, J., Smirnov, F., Weichslgartner, A., & Wildermann, S. (2023). Gradient-Free Adversarial Attacks on 3D Point Clouds from LiDAR Sensors. In Springer International Publishing (Eds.), Machine Learning and Optimization Techniques for Automotive Cyber-Physical Systems. (pp. 225 - 256).
MLA:
Urfei, Jan, et al. "Gradient-Free Adversarial Attacks on 3D Point Clouds from LiDAR Sensors." Machine Learning and Optimization Techniques for Automotive Cyber-Physical Systems. Ed. Springer International Publishing, 2023. 225 - 256.
BibTeX: Download