Adversarial Trust Poisoning in Vehicular Collaborative Perception
This paper introduces TrustFlip, a novel attack that weaponizes consistency-based defenses in vehicular collaborative perception by deploying physical adversarial objects to induce observation inconsistencies, thereby falsely penalizing benign vehicles' trust scores and degrading system performance, alongside proposing the TrustReflect mechanism to mitigate this vulnerability.
Original paper licensed under CC BY 4.0 (http://creativecommons.org/licenses/by/4.0/). This is an AI-generated explanation of the paper below. It is not written or endorsed by the authors. For technical accuracy, refer to the original paper. Read full disclaimer
Imagine a group of self-driving cars driving down a highway. To see around corners and through blind spots, they don't just rely on their own eyes (sensors); they talk to each other. They share what they see, creating a giant, shared "group mind" to understand the road better. This is called Collaborative Perception.
However, there's a problem: What if a bad actor tricks the group?
The Old Problem: The Liar in the Group
Previously, researchers worried about a "liar" car. Imagine one car in the group starts shouting, "There's a giant monster truck ahead!" when there isn't one. Or, "There's nothing here!" when there actually is a pedestrian.
To stop this, the other cars have a simple rule: "If one person says something different from the rest of the group, they must be lying." They check for consistency. If 9 cars see a tree and 1 car says "no tree," the system ignores the 1 car and trusts the 9. This is the standard defense.
The New Attack: "TrustFlip" (The Silent Saboteur)
The authors of this paper discovered a clever way to break this rule without ever sending a fake message. They call their attack TrustFlip.
Instead of a "liar" car, the attacker uses a physical object—like a strange, specially designed sign or a weirdly shaped trailer—that they tow behind their own vehicle.
Here is the trick:
- The Setup: The attacker places this object so that Car A (the victim) sees it from a specific angle where it looks invisible or confusing.
- The Trap: Meanwhile, Cars B, C, and D (the rest of the group) see the object clearly from their different angles.
- The Confusion: Car A looks at the road and says, "I see nothing." Cars B, C, and D say, "I see a big object!"
- The Mistake: The group's defense system applies its rule: "If you disagree with the majority, you are the liar."
- The Result: The system doesn't blame the weird object. It blames Car A. It thinks, "Car A is broken or malicious," and kicks Car A out of the conversation.
The Analogy: Imagine a classroom where the teacher trusts the majority vote. A student (the attacker) holds up a special card that looks like a blank piece of paper to the student in the front row (the victim) but looks like a picture of a cat to everyone else. The front-row student says, "I see nothing." The teacher says, "You're wrong, everyone else sees a cat," and punishes the front-row student for being "untrustworthy," even though the student is telling the truth about what they see.
Why This is Dangerous
Once the system kicks out the "victim" car, the group loses that car's unique view. If the victim was the only one who could see a pedestrian hiding behind a truck, the group now misses that pedestrian. The attack doesn't need to hack the car's computer or jam the radio; it just needs a piece of plastic and the right angle.
The Solution: "TrustReflect" (The Self-Check)
The authors also proposed a fix called TrustReflect.
Think of this as a "self-reflection" step. Before the group decides who to trust, every car runs a quick test on itself. It asks: "If I were the one looking at this weird object, would I also see a disagreement?"
If the victim car realizes, "Wait, I see something different than my friends, but it's because of this weird object right in front of me," it can say, "I'm not sure about this specific spot. Please don't count my opinion on this area when you decide who to trust."
This stops the system from blindly punishing the victim. It's like the student raising their hand and saying, "I see a blank paper because of this card, not because I'm lying. Let's ignore my answer for this specific question."
Summary of Results
- The Attack: The researchers built these special objects and tested them in simulations and with real LiDAR sensors. They found that in up to 88% of cases, they could successfully trick the system into kicking out a good car.
- The Impact: When a good car is kicked out, the group's ability to see the road drops significantly (by up to 13% in accuracy).
- The Fix: When they added the "TrustReflect" self-check, the attack stopped working in 35% to 100% of cases, depending on the setup.
In short, the paper shows that the very rules designed to keep self-driving cars safe (trusting the majority) can be turned against them by a clever physical trick, but a simple "self-check" can help fix the problem.
Drowning in papers in your field?
Get daily digests of the most novel papers matching your research keywords — with technical summaries, in your language.