DTP-Attack: A decision-based black-box adversarial attack on trajectory prediction
This paper introduces DTP-Attack, a practical decision-based black-box adversarial framework that effectively compromises autonomous vehicle trajectory prediction systems by manipulating intentions and degrading accuracy without requiring model internals or rigid physical constraints.
Original paper licensed under CC BY 4.0 (http://creativecommons.org/licenses/by/4.0/). This is an AI-generated explanation of the paper below. It is not written or endorsed by the authors. For technical accuracy, refer to the original paper. Read full disclaimer
Imagine you are driving a self-driving car. This car is incredibly smart; it has "eyes" (cameras and sensors) and a "brain" (a computer program) that constantly guesses what other cars, pedestrians, and cyclists will do next. If the car thinks a pedestrian is going to walk straight, it keeps driving. If it thinks they might jump out, it slams on the brakes. This guessing game is called Trajectory Prediction.
Now, imagine a hacker doesn't need to break into the car's computer to mess with it. Instead, they just need to drive a car in front of it in a very specific, slightly weird way.
This paper introduces a new hacking method called DTP-Attack. Here is how it works, explained simply:
1. The Problem: The "Black Box" Mystery
Most previous ways to hack these cars were like trying to solve a math problem where you could see the teacher's answer key (the "White Box" attack). But in the real world, hackers can't see the car's code. They only see the car's behavior. This is a "Black Box" scenario.
Also, previous hackers tried to force the car's prediction to go wrong by using rigid rules (like "don't move faster than 60 mph"). But real life is messy. If you follow rigid rules too strictly, the car's computer realizes, "Hey, this movement isn't physically possible," and ignores the attack.
2. The Solution: The "Boundary Walker"
The authors created a new strategy called DTP-Attack. Think of it like this:
Imagine you are in a dark room trying to find the edge of a table without touching it. You can't see the table, but you have a friend who tells you "Yes" if you are on the table and "No" if you are on the floor.
- Old Method (Score-Based): The hacker tries to guess the exact shape of the table by calculating angles and forces. If they guess wrong, they get stuck in a corner (a "local optimum") and can't find the edge.
- DTP-Attack (Decision-Based): The hacker just takes small steps.
- They step sideways (Orthogonal step). If the friend says "Yes, still on the table," they keep going.
- They step forward toward the original spot (Forward step). If the friend says "No, you fell off," they step back a tiny bit.
- They repeat this "dance" until they are standing right on the edge of the table, but as close to the center as possible.
This "Boundary Walking" allows the hacker to find the perfect, tiny movement that tricks the car without needing to know how the car's brain works or breaking any physics laws.
3. The Two Tricks (Attack Goals)
The paper shows this method can do two specific things:
Trick #1: The "Magic Turn" (Intention Misclassification)
Imagine a car driving straight down the highway. The hacker drives a car next to it, making tiny, almost invisible wiggles. Suddenly, the self-driving car's brain thinks, "Oh no! That car is about to swerve left and hit me!" The self-driving car might slam on its brakes or swerve dangerously, even though the other car was just driving straight.- Result: The paper shows they can make the car think a vehicle is turning or changing lanes with a deviation of less than half a meter (about 1.5 feet).
Trick #2: The "Blurry Vision" (Accuracy Degradation)
Imagine the hacker makes the other car move in a way that confuses the prediction system completely. The self-driving car can no longer guess where the other car will be in 5 seconds.- Result: The prediction errors get 2 to 4 times worse. The car might think a vehicle is 10 meters away when it's actually 2 meters away, leading to a potential crash.
4. Why This is Scary (and Important)
The scary part is how small the changes are. The hackers only moved the "attacker car" by about 0.45 meters (less than the length of a shoe). To a human driver, the car looks like it's driving normally. But to the self-driving car's AI, it looks like a completely different situation.
The paper tested this on real-world data (like the nuScenes and Apolloscape datasets) and on top-of-the-line AI models. It worked 41% to 81% of the time, which is a huge success rate for a black-box attack.
The Takeaway
This paper is a wake-up call. It shows that self-driving cars are currently very fragile. A hacker doesn't need to be a genius coder or have access to the car's secrets. They just need to drive a car in a slightly "weird" way, and the self-driving car might panic and make a catastrophic mistake.
The authors are essentially saying: "We found a way to trick these cars easily. Now, we need to build better shields to protect them before they are on our roads."
Drowning in papers in your field?
Get daily digests of the most novel papers matching your research keywords — with technical summaries, in your language.