News: 1624010470

  ARM Give a man a fire and he's warm for a day, but set fire to him and he's warm for the rest of his life (Terry Pratchett, Jingo)

Poltergeist attack could leave autonomous vehicles blind to obstacles – or haunt them with new ones

(2021/06/18)


Researchers at the Ubiquitous System Security Lab of Zhejiang University and the University of Michigan's Security and Privacy Research Group say they've found a way to blind autonomous vehicles to obstacles using simple audio signals.

"Autonomous vehicles increasingly exploit computer-vision based object detection systems to perceive environments and make critical driving decisions," they explained in the abstract to a newly released paper. "To increase the quality of images, image stabilisers with inertial sensors are added to alleviate image blurring caused by camera jitter.

"However, such a trend opens a new attack surface. This paper identifies a system-level vulnerability resulting from the combination of the emerging image stabiliser hardware susceptible to acoustic manipulation and the object detection algorithms subject to adversarial examples."

[1]

To try to prove their point, the team came up with Poltergeist: an attack against camera-based computer-vision systems, as found in autonomous vehicles, which uses audio to trigger the image stabilisation functions of the camera sensor and blur the image – tricking the machine learning system into ignoring obstacles in its way.

[2]

[3]

"The blur caused by unnecessary motion compensation can change the outline, the size, and even the colour of an existing object or an image region without any objects," the team found, "which may lead to hiding, altering an existing object, or creating a non-existing object." The team categorised these in turn as Hiding Attacks (HA), Creating Attacks (CA), and Altering Attacks (AA).

It's the first example of what the researchers have claimed as a new class of attack: AMpLe, a somewhat clunky shuffled backronym for "injecting physics into adversarial machine learning."

[4]Nvidia gobbles up mapping startup to help automakers install its self-driving platform

[5]Tesla Autopilot is a lot dumber than CEO Musk claims, says Cali DMV after speaking to the software's boss

[6]UK government gives Automated Lane Keeping Systems the green light for use on motorways

[7]Semi-autonomous cars sales move up a gear with 3.5 million units leaving forecourts

In simulation, Poltergeist showed a 100 per cent success rate for hiding, 87.9 percent for creating, and 95.1 percent for altering objects, when trialled against the YOLO V3/V4/V5 and Fast R-CNN object detection networks plus a commercial YOLO 3D implementation used in [8]Baidu's Apollo robo-taxis .

To prove the concept out of the lab, a Samsung S20 smartphone was attached to a moving vehicle and an actual attack carried out. While object creation and alteration proved considerably more difficult than the simulations had suggested, at a 43.7 per cent and 43.1 per cent success rate respectively, hiding objects was easy with a worrying 98.3 per cent success rate, the researcher said.

[9]

"PG [Poltergeist] attacks are robust," the team found, "across various scenes, weathers, time periods of a day, and camera resolutions."

The team stopped short, however, of actively attacking a real-world autonomous vehicle. "While it's clear that there exist pathways to cause computer vision systems to fail with acoustic injection," the researchers concluded, "it's not clear what products today are at risk. Rather than focus on today's nascent autonomous vehicle technology, we model the limits in simulation to understand how to better prevent future yet unimagined autonomous vehicles from being susceptible to acoustic attacks on image stabilisation systems."

The concept doesn't stop at audio signals, either. "Future AMpLe attacks could leverage signal transmission via ultrasound, visible light, infrared, lasers, radio, magnetic fields, heat, fluid, etc. to manipulate sensor outputs and thus the subsequent machine learning processes (e.g., voice recognition, computer vision)," the researchers warned.

[10]

"AMpLe attacks could cause incorrect, automated decisions with life-critical consequences for closed loop feedback systems (e.g., medical devices, autonomous vehicles, factory floors, IoT [Internet of Things])."

More information is available on the project's [11]GitHub repository , while a PDF of the paper can be downloaded under open-access terms from [12]here . ®

Get our [13]Tech Resources



[1] https://pubads.g.doubleclick.net/gampad/jump?co=1&iu=/6978/reg_security/front&sz=300x50%7C300x100%7C300x250%7C300x251%7C300x252%7C300x600%7C300x601&tile=2&c=2YMzDIAlReGmst0fPbW250QAAAFY&t=ct%3Dns%26unitnum%3D2%26raptor%3Dcondor%26pos%3Dtop%26test%3D0

[2] https://pubads.g.doubleclick.net/gampad/jump?co=1&iu=/6978/reg_security/front&sz=300x50%7C300x100%7C300x250%7C300x251%7C300x252%7C300x600%7C300x601&tile=4&c=44YMzDIAlReGmst0fPbW250QAAAFY&t=ct%3Dns%26unitnum%3D4%26raptor%3Dfalcon%26pos%3Dmid%26test%3D0

[3] https://pubads.g.doubleclick.net/gampad/jump?co=1&iu=/6978/reg_security/front&sz=300x50%7C300x100%7C300x250%7C300x251%7C300x252%7C300x600%7C300x601&tile=3&c=33YMzDIAlReGmst0fPbW250QAAAFY&t=ct%3Dns%26unitnum%3D3%26raptor%3Deagle%26pos%3Dmid%26test%3D0

[4] https://www.theregister.com/2021/06/14/in_brief_ai/

[5] https://www.theregister.com/2021/05/07/tesla_engineer_autopilot/

[6] https://www.theregister.com/2021/04/28/uk_automated_lane_keeping_approved/

[7] https://www.theregister.com/2021/03/26/semiautonomous_cars_19_per_cent/

[8] https://www.theregister.com/2021/05/06/baidu_apollo_robotaxi/

[9] https://pubads.g.doubleclick.net/gampad/jump?co=1&iu=/6978/reg_security/front&sz=300x50%7C300x100%7C300x250%7C300x251%7C300x252%7C300x600%7C300x601&tile=4&c=44YMzDIAlReGmst0fPbW250QAAAFY&t=ct%3Dns%26unitnum%3D4%26raptor%3Dfalcon%26pos%3Dmid%26test%3D0

[10] https://pubads.g.doubleclick.net/gampad/jump?co=1&iu=/6978/reg_security/front&sz=300x50%7C300x100%7C300x250%7C300x251%7C300x252%7C300x600%7C300x601&tile=3&c=33YMzDIAlReGmst0fPbW250QAAAFY&t=ct%3Dns%26unitnum%3D3%26raptor%3Deagle%26pos%3Dmid%26test%3D0

[11] https://github.com/USSLab/PoltergeistAttack

[12] https://spqrlab1.github.io/papers/ji-poltergeist-oakland21.pdf

[13] https://whitepapers.theregister.com/

Automation

Eclectic Man

This is worrying for people who want to rely on self-driving cars. I wonder whether they can also affect the lane-tracking features. As an older driver, I do find the automation in new cars intrusive such as lane tracking, 'foot off the accelerator' when approaching a roundabout, telling me I'm travelling over the speed limit when the limit is 30 not 20 as the car would have it, or that the speed limit on one minor road in the UK was 110mph.

My main problem with all this automation is that when the computer cannot cope there is the expectation from the manufacturers that the 'driver' will be alert and able to decide instantaneously what to do, when clearly anyone who is using lane tacking or automatic driving is unlikely to have been paying attention.

Re: Automation

John Robson

Only as worrying as the incompetence of most drivers.

As a disabled driver I very much appreciate lane tracking and adaptive cruise control, even if my car doesn't seem to grok that dual carriageway NSL is 70 rather than 60, or that speed limits persist around corners. At least use the manual speed limiter setting is nice and easy to use.

Pascal Monett

The fact that you are disabled does not matter. Your car has been modified to adapt to your disability so that you can drive it.

You're still the diver, whatever semi-autonomous thingamajigs you have, and if you cause an accident, you will still be held responsible.

As a society, we're getting ready to unleash a storm of metal controlled by a program that, in the best of circumstances, can only prove it works when the day is sunny, the road clean and the road markings new.

I want tests for when it rains, when it pours, when it snows, and when the road markings haven't been refreshed in 20 years.

Once an autonomous vehicle can cope with those conditions, then we can start worrying about audio attacks on detectors.

Re: Automation

boblongii

"Computer assisted" is the Big Lie™ of self-driving cars. You're either aware of what's going on enough to drive at the drop of a hat or you're not, and if you're paying that amount of attention then you might as well drive the damn thing yourself.

Every manufacturer knows this and knows that their cars' passengers will not be paying attention - they'll be talking to other passengers, reading the paper, admiring the scenery, or making rude gestures to cyclists. Designating one of these passengers to be "the driver" is simply a fig-leaf for the manufacturers' insurance requirements.

Similar Attacks Work Against Humans

Adam Oellermann

It's to be expected that such attacks will be discovered, but they are no worse than the attacks that can be deployed against human drivers. For example, shining a 3W laser pointer in the eyes of a human driver will reduce their ability to detect obstacles. Audio attacks are similarly effective - playing Billy Ray Cyrus at sufficient volume will cause the driver to lose the will to live and steer of the nearest cliff.

Re: Similar Attacks Work Against Humans

Anonymous Coward

They're obviously way worse than the attack you suggest, human driver will close/cover their eyes and try to come to a controlled stop. Making an autonomous vehicle think the stopped truck/bridge support isn't there at 70 mph I suspect will have a worse outcome for the passengers. I'm willing to play guinea pig as the passenger in the car driven by a human, if your game to be a passenger in the autonomous car?

Re: Similar Attacks Work Against Humans

Blazde

Concrete block dropped off an overpass is one of the more commonly exploited human vulnerabilities (sadly). Much cheaper than either an audio device or laser too.

Re: Similar Attacks Work Against Humans

zuckzuckgo

Large posters of scantily clad women (or men) have been know to reduce the ability of humans to recognize road hazards.

Would a poster of say a Lamborghini Gallardo have a similar effect on autonomous systems? If not, we need to train them better if they are to eventually drive like humans.

DJV

I see a future BOFH episode derived from this!

Simpler DoS attacks possible

Fonant

I fear that there will be simpler attacks on AVs. Simply walk, or ride a bike, or drive a car, as if you were about to collide with the AV (in the knowledge that you will stop, obvs). The AV will be forced to take avoiding action.

A new form of "chicken" for the teenagers of tomorrow, perhaps?

Re: Simpler DoS attacks possible

Chris G

Equally simple, is to use a laser pointer to confuse the lidar.

perfect example of using one thing - and unintended consequences

John Jennings

At the moment, I cant think of an effective countermeasure.

These camera modules are generally third party and (fairly) standardised COTS. The onboard processing is 'correct' for its context. It could well prove a major refactor to avoid this attack vector. I wonder if any self driving incidents to date could be associated with (even inadvertent) for of image destabilisation?

Better tried by twelve than carried by six.
-- Jeff Cooper