Source-linked AI summary
Dirty Road Can Attack: Security of Deep Learning based Automated Lane Centering under Physical-World Attack
Takami Sato, Junjie Shen, Ningfei Wang, Yunhan Jack Jia, Xue Lin, Qi Alfred Chen
TL;DR
The paper asks whether production DNN-based ALC systems are vulnerable to physical-world attacks in their intended lane-lined operating domain. It introduces an optimization-based dirty-road-patch attack that addresses ALC-specific temporal and lane-detection challenges, achieving high attack success and collision rates while remaining robust and stealthy. The study also evaluates defenses and identifies important evaluation boundaries.
Problem
The paper studies the security of DNN-based ALC systems against physical-world attacks in their designed operational domain, where failures can create driving and collision hazards.
Method
The DRP method uses dirty road patches and optimization-based generation to handle attack-influenced frame interdependencies and lane-detection objectives.
Results
Over 97.5% success rates and less than 0.903 sec average success time were achieved across 80 real-world-trace scenarios on a production ALC.
Takeaways & Limitations
The attack was robust to tested real-world factors, general across lane-detection model designs, stealthy from the driver’s view, and associated with 100% collision rates in evaluated scenarios.
Takeaways & Limitations
The evaluation covers one open-source production ALC and does not include direct end-to-end physical-world attacks with real vehicles.
Abstract
from arXiv · showhide
Automated Lane Centering (ALC) systems are convenient and widely deployed today, but also highly security and safety critical. In this work, we are the first to systematically study the security of state-of-the-art deep learning based ALC systems in their designed operational domains under physical-world adversarial attacks. We formulate the problem with a safety-critical attack goal, and a novel and domain-specific attack vector: dirty road patches. To systematically generate the attack, we adopt an optimization-based approach and overcome domain-specific design challenges such as camera frame inter-dependencies due to attack-influenced vehicle control, and the lack of objective function design for lane detection models. We evaluate our attack on a production ALC using 80 scenarios from real-world driving traces. The results show that our attack is highly effective with over 97.5% success rates and less than 0.903 sec average success time, which is substantially lower than the average driver reaction time. This attack is also found (1) robust to various real-world factors such as lighting conditions and view angles, (2) general to different model designs, and (3) stealthy from the driver's view. To understand the safety impacts, we conduct experiments using software-in-the-loop simulation and attack trace injection in a real vehicle. The results show that our attack can cause a 100% collision rate in different scenarios, including when tested with common safety features such as automatic emergency braking. We also evaluate and discuss defenses.
1 Introduction
This work studies physical-world attacks against DNN-based Automated Lane Centering in roads with lane lines, targeting deviations that exceed a fully attentive driver’s reaction time. It introduces dirty road patches and evaluates their effectiveness, robustness, generality, stealthiness, and safety impact.
- Motivation: ALC automatically steers vehicles to remain centered in traffic lanes but is safety critical because wrong steering can cause insufficient driver reaction time.Potential hazards include driving off road and collisions with vehicles in adjacent lanes.
- Research gap: Existing physical-world DNN attacks do not directly address ALC’s lane-lined operational domain or its attack-generation challenges.The prior production-ALC effort used white stickers to create fake lane lines on roads without lane lines and did not systematically address these challenges.
- Attack design: The DRP attack uses dirty road patches as a domain-specific physical attack vector that can resemble legitimate road repairs or ordinary dirt and stains.These properties support physical-world realizability and stealthiness from the driver’s view.
- Attack design: The optimization-based generation handles attack-influenced camera-frame updates and lane-detection objectives, with additional designs for robustness, stealthiness, and physical-world realizability.The approach uses vehicle motion and perspective transformation to synthesize frame updates according to attack-influenced control.
- Evaluation: Over 97.5% success rates and less than 0.903 sec average success time were achieved across 80 real-world-trace scenarios on a production ALC.The average success time was substantially lower than the 2.5 sec average driver reaction time; the attack was robust to lighting and viewing conditions, general across lane-detection designs, and stealthy from the driver’s view.
- Safety impact: 100% collision rates were observed in simulation and real-vehicle experiments, including trials with Automatic Emergency Braking enabled.Simulation attacks caused impacts with highway barriers or opposing trucks, while real-vehicle attack trace injection caused collisions with dummy road obstacles in all 10 trials.
2 Background
A typical DNN-based ALC pipeline detects lane lines from front-camera frames, computes a centered driving path and steering decisions, then actuates constrained steering changes. DNN vulnerability research motivates studying ALC-specific physical attacks because prior work largely targets classification and object detection.
- System pipeline: A typical ALC system operates through lane detection, lateral control, and vehicle actuation.The three stages connect camera-based lane perception to steering commands constrained by vehicle mechanics.
- Lane Detection: Lane detection uses front-camera frames and DNN models to predict lane-line points, which are post-processed into lane-line curves.Recurrent DNN structures are commonly used because lane-line shapes change little across consecutive frames.
- Lane Detection: Region-of-Interest filtering crops the central road surface containing lane lines before lane detection.The cropped area is smaller than the original frame to improve model performance and accuracy.
- Lateral control: Lateral control computes a desired path near the center of detected lane lines and applies PID or MPC control to determine steering angles.The controller seeks to follow the desired path as closely as possible.
- Vehicle actuation: Vehicle actuation converts steering decisions into steering-angle changes limited by mechanical constraints, stability, and safety requirements.One production ALC example limits changes to 0.25° per 10 ms control step.
- Security context: Prior physical-world adversarial-attack research mainly addresses image classification and object detection rather than production DNN-based ALC systems.The paper frames ALC as requiring new, domain-specific design solutions.
3 Attack Formulation and Challenge
The paper defines success as rapidly inducing sufficient lateral deviation to drive outside lane boundaries before a fully attentive driver can intervene. It specifies the threat model, operational setting, and three ALC-specific challenges that shape the attack design.
- 3.1 Attack Goal and Incentives: A successful attack must create lateral deviation large enough to leave lane boundaries within the average driver reaction time.Required deviations and success times are specified separately for highway and local-road scenarios.
- 3.1 Attack Goal and Incentives: The evaluation targets free-flow driving with at least 5–9 seconds of clear headway, allowing the vehicle to proceed without considering a front vehicle.This is identified as the most common ALC-use scenario in the study.
- 3.1 Attack Goal and Incentives: The attack can create hazards including driving off road and collisions with roadside, adjacent-lane, or opposing vehicles.The paper notes that obstacle avoidance and AEB may not reliably prevent crashes or secondary impacts.
- 3.2 Threat Model: The threat model assumes the attacker can obtain and reverse-engineer the victim’s ALC system and collect target-road inputs during preparation.The attacker is assumed to have full knowledge of implementation details and to collect inputs by driving the target road with the system engaged.
- 3.3 Design Challenges: C1 is the lack of a physical attack vector that appears legitimate around traffic lanes without changing human-perceived lane information.The paper contrasts this requirement with small stickers or graffiti used in prior attacks.
- 3.3 Design Challenges: C2 is sequential camera-frame interdependence caused by attack-influenced vehicle actuation and steering-angle limits.The attack must remain effective across successive frames because earlier deviations affect later frame inputs and vehicle control.
- 3.3 Design Challenges: C3 is the lack of a differentiable lane-detection objective that directly changes lane-line curves rather than classification probabilities or final steering angles.Lane detection outputs curves, while lateral control computes steering decisions downstream.
4 Dirty Road Patch Attack Design
The DRP attack uses stealthy dirty road patches and an optimization-based pipeline that synthesizes attack-consistent camera inputs while accounting for vehicle motion and lane-control behavior.
- 4.1 Design Overview: DRP introduces dirty road patches as a domain-specific physical-world attack vector for ALC systems.The patches can resemble legitimate road repairs or ordinary dirt and stains, supporting physical deployment and stealth.
- 4.1 Design Overview: The attack restricts perturbations to grayscale patterns and preserves covered lane lines to avoid visibly changing lane information.
- 4.2 Motion Model based Input Generation: The method synthesizes attack-influenced camera frames by combining a vehicle motion model with perspective transformations from one unattacked input trace.This avoids repeated real-world driving and heavyweight simulator execution during optimization.
- 4.2 Motion Model based Input Generation: The pipeline places the optimized patch in BEV space, simulates attack-influenced vehicle states, projects the result back to the camera view, and feeds ROI inputs to ALC.The vehicle state is updated from prior attacked-frame steering decisions using a motion model.
- 4.3 Optimization-Based DRP Generation: DRP generation optimizes a patch image whose loss aims to drive the victim outside lane boundaries as quickly as possible.The patch combines an asphalt-like base color with a constrained perturbation and blur operation.
- 4.3.2 Lane-Bending Objective Function Design: The lane-bending objective uses a differentiable surrogate that changes desired-path derivatives, making steering deviations optimizable through lane-detection outputs.Maximizing the curve derivative at each point produces the intended lane-bending effect.
5 Attack Methodology Evaluation
The evaluation tests DRP on production OpenPilot across real driving scenarios, stealthiness levels, baselines, model designs, lighting and viewing angles. The attack remains effective, stealthy, deployable, and robust across these conditions.
- Evaluation setup: OpenPilot was evaluated using 40 ten-second clips from the comma2k19 real-world driving dataset and the production lane-detection model in version 0.7.0.The dataset contains over 33 hours of Toyota RAV4 driving traces between San Jose and San Francisco.
- Attack effectiveness: At least 97.5% attack success and under 0.91 seconds average success time were achieved across all three stealthiness levels.The average success time was substantially below the 2.5-second driver reaction-time benchmark.
- Stealthiness: At λ = 10^-2 and 10^-3, fewer than 15% of participants chose to take over 2.5 seconds before attack success, while the default configuration preserved effectiveness.The study involved 100 participants; even at λ = 10^-4, fewer than 25% took over before the attack began affecting driving.
- Baseline comparison: DRP outperformed single-frame EoT and drawing-lane-line baselines by at least 46% in attack success rate.With a 12-meter patch, the two baselines achieved 0% and 2.5%, while DRP achieved 66%.
- Generality: Across three substantially different lane-detection architectures, DRP achieved at least 90% success and 63% average transferability.The models were older OpenPilot versions because OpenPilot was the only production ALC system available as open source.
- Robustness: The attack maintained a leftward steering effect across 12 lighting conditions and 45 viewing angles.It produced 20–24° left steering across lighting conditions and over 23.4° left steering from every tested viewing angle.
6 Software-in-the-Loop Simulation
Software-in-the-loop experiments evaluated DRP against barrier and truck collision scenarios from varied starting positions. The attack achieved collisions from every tested starting position.
- Evaluation scenarios: The software-in-the-loop evaluation used LGSVL with two scenarios: a highway concrete barrier and a local-road truck.The attack goals were to hit the barrier or truck, respectively.
- Evaluation setup: The evaluation tested each scenario from 18 starting positions formed by two longitudinal distances and nine lateral offsets.The same patch was evaluated repeatedly from these varied approaching positions.
- Results: DRP achieved a 100% success rate from all 18 starting positions in both highway and local-road scenarios.The vehicle first corrected toward lane center, then deviated left and hit the barrier or truck after encountering the patch.
- Results: The simulation scenarios and driver views were examined shortly before attack success to visualize the resulting vehicle trajectories and collision outcomes.Figure 13 reports averaged trajectories, while Figure 12 presents the scenarios and driver views 2.5 seconds before success.
7 Safety Impact on Real Vehicle
Real-vehicle experiments tested injected attack traces on a Toyota Camry with OpenPilot and built-in safety features. The attack caused collisions in every attack trial, while un attacked trials remained collision-free.
- Experimental setup: The real-vehicle setup combined OpenPilot ALC, LDW, and ACC with the Camry’s stock AEB and FCW features.Experiments used cardboard boxes outside the lane as safe proxies for barriers and opposing-lane obstacles.
- Experimental setup: The vehicle was tested at approximately 28 mph in ten attacked and ten unattacked trials.The injected attack trace came from the software-in-the-loop simulation at the same driving speed.
- Safety impact: The attack caused collisions in all ten trials even with Automatic Emergency Braking enabled.Figure 14 reports this result for the Toyota 2019 Camry with OpenPilot engaged.
- Results: 100% of attack trials ended in collisions, including five front and five side collisions, whereas unattacked trials had no contact with the objects.The collision variation was attributed to dynamic-control randomness and timing differences in system engagement and attack launch.
- Safety-feature analysis: FCW triggered in 5 of 10 collisions but only 0.46 seconds before impact on average, while AEB did not trigger in any attack trial.The authors report that LDW and ACC also failed to prevent the observed safety damage.
8 Limitations and Defense Discussion
The paper examines practical limitations of the attack and finds that directly applicable input-transformation defenses reduce benign performance alongside attack success. It discusses sensor/data-fusion defenses, including HD maps, but notes deployment and scalability constraints.
- Limitations: 93.8% success is achieved with 8 small road-patch pieces, each requiring 5–10 seconds for 2 people to deploy.The authors identify lower deployment effort as a remaining concern and leave other common road-surface patterns for future work.
- Limitations: Evaluation covers one production ALC, OpenPilot, so vulnerability of Tesla Autopilot and GM Cruise remains unclear.The authors cannot evaluate transfer attacks because those systems are not open sourced.
- Limitations: Direct end-to-end physical-world attacks with real vehicles were not evaluated because of safety and private-facility access constraints.The study instead uses simulation and attack-trace injection in a real vehicle.
- Machine Learning Model Level Defenses: When benign-case success remains 100%, the five input-transformation defenses retain 99–100% attack success rates.Increasing defense strength lowers both attack success and benign-case success, revealing a utility trade-off.
- Defense Discussion: Directly applicable defenses cannot easily defeat the attack, motivating lane-detection-specific defenses or adaptations of adversarial training.The paper also discusses LiDAR and HD-map fusion, while noting that accurate HD maps are costly and difficult to scale for Level-2 systems.
9 Related Work
Related work covers physical-world attacks against multiple perception and autonomy components, but prior efforts largely focus on image classification and object detection. The paper positions its contribution as systematic physical-world attack design for lane detection in ALC.
- Autonomous Driving System Security: Prior autonomous-driving security work studies spoofing or jamming across cameras, LiDAR, RADAR, ultrasonic sensors, and IMUs.Other work targets object detection, tracking, localization, traffic-light detection, and end-to-end driving models.
- Physical-World Adversarial Attacks: Physical-world adversarial attacks have mainly targeted image classification and object detection rather than lane-detection models.Existing techniques improve physical-world robustness using non-printability scores, low-saturation colors, and expectation over transformation.
10 Conclusion
The paper concludes that dirty-road-patch attacks can systematically and stealthily compromise production ALC under realistic evaluation conditions. It also identifies deployment, model coverage, physical-world evaluation, and defense design as open boundaries.
- Conclusion: The attack achieves over 95% success rates with success time substantially below average driver reaction time and causes 100% collision rates in evaluated scenarios.The safety evaluation uses simulation and attack-trace injection in a real vehicle.
- Required Deviations and Success Time: Required lane-line deviations are 0.735m on highways and 0.285m on local roads, computed as L−C/2 from lane and vehicle widths.The calculation uses Toyota RAV4 width and standard U.S. lane widths.
- Required Deviations and Success Time: The attack goal requires success within the average driver reaction time, estimated as 2.5–2.75 seconds from hazard perception to physical action.The paper uses 2.5 seconds as its required success time and notes that this estimate concerns braking reactions applied to steering takeover.
- Required Deviations and Success Time: The reported 2.5-second reaction-time threshold is conservative because drivers may react more slowly when ALC controls steering.A cited simulation study found 40% of drivers failed to react in time to avoid a crash occurring 6.2 seconds after Autopilot failure.
- Attack Generation: The optimization pipeline makes lane-line curve fitting differentiable so gradients can propagate from the driving-path objective to lane-line points.It fits left and right lane points with least-squares polynomial curves and derives a differentiable driving-path polynomial.
- Attack Generation: BEV-space gradients are averaged using visible patch-area weights so early frames do not dominate when the patch is distant and small.The weights are normalized over frames, but the procedure is an approximation rather than the true gradient through BEV inversion.
- Attack Generation: Robustness optimization adds normally distributed noise to predicted lateral position and heading angle and applies Gaussian blur to patches and gradients.These changes address trajectory, angle, and camera-sensing differences between attack generation and evaluation.
- Attack Deployability: The optional multi-piece mode partitions the placement area into grid cells and selects cells with the largest perturbation amounts.This mode is intended to make large patches easier and faster to deploy.
D Detailed Discussion of Attack Effectiveness and Stealthiness Evaluation
The detailed evaluation shows that the attack remains highly effective across tested stealthiness levels while using small visual perturbations. Its success time is far below the reaction-time threshold, and its driver-view appearance can resemble ordinary road dirt.
- Effectiveness: 100% success rates occur at λ = 10^-4 and 10^-3, while success remains above 97.5% at λ = 10^-2.Across successful cases, average success time stays below 0.91 seconds, compared with the 2.5-second required threshold.
- Stealthiness: L1 and L2 perturbation distances are at most 0.071 and 0.109, respectively.The paper interprets the maximum L2 distance as patches averaging only 10.9% brighter than the original surface at the lowest stealthiness level.
E Attack Stealthiness User Study
The user study evaluates whether drivers recognize DRP attacks from the driver’s view. Most participants did not take over before the attack began affecting control, especially for stealthier patches.
- Study design: 100 participants with driving experience viewed attacked and benign frames at 3, 2.5, 2, 1.5, and 1 seconds before attack success.Participants were screened to avoid taking over in benign cases and were not told the study concerned security attacks.
- Results: As attack success approached, take-over rates increased because the dirty patterns became larger and clearer.The lowest stealthiness level, λ = 10−4, produced the highest take-over rate, while λ = 10−2 produced the lowest.
- Results: Less than 25% of participants took over before the attack started affecting control, even for λ = 10−4.At this level, the white dirty patterns were dense and prominent.
- Results: Less than 20% took over at 2.5 or 3 seconds before success for λ = 10−4, while λ = 10−2 and λ = 10−3 appeared as innocent as clean road patches.At those earlier time points, take-over rates for λ = 10−2 and λ = 10−3 were similar to benign patches and below 15%.
- Limitations: The authors note that practical take-over rates may be lower because highway patches are farther away and digitally synthesized patches may appear less natural.These factors could make patches less noticeable or more likely to alert participants, respectively.
- Results: At roughly 7 meters, fewer than 25% of participants took over, also informing stealthiness from a pedestrian-like distance.The study’s 1-second driver-view frame was considered similar to a local-road pedestrian distance.
F Robustness to Run-Time Driving Trajectory and Angle Deviations
The robustness evaluation perturbs the vehicle trajectory and viewing angle at run time, including deviations far beyond typical motion-model error. DRP remains effective across these perturbations and starting positions, though lateral displacement from lane center reduces success.
- Evaluation setup: The evaluation models run-time trajectory deviations by shifting vehicle position at each control step and varying initial longitudinal and lateral positions.The setup uses the kinematic bicycle model and evaluates multiple perturbation magnitudes and 27 starting positions.
- Evaluation setup: The robustness experiments reused patches with λ = 10−3 and PAR = 50%, the default stealthiness configuration.The evaluation dataset and metrics matched those used in §5.1.
- Trajectory and angle robustness: At ∆ = 0.096, corresponding to 16× standard deviation, patches still achieved at least 95% success rates and at most 0.869 sec success time.This perturbation produced average trajectory changes up to 1 m and viewing-angle changes from 2.0° to 5.8° per control step.
- Starting-position robustness: Success rates decreased monotonically with larger lateral offsets from lane center, while longitudinal shifting had almost no effect.The tested lateral offset range was below 0.735 m, compared with a 1 m longitudinal offset range.
G Attack Generality Evaluation
The authors test DRP against three OpenPilot lane-detection models with substantially different DNN designs. The attack generalizes across models, although one batch-normalized model is more robust and cross-model transfer is weaker.
- Experimental setup: The study uses OpenPilot v0.7.0, v0.6.6, and v0.5.9 models with large architectural differences.The models differ in parameter counts, layer counts, and batch-normalization design.
- Generality results: At least 90% success rates were achieved against all three lane-detection models, indicating high generality across DNN designs.The evaluation uses the same dataset and metrics as §5.1.
- Generality results: The v0.6.6 model had 5–15% lower success rates and higher success times than the other models.It also had the smallest L1 and L2 pixel distances; the authors suspect its batch-normalization layers may contribute to increased robustness.
- Transferability: Transfer success averaged 63% when patches generated for one model were applied to the other two models.The authors compare this rate with reported state-of-the-art transfer rates for MNIST and CIFAR10.
H Attack Deployability Evaluation
The deployability evaluation estimates the effort required to place multi-piece road patches. Reducing the number of pieces lowers success, but eight pieces still retain high effectiveness while nearly halving deployment effort.
- Deployment setup: A deployment unit is a 1.6–1.8 m-wide and 6–8 m-long patch placed by two people, requiring only 5–10 seconds for placement.Unlike legitimate road work, the attacker need not fill asphalt or stamp the road.
- Deployment setup: Fifteen 1.8 m × 7.2 m pieces are required to cover the full 5.4 m × 36 m placement area for two people.The evaluation varies the allowed number of pieces from 4 to 15.
- Deployability results: 93.8% success was retained with eight pieces, reducing the original deployment effort by nearly 50%.Success rates decreased as fewer pieces reduced the perturbable area.
I Robustness To Different Lighting Conditions in Physical World
The DRP attack was evaluated under 12 controlled lighting conditions spanning substantially different light intensities. Its physically printed patch maintained a strong leftward steering effect across this range, with camera auto-exposure likely contributing to robustness.
- Experimental setup: 12 lighting conditions combined studio, room, and window-light settings to model varied physical-world illumination.The setup varied studio-light intensity, room-light state, and window-blind position.
- Attack effectiveness: 15-1210 lux: the patch maintained a desired steering angle of 20-24° to the left across the tested illumination range.This range corresponded to conditions from sunset or sunrise on a fully overcast day to midday on an overcast day.
- Attack effectiveness: Except for the two darkest conditions, camera images appeared relatively similar despite substantial lighting variation.The results are shown in the lighting-condition visualization and corresponding table.
- Attack effectiveness: OpenPilot’s automatic exposure adjustment likely helps the attack remain robust by keeping DNN inputs at relatively similar brightness.The paper notes that auto-exposure is commonly enabled for vision-model performance, while also benefiting this attack.