TY - JOUR
T1 - AdvGLOW
T2 - Covert Adversarial Attacks Against Autonomous Driving Perception
AU - Bai, Xuesong
AU - Dong, Peng
AU - Wang, Jinlei
AU - Huang, Yuanhao
AU - Yu, Haiyang
AU - Ren, Yilong
N1 - Publisher Copyright:
© 2018 Tsinghua University Press.
PY - 2025
Y1 - 2025
N2 - Autonomous driving technology is becoming increasingly popular, transforming transportation systems worldwide. However, its perception modules are highly vulnerable to adversarial attacks, which exploit weaknesses in deep neural networks, leading to potential safety risks and compromised decision-making in autonomous systems. In this study, we propose AdvGLOW, a novel adversarial attack model tailored for covert attacks on autonomous driving perception modules in traffic scenarios. Leveraging an information exchange network within a flow-based model, AdvGLOW introduces reversible data transformations to achieve high attack success with minimal perturbation visibility. By optimizing a combined global-local loss, our model preserves structural details while embedding adversarial features, resulting in robust yet visually imperceptible adversarial samples. We conduct extensive experiments on traffic-related datasets, demonstrating that the generated adversarial samples are challenging for both humans and algorithms to detect. Additionally, this method exhibits strong attack robustness and transferability.
AB - Autonomous driving technology is becoming increasingly popular, transforming transportation systems worldwide. However, its perception modules are highly vulnerable to adversarial attacks, which exploit weaknesses in deep neural networks, leading to potential safety risks and compromised decision-making in autonomous systems. In this study, we propose AdvGLOW, a novel adversarial attack model tailored for covert attacks on autonomous driving perception modules in traffic scenarios. Leveraging an information exchange network within a flow-based model, AdvGLOW introduces reversible data transformations to achieve high attack success with minimal perturbation visibility. By optimizing a combined global-local loss, our model preserves structural details while embedding adversarial features, resulting in robust yet visually imperceptible adversarial samples. We conduct extensive experiments on traffic-related datasets, demonstrating that the generated adversarial samples are challenging for both humans and algorithms to detect. Additionally, this method exhibits strong attack robustness and transferability.
KW - adversarial attack
KW - autonomous driving
KW - flow-based generation
KW - perception test
UR - https://www.scopus.com/pages/publications/105026663871
U2 - 10.26599/JICV.2025.9210067
DO - 10.26599/JICV.2025.9210067
M3 - 文章
AN - SCOPUS:105026663871
SN - 2399-9802
VL - 8
JO - Journal of Intelligent and Connected Vehicles
JF - Journal of Intelligent and Connected Vehicles
IS - 4
M1 - 9210067
ER -