Exploring Adversarial Robustness of LiDAR Semantic Segmentation in Autonomous Driving
Article
Article Title | Exploring Adversarial Robustness of LiDAR Semantic Segmentation in Autonomous Driving |
---|---|
ERA Journal ID | 34304 |
Article Category | Article |
Authors | Mahima, K. T. Yasas, Perera, Asanka, Anavatti, Sreenatha and Garratt, Matt |
Journal Title | Sensors |
Journal Citation | 23 (23) |
Article Number | 9579 |
Number of Pages | 22 |
Year | 2023 |
Publisher | MDPI AG |
Place of Publication | Switzerland |
ISSN | 1424-8220 |
1424-8239 | |
Digital Object Identifier (DOI) | https://doi.org/10.3390/s23239579 |
Web Address (URL) | https://www.mdpi.com/1424-8220/23/23/9579 |
Abstract | Deep learning networks have demonstrated outstanding performance in 2D and 3D vision tasks. However, recent research demonstrated that these networks result in failures when imperceptible perturbations are added to the input known as adversarial attacks. This phenomenon has recently received increased interest in the field of autonomous vehicles and has been extensively researched on 2D image-based perception tasks and 3D object detection. However, the adversarial robustness of 3D LiDAR semantic segmentation in autonomous vehicles is a relatively unexplored topic. This study expands the adversarial examples to LiDAR-based 3D semantic segmentation. We developed and analyzed three LiDAR point-based adversarial attack methods on different networks developed on the SemanticKITTI dataset. The findings illustrate that the Cylinder3D network has the highest adversarial susceptibility to the analyzed attacks. We investigated how the class-wise point distribution influences the adversarial robustness of each class in the SemanticKITTI dataset and discovered that ground-level points are extremely vulnerable to point perturbation attacks. Further, the transferability of each attack strategy was assessed, and we found that networks relying on point data representation demonstrate a notable level of resistance. Our findings will enable future research in developing more complex and specific adversarial attacks against LiDAR segmentation and countermeasures against adversarial attacks. |
Keywords | adversarial attacks; LiDAR; semantic segmentation; autonomous vehicles |
Contains Sensitive Content | Does not contain sensitive content |
ANZSRC Field of Research 2020 | 4007. Control engineering, mechatronics and robotics |
Byline Affiliations | University of New South Wales |
School of Engineering |
https://research.usq.edu.au/item/z7724/exploring-adversarial-robustness-of-lidar-semantic-segmentation-in-autonomous-driving
Download files
37
total views17
total downloads1
views this month0
downloads this month