日本フィジカルAI新聞

世界のフィジカルAIを、日本語で。

週刊ニュースレター購読
協調知覚/敵対的攻撃arXiv:2609.17856

異種協調知覚の敵対的ロバスト性の検証

Investigating Adversarial Robustness of Heterogeneous Cooperative Perception

シェア:XThreadsFacebookLINEはてブBluesky

異種センサ構成の協調知覚は攻撃に自然に強いという通説を覆し、ラベル不要の単一順伝播で物体除去攻撃を生成するHetPoisonを提案した研究。

詳しい要約

1. どんなもの?

- 異種協調知覚(Heterogeneous Cooperative Perception, CP)の敵対的ロバスト性を調査 - 異種性が攻撃に対する自然な防御になるとの仮説を検証 - 攻撃手法HetPoisonと防御手法HetShieldを提案 - 異種設計間で転移する単一順伝播のラベル不要攻撃を実現 - 時空間一貫性を検証する軽量信頼層で攻撃による精度低下を83-95%回復

2. 先行研究と比べてどこがすごい?

- 従来は異種性が防御になると広く仮説されていた - 本研究はその保護がほぼ幻想であることを実証 - 適切に調整した反復攻撃でロバスト性ギャップを閉じるか逆転 - 最適化ベース攻撃は実用的脅威でないが、HetPoisonは単一順伝播で実用的 - HetShieldは先行技術を上回る回復性能を示す

3. 技術・手法の肝は?

- 異種CPの攻撃面を分析 - マッチドオブジェクティブハーネスで摂動予算・目的・順伝播を標準化 - 反復攻撃を適用しロバスト性ギャップを評価 - HetPoison: 学習済み生成器で単一順伝播・ラベル不要の除去摂動を生成 - HetShield: 特徴間の時空間一貫性を検証する軽量信頼層

4. どうやって有効だと検証した?

- マッチドオブジェクティブハーネスで攻撃を標準化し評価 - 反復攻撃がロバスト性ギャップを閉じる/逆転することを示す - HetPoisonが主要異種設計間で転移し、最適化ベース攻撃と同等以上 - HetShieldが攻撃による精度低下を83-95%回復し先行技術を上回る

5. 議論はある?

- 異種性自体は防御にならないと結論 - 最適化ベース攻撃は実用的脅威でないが、HetPoisonは実用的 - HetShieldの有効性を示すが、限界や議論は要旨からは不明

6. 次に読むべき論文は?

- 異種協調知覚(Heterogeneous Cooperative Perception) - 敵対的攻撃(Adversarial Attacks) - ロバスト性(Robustness) - 特徴マップ融合(Feature Map Fusion) - 転移学習(Transfer Learning) - 信頼層(Trust Layer)

※ AIが要旨から生成した要約です。正確性は原文をご確認ください。

著者: Chenyi Wang, Yutong Liu, Qingzhao Zhang, Ming F. Li

分類: cs.CV, cs.CR, cs.MA, cs.RO

原文アブストラクト

Heterogeneous cooperative perception (CP) enables connected vehicles with diverse sensor setups to share spatial awareness via compact feature maps, where receivers reconcile these maps using learned translation modules for fusion and inference. Prior attacks against CP in a homogeneous setting reveal that the data exchange introduces a critical attack surface: a single malicious agent can transmit crafted features that erase real objects from a neighbor's fused scene. Yet, it is widely hypothesized that heterogeneity naturally defends against these attacks, as the attacker lacks knowledge of the victim's detector and the translation module scrambles adversarial gradients. We demonstrate that this protection is largely an illusion. Using a matched-objective harness to standardize the perturbation budget, objective, and forward path, we show that properly tuned iterative attacks close or reverse the apparent robustness gap. However, these optimization-based attacks require ground-truth labels and iterative backpropagation, meaning they do not represent a practical field threat running in real-time. To bridge this gap, we introduce HetPoison, a learned generator that crafts a removal perturbation in a single, label-free forward pass. HetPoison transfers across major heterogeneous designs without requiring access to the victim's detector, matching or exceeding the effectiveness of expensive optimizer-based attacks. Since heterogeneity itself is not a defense, we propose HetShield, a lightweight trust layer that validates the spatiotemporal consistency across features, recovering 83--95% of the accuracy degraded by attacks, outperforming prior art.

PR本紙発行元 EmplifAI