On Data Fabrication in Collaborative Vehicular Perception: Attacks and Countermeasures (2309.12955v2)
Abstract: Collaborative perception, which greatly enhances the sensing capability of connected and autonomous vehicles (CAVs) by incorporating data from external resources, also brings forth potential security risks. CAVs' driving decisions rely on remote untrusted data, making them susceptible to attacks carried out by malicious participants in the collaborative perception system. However, security analysis and countermeasures for such threats are absent. To understand the impact of the vulnerability, we break the ground by proposing various real-time data fabrication attacks in which the attacker delivers crafted malicious data to victims in order to perturb their perception results, leading to hard brakes or increased collision risks. Our attacks demonstrate a high success rate of over 86% on high-fidelity simulated scenarios and are realizable in real-world experiments. To mitigate the vulnerability, we present a systematic anomaly detection approach that enables benign vehicles to jointly reveal malicious fabrication. It detects 91.5% of attacks with a false positive rate of 3% in simulated scenarios and significantly mitigates attack impacts in real-world scenarios.
- 3GPP Release 14. https://www.3gpp.org/specifications-technologies/releases/release-14, 2017.
- Qualcomm C-V2X. https://www.qualcomm.com/news/releases/2017/09/qualcomm-announces-groundbreaking-cellular-v2x-solution-support-automotive, 2017.
- Huawei C-V2X. https://carrier.huawei.com/en/products/wireless-network-v3/Components/c-v2x, 2019.
- Infineon C-V2X. https://www.infineon.com/dgdl/Infineon-ISPN-Use-Case-Savari-Securing-V2X+communications-ABR-v01_00-EN.pdf?fileId=5546d462689a790c0168e1c1f5e35221, 2019.
- Carla: Open-source simulator for autonomous driving research. https://carla.org/, 2021.
- Autopilot | Tesla. https://www.tesla.com/autopilot, 2022.
- Autoware: Open-source software for self-driving vehicles. https://github.com/Autoware-AI, 2022.
- Baidu Apollo. http://apollo.auto, 2022.
- Bosch C-V2X. https://www.bosch-mobility-solutions.com/en/solutions/connectivity/v2x-connectivity-solutions-cv/, 2022.
- Honda Global | Automated Drive. https://global.honda/innovation/automated-drive/detail.html, 2022.
- OxTS - the inertial navigation (INS) experts since 1998. https://www.oxts.com, 2022.
- SUMO: Simulation of Urban Mobility. https://www.eclipse.org/sumo/, 2022.
- Waymo. https://waymo.com/, 2022.
- Automotive Edge Computing Consortium. https://aecc.org/, 2023.
- Details of ’dts/its-00167’ work item. https://portal.etsi.org/webapp/WorkProgram/Report_WorkItem.asp?WKI_ID=46541, 2023.
- Ford AV Dataset. https://aecc.org/, 2023.
- Ieee sa - ieee 1609.2-2022. https://standards.ieee.org/ieee/1609.2/10258/, 2023.
- J3224_202208: V2x sensor-sharing for cooperative and automated driving. https://www.sae.org/standards/content/j3224_202208/, 2023.
- Mcity - University of Michigan. https://mcity.umich.edu/, 2023.
- Tr 103 562 - v2.1.1 - intelligent transport systems (its). https://www.etsi.org/deliver/etsi_tr/103500_103599/103562/02.01.01_60/tr_103562v020101p.pdf, 2023.
- A survey on deep-learning-based lidar 3d object detection for autonomous driving. Sensors, 22(24):9577, 2022.
- Lidar spoofing attack detection in autonomous vehicles. In 2022 IEEE International Conference on Consumer Electronics (ICCE), pages 1–2. IEEE, 2022.
- Design of a misbehavior detection system for objects based shared perception v2x applications. In 2019 IEEE Intelligent Transportation Systems Conference (ITSC), pages 1165–1172. IEEE, 2019.
- How good are convex hull algorithms? In Proceedings of the eleventh annual symposium on Computational geometry, pages 20–28, 1995.
- Broadcast authentication in latency-critical applications: On the efficiency of ieee 1609.2. IEEE Transactions on Vehicular Technology, 68(12):11577–11587, 2019.
- Replace: Real-time security assurance in vehicular platoons against v2v attacks. In 2021 IEEE International Intelligent Transportation Systems Conference (ITSC), pages 1179–1185. IEEE, 2021.
- Redem: Real-time detection and mitigation of communication attacks in connected autonomous vehicle applications. In Internet of Things. A Confluence of Many Disciplines: Second IFIP International Cross-Domain Conference, IFIPIoT 2019, Tampa, FL, USA, October 31–November 1, 2019, Revised Selected Papers 2, pages 105–122. Springer, 2020.
- Multi-core for k-means clustering on fpga. In 2016 26th International Conference on Field Programmable Logic and Applications (FPL), pages 1–4. IEEE, 2016.
- Invisible for both camera and lidar: Security of multi-sensor fusion based perception in autonomous driving under physical-world attacks. In 2021 IEEE Symposium on Security and Privacy (SP), pages 176–194. IEEE, 2021.
- Adversarial sensor attack on lidar-based perception in autonomous driving. In Proceedings of the 2019 ACM SIGSAC conference on computer and communications security, pages 2267–2281, 2019.
- A cooperative perception environment for traffic operations and control. arXiv preprint arXiv:2208.02792, 2022.
- F-cooper: Feature based cooperative perception for autonomous vehicle edge computing system using 3d point clouds. In Proceedings of the 4th ACM/IEEE Symposium on Edge Computing, pages 88–100, 2019.
- Cooper: Cooperative perception for connected autonomous vehicles based on 3d point clouds. In 2019 IEEE 39th International Conference on Distributed Computing Systems (ICDCS), pages 514–524. IEEE, 2019.
- Coopernaut: End-to-end driving with cooperative perception for networked vehicles. In Proceedings of the IEEE/CVF Conference on Computer Vision and Pattern Recognition, pages 17252–17262, 2022.
- On the segmentation of 3d lidar point clouds. In 2011 IEEE International Conference on Robotics and Automation, pages 2798–2805. IEEE, 2011.
- Random sample consensus: a paradigm for model fitting with applications to image analysis and automated cartography. Communications of the ACM, 24(6):381–395, 1981.
- A grid-based framework for collective perception in autonomous vehicles. Sensors, 21(3):744, 2021.
- Realizing collective perception in a vehicle. In 2016 IEEE Vehicular Networking Conference (VNC), pages 1–8. IEEE, 2016.
- Security attacks impact for collective perception based roadside assistance: A study of a highway on-ramp merging case. In 2020 International Wireless Communications and Mobile Computing (IWCMC), pages 1284–1289. IEEE, 2020.
- Security analysis of {{\{{Camera-LiDAR}}\}} fusion against {{\{{Black-Box}}\}} attacks on autonomous vehicles. In 31st USENIX Security Symposium (USENIX Security 22), pages 1903–1920, 2022.
- Shadow-catcher: Looking into shadows to detect ghost objects in autonomous vehicle 3d sensing. In Computer Security–ESORICS 2021: 26th European Symposium on Research in Computer Security, Darmstadt, Germany, October 4–8, 2021, Proceedings, Part I 26, pages 691–711. Springer, 2021.
- Cvshield: Guarding sensor data in connected vehicle with trusted execution environment. In Proceedings of the Second ACM Workshop on Automotive and Aerial Vehicle Security, pages 1–4, 2020.
- Gatekeeper: A gateway-based broadcast authentication protocol for the in-vehicle ethernet. In Proceedings of the 2022 ACM on Asia Conference on Computer and Communications Security, pages 494–507, 2022.
- Pla-lidar: Physical laser attacks against lidar-based 3d object detection in autonomous vehicle. In 2023 IEEE Symposium on Security and Privacy (SP), pages 710–727. IEEE Computer Society, 2022.
- Probabilistic vehicle trajectory prediction over occupancy grid map via recurrent neural network. In 2017 IEEE 20th International Conference on Intelligent Transportation Systems (ITSC), pages 399–404. IEEE, 2017.
- Vehicle-to-vehicle (v2v) message content plausibility check for platoons through low-power beaconing. Sensors, 19(24):5493, 2019.
- Joint 3d proposal generation and object detection from view aggregation. IROS, 2018.
- Carspeak: a content-centric network for autonomous driving. ACM SIGCOMM Computer Communication Review, 42(4):259–270, 2012.
- Pointpillars: Fast encoders for object detection from point clouds. In Proceedings of the IEEE/CVF Conference on Computer Vision and Pattern Recognition, pages 12697–12705, 2019.
- Multivehicle cooperative local mapping: A methodology based on occupancy grid map merging. IEEE Transactions on Intelligent Transportation Systems, 15(5):2089–2100, 2014.
- Fooling lidar perception via adversarial trajectory perturbation. In Proceedings of the IEEE/CVF International Conference on Computer Vision, pages 7898–7907, 2021.
- Lidar for autonomous driving: The principles, challenges, and trends for automotive lidar and perception systems. IEEE Signal Processing Magazine, 37(4):50–61, 2020.
- The architectural implications of autonomous driving: Constraints and acceleration. In Proceedings of the Twenty-Third International Conference on Architectural Support for Programming Languages and Operating Systems, pages 751–766, 2018.
- Fusioneye: Perception sharing for connected vehicles and its bandwidth-accuracy trade-offs. In 2019 16th Annual IEEE International Conference on Sensing, Communication, and Networking (SECON), pages 1–9. IEEE, 2019.
- “seeing is not always believing”: Detecting perception error attacks against autonomous vehicles. IEEE Transactions on Dependable and Secure Computing, 18(5):2209–2223, 2021.
- Stars can tell: A robust method to defend against gps spoofing attacks using off-the-shelf chipset. In USENIX Security Symposium, pages 3935–3952, 2021.
- Miso-v: Misbehavior detection for collective perception services in vehicular communications. In 2021 IEEE Intelligent Vehicles Symposium (IV), pages 369–376. IEEE, 2021.
- Robust collaborative 3d object detection in presence of pose errors. arXiv preprint arXiv:2211.07214, 2022.
- Efficientps: Efficient panoptic segmentation. International Journal of Computer Vision, 129(5):1551–1579, 2021.
- A variegated look at 5g in the wild: performance, power, and qoe implications. In Proceedings of the 2021 ACM SIGCOMM 2021 Conference, pages 610–625, 2021.
- A survey on security attacks and defense techniques for connected and autonomous vehicles. Computers & Security, 109:102269, 2021.
- Autocast: Scalable infrastructure-less cooperative perception for distributed collaborative driving. arXiv preprint arXiv:2112.14947, 2021.
- Spree: A spoofing resistant gps receiver. In Proceedings of the 22nd Annual International Conference on Mobile Computing and Networking, pages 348–360, 2016.
- Analytical performance evaluation of the collective perception service in ieee 802.11 p networks. In 2020 IEEE Wireless Communications and Networking Conference (WCNC), pages 1–6. IEEE, 2020.
- Drift with devil: Security of multi-sensor fusion based localization in high-level autonomous driving under gps spoofing. In Proceedings of the 29th USENIX Conference on Security Symposium, pages 931–948, 2020.
- Pointrcnn: 3d object proposal generation and detection from point cloud. In Proceedings of the IEEE/CVF conference on computer vision and pattern recognition, pages 770–779, 2019.
- Vips: real-time perception fusion for infrastructure-assisted autonomous driving. In Proceedings of the 28th Annual International Conference on Mobile Computing And Networking, pages 133–146, 2022.
- An efficient and robust object-level cooperative perception framework for connected and automated driving. arXiv preprint arXiv:2210.06289, 2022.
- Towards robust {{\{{LiDAR-based}}\}} perception in autonomous driving: General black-box adversarial sensor attack and countermeasures. In 29th USENIX Security Symposium (USENIX Security 20), pages 877–894, 2020.
- Multiple access in cellular v2x: Performance analysis in highly congested vehicular networks. In 2018 IEEE Vehicular Networking Conference (VNC), pages 1–8. IEEE, 2018.
- Physically realizable adversarial examples for lidar object detection. In Proceedings of the IEEE/CVF Conference on Computer Vision and Pattern Recognition, pages 13716–13725, 2020.
- Adversarial attacks on multi-agent communication. In Proceedings of the IEEE/CVF International Conference on Computer Vision, pages 7768–7777, 2021.
- V2vnet: Vehicle-to-vehicle communication for joint perception and prediction. In European Conference on Computer Vision, pages 605–621. Springer, 2020.
- Gps spoofing countermeasures. Homeland Security Journal, 25(2):19–27, 2003.
- 3d multi-object tracking: A baseline and new evaluation metrics. In 2020 IEEE/RSJ International Conference on Intelligent Robots and Systems (IROS), pages 10359–10366. IEEE, 2020.
- Squeezeseg: Convolutional neural nets with recurrent crf for real-time road-object segmentation from 3d lidar point cloud. In 2018 IEEE International Conference on Robotics and Automation (ICRA), pages 1887–1893. IEEE, 2018.
- Cobevt: Cooperative bird’s eye view semantic segmentation with sparse transformers. arXiv preprint arXiv:2207.02202, 2022.
- V2x-vit: Vehicle-to-everything cooperative perception with vision transformer. In European Conference on Computer Vision, pages 107–124. Springer, 2022.
- Opv2v: An open benchmark dataset and fusion pipeline for perception with vehicle-to-vehicle communication. In 2022 International Conference on Robotics and Automation (ICRA), pages 2583–2589. IEEE, 2022.
- Survey of security aspect of v2x standards and related issues. In 2019 IEEE Conference on Standards for Communications and Networking (CSCN), pages 1–5. IEEE, 2019.
- Dair-v2x: A large-scale dataset for vehicle-infrastructure cooperative 3d object detection. In Proceedings of the IEEE/CVF Conference on Computer Vision and Pattern Recognition, pages 21361–21370, 2022.
- Keypoints-based deep feature fusion for cooperative vehicle detection of autonomous driving. IEEE Robotics and Automation Letters, 7(2):3054–3061, 2022.
- Fast segmentation of 3d point clouds: A paradigm on lidar data for autonomous vehicle applications. In 2017 IEEE International Conference on Robotics and Automation (ICRA), pages 5067–5073. IEEE, 2017.
- On adversarial robustness of trajectory prediction for autonomous vehicles. In Proceedings of the IEEE/CVF Conference on Computer Vision and Pattern Recognition, pages 15159–15168, 2022.
- Robust real-time multi-vehicle collaboration on asynchronous sensors. In Proceedings of the 29th Annual International Conference on Mobile Computing and Networking, 2023.
- Design, implementation, and evaluation of a roadside cooperative perception system. Transportation research record, 2676(11):273–284, 2022.
- Emp: edge-assisted multi-vehicle perception. In Proceedings of the 27th Annual International Conference on Mobile Computing and Networking, pages 545–558, 2021.
- Detection of false data injection attack in connected and automated vehicles via cloud-based sandboxing. IEEE Transactions on Intelligent Transportation Systems, 23(7):9078–9088, 2021.
- A collaborative v2x data correction method for road safety. IEEE Transactions on Reliability, 71(2):951–962, 2022.
- Voxelnet: End-to-end learning for point cloud based 3d object detection. In Proceedings of the IEEE Conference on Computer Vision and Pattern Recognition, pages 4490–4499, 2018.
- Can we use arbitrary objects to attack lidar perception in autonomous driving? In Proceedings of the 2021 ACM SIGSAC Conference on Computer and Communications Security, pages 1945–1960, 2021.