On Adversarial Attacks In Acoustic Drone Localization
This paper addresses the gap in adversarial research for drone navigation by analyzing the impact of PGD attacks on acoustic-based localization systems and proposing a novel algorithm to effectively recover from such perturbations.
Original authors:Tamir Shor, Chaim Baskin, Alex Bronstein
Original authors: Tamir Shor, Chaim Baskin, Alex Bronstein
Original paper licensed under CC BY 4.0 (http://creativecommons.org/licenses/by/4.0/). ✨ This is an AI-generated explanation of the paper below. It is not written or endorsed by the authors. For technical accuracy, refer to the original paper. Read full disclaimer
Imagine a drone flying through a dark, foggy room where it can't see anything. To find its way, it doesn't use a camera or GPS; instead, it listens to the hum of its own spinning propellers. It knows exactly how its own sound should sound, and by comparing that to what it hears, it can figure out where it is in the room. This is called acoustic localization.
This paper is a story about how a "hacker" could trick this system, and how the drone can fight back.
The Problem: The "Bad Actor" in the Room
The researchers asked: What if someone stands in the room with a loudspeaker and plays a specific, tricky noise designed to confuse the drone?
They discovered that you don't need to break the drone's software. You just need to play the right "wrong" sound.
The Analogy: Imagine you are trying to hear a friend whispering in a crowded room. If someone starts playing a recording of your friend's voice, but slightly out of sync and with a weird echo, you might get confused about where your friend actually is.
The Result: The researchers created a "universal" noise (a specific pattern of sound) that, when played from a speaker, made the drone think it was in a completely different part of the room. In their tests, this tricked the drone so badly that its location errors jumped from being very accurate (almost perfect) to being wildly wrong (off by nearly 40% of the room size). The drone could be tricked into crashing or flying into a wall.
The Defense: The "Shaking Handshake"
The researchers didn't just stop at breaking the system; they built a shield. They used a clever trick involving the drone's own rotors.
The Analogy: Imagine you and a friend are trying to talk in a noisy room. Your friend decides to speak in a very specific rhythm: Clap, clap, pause, clap. The noise in the room is random and doesn't follow that rhythm.
If you listen to the noise without the rhythm, it's just chaos.
But if you know your friend's rhythm, you can predict exactly when they will speak. You can subtract their voice from the total noise, leaving only the "static" (the bad guy's noise).
Once you isolate the bad guy's noise, you can ignore it and hear your friend clearly again.
How it works for the drone: The drone's rotors spin at a constant speed, but the researchers made the drone slightly change the timing (phase) of its rotors in a predictable pattern.
The drone's own sound changes when the rotors change their timing.
The hacker's sound (from the speaker) stays exactly the same because it doesn't know the rotors are changing.
By listening to the sound before and after a tiny timing shift, the drone can mathematically subtract the hacker's sound (which didn't change) from the total noise. This leaves only the drone's clean, original sound, allowing it to know its true location again.
The Big Takeaways
Acoustic systems are vulnerable: Just like cameras can be fooled by stickers or lights, sound-based navigation can be fooled by a speaker playing the right song.
Location doesn't matter much: The hacker doesn't need to stand in a specific spot to be effective. Even a speaker in the middle of the room can confuse the drone everywhere.
The "Self-Sound" trick works: By using the drone's own mechanical movements as a "secret code," the drone can filter out the hacker's noise and see the truth again.
In short: The paper shows that while drones listening to themselves are a great idea for navigating in the dark, they are currently easy to trick with a loudspeaker. However, the authors found a way to make the drone "tune out" the trickery by using its own spinning blades as a filter, keeping it safe and on course.
1. Problem Statement
The paper addresses a critical security gap in acoustic-based drone localization. While drones increasingly rely on acoustic sensing (using the sound of their own rotors) to navigate in GPS-denied or visually obscured environments, the security of these systems against adversarial attacks has not been studied.
The Threat: An attacker can use an external speaker to emit adversarial sound waves that interfere with the drone's microphone array.
The Goal: To manipulate the drone's localization model, causing it to miscalculate its position, potentially leading to navigation failure or collisions.
The Gap: Unlike vision-based systems where adversarial attacks are well-studied, acoustic localization lacks a formal threat model, attack methodology, or defense mechanisms.
2. Methodology
The authors propose a comprehensive framework involving three main components: a modified localization pipeline, an adversarial attack formulation, and a novel defense mechanism.
A. Modified Localization Pipeline (The "Clean" Model)
The authors build upon the acoustic localization algorithm from Serussi et al. (2024) but adapt it for differentiable optimization:
Neural Acoustic Fields (NAFs): They replace the computationally expensive Image Source Model (ISM) with NAFs. NAFs provide a neural representation of Room Impulse Responses (RIRs) trained on real acoustic data, allowing for fast, differentiable simulation of sound propagation.
Process: The drone's self-sound is modeled as a set of point sources. The RIR (convolving source and sensor locations) is computed via NAFs, and a transformer-based neural network regresses the drone's 2D location from the microphone array inputs.
B. Adversarial Attack Formulation
The authors formulate a White-Box Projected Gradient Descent (PGD) attack:
Threat Model: A stationary, omni-directional external speaker controlled by the attacker.
Perturbation Strategy: Instead of optimizing raw audio samples, the attack optimizes a set of learnable amplitudes for a basis of sine waves. This ensures the perturbation is periodic (matching the drone's rotor cycle) and reduces the search space.
Constraints: To make the attack stealthy and feasible, they impose:
Frequency Constraints: Perturbation frequencies must be integer multiples of the drone's cycle frequency.
Signal Constraints: Limits on amplitude and power (loudness) to prevent trivial detection.
Location Constraints: The source must remain within physical environment boundaries.
Optimization: The objective is to maximize the Mean Squared Error (MSE) between the predicted location and the ground truth. They optimize both the perturbation waveform and the source location (though they find optimizing location yields marginal gains).
C. Defense: Phase Modulation Perturbation Delineation
The authors propose a novel defense algorithm that exploits the drone's ability to actively modulate its own sound:
Mechanism: The drone actively adjusts the phase (timing offsets) of its rotors.
Principle:
The drone's sound changes predictably based on the phase modulation.
The adversarial sound (external speaker) remains constant and is unaffected by the drone's internal rotor modulation.
Algorithm: By sampling the microphone signal under different phase modulation states (e.g., j timesteps delay) and subtracting the baseline (j=0), the system can mathematically isolate and subtract the constant adversarial perturbation (σp), recovering the clean drone signal (sdrone).
Assumption: The attack assumes the perturbation is stationary relative to the drone's modulation cycle.
3. Key Contributions
First Comprehensive Study: The first formulation and analysis of adversarial attacks specifically targeting acoustic drone localization.
Differentiable Attack Pipeline: A fully differentiable attack framework using NAFs to optimize universal adversarial perturbations from an external source.
Source Location Analysis: An analysis showing that optimizing the attacker's physical location provides negligible improvement over a fixed central location, suggesting attacks can be efficient without complex spatial optimization.
Novel Defense Algorithm: A "Phase Modulation Perturbation Delineation" method that separates clean signals from adversarial noise using the drone's own rotor modulation, requiring only a single scalar degree of freedom (uncertainty at t=0) to reconstruct the clean signal.
Real-World Validation: Extension of prior simulation-based work to real-world acoustic data and environments (Matterport3D and Replica datasets).
4. Results
Attack Effectiveness:
The adversarial attack successfully increased the Mean Root Mean Square (RMS) localization error from ~5% (clean) to 37.4% under high amplitude/power bounds.
The attack is universal, degrading performance uniformly across the entire environment rather than exploiting specific "weak spots."
Targeted Attacks: The authors demonstrated the ability to force the drone to localize itself at a specific, arbitrary coordinate chosen by the attacker with near-zero error relative to that target.
Source Location: Optimizing the attacker's location yielded negligible performance gains over a fixed central source, reducing computational costs for attackers.
Defense Effectiveness:
The Phase Modulation defense successfully recovered the clean signal, reducing the localization error from 37% (attacked) back down to ~6%, which is nearly indistinguishable from the clean baseline (4.87%).
The defense works effectively even in the presence of white noise.
Noise Robustness:
Experiments showed that the presence of white noise (up to 50% of the signal's standard deviation) did not significantly diminish the attack's success rate, nor did it prevent the defense from functioning.
5. Significance and Future Work
Security Implications: This work highlights that acoustic localization, often touted as a robust alternative to vision/GPS, is highly vulnerable to physical-world adversarial attacks.
Defense Viability: The proposed defense offers a practical, active countermeasure that does not require external hardware, leveraging the drone's existing propulsion system.
Limitations & Future Directions:
Dimensionality: Current work is limited to 2D localization; 6-DoF (position + orientation) is a necessary next step.
Complexity: The defense requires processing an entire drone cycle to recover a single waveform, introducing latency.
Dynamic Attacks: Future work should explore active, real-time adaptive attacks where the attacker reacts to the drone's phase modulation, though the authors note causality constraints (sound propagation delay) may limit this.
In conclusion, the paper establishes a foundational framework for understanding and securing acoustic perception in autonomous systems, demonstrating both severe vulnerabilities and effective, physics-based defenses.