Javascript must be enabled to continue!
Enhancing Autonomous Vehicle's Perception Under Adversarial Attacks Using Dual Autoencoders
View through CrossRef
Machine learning (ML) has become essential for tasks like detection and classification in autonomous vehicles (AVs). However, ML models are vulnerable to adversarial attacks, which can undermine passenger trust and raise safety concerns in autonomous driving systems. This is especially critical in systems like traffic sign recognition (TSR), where a misclassification caused by an adversarial attack could lead to serious safety risks. In this work, we propose a lightweight yet accurate defense system against adversarial attacks in TSR systems. Specifically, we first investigate the vulnerabilities of TSR models to adversarial attacks, where adversarial attacks, such as projected gradient descent (PGD) and the fast gradient sign method (FGSM), are considered and an adversarial attack pipeline is proposed that focuses on specific regions of interest (ROI) in traffic signs using a ScoreCAM-based approach to improve the effectiveness of FGSM and PGD attacks on TSR models. These attacks manipulate the input data to mislead the models, achieving a high attack success rate (ASR) by exploiting their vulnerabilities. Then, to address adversarial attacks, we propose a dual autoencoder-based defense system against adversarial attacks on traffic signs. This model combines two encoders that work collaboratively: one optimized for global feature extraction and the other for local features. The defense mechanism also integrates residual connections to retain important features of the input and attention mechanism to highlight critical regions in traffic sign images. Experimental results demonstrate that the proposed defense model outperforms existing works with a test classification accuracy of 96.08% and 96.69% against PGD and FGSM attack scenarios, respectively, while maintaining a fraction of the model size (approximately 9MBs) and a reduced parameter count, thereby making it the most lightweight and high-performance model available for TSR.
Institute of Electrical and Electronics Engineers (IEEE)
Title: Enhancing Autonomous Vehicle's Perception Under Adversarial Attacks Using Dual Autoencoders
Description:
Machine learning (ML) has become essential for tasks like detection and classification in autonomous vehicles (AVs).
However, ML models are vulnerable to adversarial attacks, which can undermine passenger trust and raise safety concerns in autonomous driving systems.
This is especially critical in systems like traffic sign recognition (TSR), where a misclassification caused by an adversarial attack could lead to serious safety risks.
In this work, we propose a lightweight yet accurate defense system against adversarial attacks in TSR systems.
Specifically, we first investigate the vulnerabilities of TSR models to adversarial attacks, where adversarial attacks, such as projected gradient descent (PGD) and the fast gradient sign method (FGSM), are considered and an adversarial attack pipeline is proposed that focuses on specific regions of interest (ROI) in traffic signs using a ScoreCAM-based approach to improve the effectiveness of FGSM and PGD attacks on TSR models.
These attacks manipulate the input data to mislead the models, achieving a high attack success rate (ASR) by exploiting their vulnerabilities.
Then, to address adversarial attacks, we propose a dual autoencoder-based defense system against adversarial attacks on traffic signs.
This model combines two encoders that work collaboratively: one optimized for global feature extraction and the other for local features.
The defense mechanism also integrates residual connections to retain important features of the input and attention mechanism to highlight critical regions in traffic sign images.
Experimental results demonstrate that the proposed defense model outperforms existing works with a test classification accuracy of 96.
08% and 96.
69% against PGD and FGSM attack scenarios, respectively, while maintaining a fraction of the model size (approximately 9MBs) and a reduced parameter count, thereby making it the most lightweight and high-performance model available for TSR.
Related Results
What Will the Law Do About Autonomous Vehicles?
What Will the Law Do About Autonomous Vehicles?
Autonomous vehicles are just beginning to emerge on roads and highways all over the world. The autonomous vehicle prototypes available now provide some clues to understanding how l...
ProDef-MDS: A Proactive Defense Mechanism Protecting Malware Detection Systems from Adversarial Attacks
ProDef-MDS: A Proactive Defense Mechanism Protecting Malware Detection Systems from Adversarial Attacks
Malware threatens cybersecurity by enabling data theft, unauthorized access, and extortion. Traditional malware detection systems (MDS) struggle with the increasing volume and comp...
Efficient Defense Against First Order Adversarial Attacks on Convolutional Neural Networks
Efficient Defense Against First Order Adversarial Attacks on Convolutional Neural Networks
Machine learning models, especially neural networks, are vulnerable to adversarial attacks, where inputs are purposefully altered to induce incorrect predictions. These adversarial...
Optimized Adversarial Defense: Combating Adversarial Attacks with Denoising Autoencoders and Ensemble Learning
Optimized Adversarial Defense: Combating Adversarial Attacks with Denoising Autoencoders and Ensemble Learning
Adversarial attacks pose a significant risk to machine learning models by introducing carefully crafted perturbations that can mislead the models into producing incorrect outputs. ...
Robustness and Security in Deep Learning: Adversarial Attacks and Countermeasures
Robustness and Security in Deep Learning: Adversarial Attacks and Countermeasures
Deep learning models have demonstrated remarkable performance across various domains, yet their susceptibility to adversarial attacks remains a significant concern. In this study, ...
AHEAD: A Novel Technique Combining Anti-Adversarial Hierarchical Ensemble Learning with Multi-Layer Multi-Anomaly Detection for Blockchain Systems
AHEAD: A Novel Technique Combining Anti-Adversarial Hierarchical Ensemble Learning with Multi-Layer Multi-Anomaly Detection for Blockchain Systems
Blockchain technology has impacted various sectors and is transforming them through its decentralized, immutable, transparent, smart contracts (automatically executing digital agre...
Computational Analysis of Concept Autonomous Heavy Vehicle to Reduce Drag Using Shape Optimization Technique and Add-On Devices
Computational Analysis of Concept Autonomous Heavy Vehicle to Reduce Drag Using Shape Optimization Technique and Add-On Devices
The design of heavy commercial vehicles plays a vital role in improving aerodynamic performance. Typically, conventional commercial vehicles have box-shaped driver cabins and stand...
Improving Intrusion Detection Systems' Resilience to Adversarial Attacks through Feature Engineering and Hybrid Metaheuristic Algorithms
Improving Intrusion Detection Systems' Resilience to Adversarial Attacks through Feature Engineering and Hybrid Metaheuristic Algorithms
Abstract
Intrusion Detection Systems (IDS) are essential for securing computer networks against malicious activities. However, the rise of adversarial attacks serio...

