TY - GEN
T1 - Defending Autonomous Driving Perception against Adversarial Object-Based Attacks via Motion Planning
AU - Liu, Zihao
AU - Zhang, Yan
AU - Zhu, Yi
AU - Su, Lu
AU - Qiao, Chunming
AU - Miao, Chenglin
N1 - Publisher Copyright:
© 2026 Copyright held by the owner/author(s).
PY - 2026/5/10
Y1 - 2026/5/10
N2 - Autonomous vehicles (AVs) rely on perception systems to detect surrounding objects using sensors such as cameras, LiDAR (Light Detection and Ranging), and millimeter-wave (mmWave) radar. However, recent studies have shown that attackers can deceive these systems by strategically placing adversarial objects (e.g., color patches, cardboard, or metal foil) in the driving environment. These attacks pose serious safety risks, yet existing defenses primarily focus on individual sensor modalities and lack generalizability across different sensing systems. To address this gap, we propose the first generalized defense mechanism capable of mitigating various attacks using adversarial objects. Our approach integrates real-time attack detection with trajectory adaptation, guiding the victim AV to positions where the attack is less effective. The defense mechanism combines a deep reinforcement learning (DRL)-based motion planning model, which dynamically adjusts the AV's trajectory, with an uncertainty-aware filtering scheme that refines perception outputs to enhance detection robustness. Extensive experiments in both simulated and real-world environments demonstrate that our defense mechanism effectively mitigates adversarial object-based attacks across different sensing modalities and sensor fusion while maintaining safe and smooth driving behavior.
AB - Autonomous vehicles (AVs) rely on perception systems to detect surrounding objects using sensors such as cameras, LiDAR (Light Detection and Ranging), and millimeter-wave (mmWave) radar. However, recent studies have shown that attackers can deceive these systems by strategically placing adversarial objects (e.g., color patches, cardboard, or metal foil) in the driving environment. These attacks pose serious safety risks, yet existing defenses primarily focus on individual sensor modalities and lack generalizability across different sensing systems. To address this gap, we propose the first generalized defense mechanism capable of mitigating various attacks using adversarial objects. Our approach integrates real-time attack detection with trajectory adaptation, guiding the victim AV to positions where the attack is less effective. The defense mechanism combines a deep reinforcement learning (DRL)-based motion planning model, which dynamically adjusts the AV's trajectory, with an uncertainty-aware filtering scheme that refines perception outputs to enhance detection robustness. Extensive experiments in both simulated and real-world environments demonstrate that our defense mechanism effectively mitigates adversarial object-based attacks across different sensing modalities and sensor fusion while maintaining safe and smooth driving behavior.
KW - Adversarial attacks
KW - Autonomous driving perception
KW - Defense
KW - Motion planning
UR - https://www.scopus.com/pages/publications/105040952634
U2 - 10.1145/3774906.3800480
DO - 10.1145/3774906.3800480
M3 - Conference contribution
AN - SCOPUS:105040952634
T3 - SenSys 2026 - Proceedings of the 2026 ACM/IEEE International Conference on Embedded Artificial Intelligence and Sensing Systems, Part of CPS-IoTWeek 2026
SP - 833
EP - 846
BT - SenSys 2026 - Proceedings of the 2026 ACM/IEEE International Conference on Embedded Artificial Intelligence and Sensing Systems, Part of CPS-IoTWeek 2026
PB - Association for Computing Machinery, Inc
T2 - International Conference on Embedded Artificial Intelligence and Sensing Systems, SenSys 2026
Y2 - 11 May 2026 through 14 May 2026
ER -