Key Takeaways & Executive Findings
- •• The survey provides a systematic taxonomy that categorizes physical adversarial attacks and defenses into real-world, simulator-based, and digital-world scenarios, offering a structured understanding of the threat landscape. • It analyzes adversarial vulnerabilities across different sensor modalities—camera, LiDAR, and multifusion—highlighting the unique challenges each sensor type faces in autonomous driving systems. • Defense mechanisms are classified into input image preprocessing, adversarial example detection, and model enhancement, covering the full spectrum of countermeasures for DNN-based systems. • The paper identifies open challenges and future research directions for enhancing the robustness and safety of autonomous driving systems against physical adversarial threats.
Abstract
Autonomous driving systems (ADSs) have attracted wide attention in the machine learning communities. With the help of deep neural networks (DNNs), ADSs have shown both satisfactory performance under significant uncertainties in the environment and the ability to compensate for system failures without external intervention. However, the vulnerability of ADSs has raised concerns since DNNs have been proven vulnerable to adversarial attacks. In this paper, we present a comprehensive survey of current physical adversarial vulnerabilities in ADSs. We first divide the physical adversarial attack methods and defense methods by their restrictions of deployment into three scenarios: the real-world, simulator-based, and digital-world scenarios. Then, we consider the adversarial vulnerabilities that focus on various sensors in ADSs and separate them as camera-based, light detection and ranging (LiDAR) based, and multifusion-based attacks. Subsequently, we divide the attack tasks by traffic elements. For the physical defenses, we establish the taxonomy with reference to input image preprocessing, adversarial example detection, and model enhancement for the DNN models to achieve full coverage of the adversarial defenses. Based on the above survey, we finally discuss the challenges in this research field and provide further outlook on future directions.
1. Introduction
Autonomous driving (AD) systems (ADSs) constitute multiple perception-level tasks that have achieved high precision because of deep learning architectures (Kiran et al., 2022). With the help of artificial intelligence (AI) based self-driving architectures, ADSs can perceive various traffic assignments. To handle real-world scenes through visual complexity, ADSs deploy multiple sensors such as light detection and ranging (LiDAR), radar, and global positioning system (GPS) to assist camera sensors. Moreover, the growing interest in the development of ADSs has introduced new security challenges and vulnerabilities. Besides the usual cyber-attacks (Dibaei et al., 2020), such as denial-of-service (DoS) attack, black-hole attack, and malware attack, the vulnerability of deep neural networks (DNNs) in ADSs needs to be investigated.
DNN predictions can be manipulated by adversarial examples (Szegedy et al., 2014). In the early stage, most adversarial examples are designed in the digital world, which means that the adversarial perturbations are generated in a pixel-to-pixel manner. These digital adversarial samples cannot effectively attack ADSs. Research indicates that digital adversarial attacks perform poorly against ADSs due to two potential reasons: real-world properties and multisensor fusions (MSFs) (Boloor et al., 2019).
Things have changed since Eykholt et al. (2018b) proposed the physical adversarial attack for object detectors. They evaluated the difference between digital and physical adversarial attacks from four perspectives: environmental conditions, spatial restrictions, physical limits on imperceptibility, and fabrication error. The environmental conditions represent the camera in autonomous vehicles taking photos of adversarial examples from diverse angles, distances, and weather conditions. Attackers can manipulate only the “restrictive region” rather than background imagery. The physical limits on imperceptibility impose that physical adversarial perturbations should be stealthy instead of imperceptible so that the camera can perceive perturbations. The fabrication error means that all perturbation values must be valid colors that can be reproduced in the real world. Furthermore, even if a fabrication device such as a printer can produce specific colors, some reproduction errors will occur in the progress of digital-to-physical transformation (Fig. 1). Sensor fusion involves gathering inputs from multiple sensors to interpret environmental conditions with increased detection certainty. The integration of diverse sensor types in ADSs allows them to harness the collective advantages of the sensors, effectively compensating for their limitations. Therefore, the majority of today’s automotive manufacturers commonly use the following sensors in ADSs: visible camera, LiDAR, infrared camera, depth camera, GPS, r
Loading authentic research manuscript (Pages 1–5)...
Shuai ZHAO, Boyuan ZHANG, Yucheng SHI, Yang ZHAI, Yahong HAN, Qinghua HU (2025). A comprehensive survey of physical adversarial vulnerabilities in autonomous driving systems. Frontiers of Information Technology & Electronic Engineering. https://doi.org/10.1631/FITEE_2300867
Research & Educational Purpose Only:The translations, structured abstracts, analytical annotations, and data reports provided by SinoTechIntel are intended exclusively for academic research, internal corporate R&D, and educational benchmarking. They do not constitute formal engineering, chemical safety, legal, or professional advice.
Copyright & Intellectual Property Notice: Original copyright of the underlying source articles and experimental data remains with the respective authors, institutions, and original publishing journals. SinoTechIntel claims intellectual property only over its proprietary translations, analytical syntheses, and AEO structured enhancements in accordance with international fair use and academic citation principles.
Frequently Asked Questions
What scenarios are considered in the survey of physical adversarial attacks on autonomous driving?
The survey categorizes physical adversarial attacks and defenses into three scenarios: real-world, simulator-based, and digital-world, providing a comprehensive analysis of the threat landscape in each context.
How are adversarial vulnerabilities categorized by sensor type?
The paper separates adversarial vulnerabilities into camera-based, LiDAR-based, and multifusion-based attacks, addressing the unique challenges and attack surfaces associated with different sensor modalities in autonomous driving systems.
What are the main defense mechanisms discussed in the survey?
Physical defenses are classified into input image preprocessing, adversarial example detection, and model enhancement, covering a broad spectrum of countermeasures to protect DNN models against physical adversarial threats.
What is the significance of this survey for autonomous driving security?
The survey consolidates existing knowledge on physical adversarial threats and defenses, identifies open challenges, and outlines future research directions to enhance the robustness and safety of autonomous driving systems in real-world applications.
Related Technical Papers & Translations
Design and optimization of a high-efficiency distillation process for cellulosic fuel ethanol integrated with thermal coupling and molecular sieve adsorption
To address the challenges of high energy consumption and prominent costs in the traditional three-columns distillation process for cellulosic fuel ethanol, a distillation—molecular sieve coupling separation process is proposed. This process integrates a three-column (crude distillation column, first distillation column, second distillation column) system with a 3A molecular sieve adsorption deep dehydration unit. A thermal coupling network is constructed via differential pressure design (steam from medium/high-pressure columns as mutual heat sources, reboiler liquid waste heat for feed preheating), and molecular sieve adsorption conditions are optimized. The study first performs a thermodynamic consistency test on the ethanol—water system, determines optimal non-random two-liquid (NRTL) model binary interaction parameters via experimental data regression for Aspen Plus simulation. Aiming at minimum total annual cost (TAC), Aspen Plus is used to optimize process parameters (theoretical tray number, feed location, reflux ratio, side-draw position, etc.). Economic analysis shows this process reduces CO2 emission costs by 27.56%, TAC by 15.58% (to 5.123 × 106 USD·a-1), and increases ethanol purity to >99.6%, providing an effective solution for green, efficient separation.
A cohesion loss model for determining residual strength of deep bedded sandstone
Rock residual strength, as an important input parameter, plays an indispensable role in proposing the reasonable and scientific scheme about stope design, underground tunnel excavation and stability evaluation of deep chambers. Therefore, previous residual strength models of rocks established were reviewed. And corresponding related problems were stated. Subsequently, starting from the effects of bedding and whole life-cycle evolution process, series of triaxial mechanical tests of deep bedded s
Federated model with contrastive learning and adaptive control variates for human activity recognition
Recent attention to privacy issues demands a communication-safe method for training human activity recognition (HAR) models on client activity data. Federated learning (FL) has become a compelling technique to facilitate model training between the server and clients while preserving data privacy. However, classical FL methods often assume independent and identically distributed (IID) data among clients. This assumption does not hold true in practical scenarios. Human activity in real-world scena