Article Details
Scrape Timestamp (UTC): 2024-06-03 05:51:37.969
Source: https://www.theregister.com/2024/06/03/baidu_robotaxi_attack/
Original Article Text
Click to Toggle View
Researchers crash Baidu robo-cars with tinfoil and paint daubed on cardboard. The fusion of Lidar, radar, and cameras can be fooled by stuff from your kids' craft box. A team of researchers from prominent universities – including SUNY Buffalo, Iowa State, UNC Charlotte, and Purdue – were able to turn an autonomous vehicle (AV) operated on the open sourced Apollo driving platform from Chinese web giant Baidu into a deadly weapon by tricking its multi-sensor fusion system. "Extensive experiments based on a real-world AV testbed show that the proposed attack can continuously hide a target vehicle from the perception system of a victim AV using only two small adversarial objects," explained the researchers, whose work was published last week in The 30th Annual International Conference on Mobile Computing and Networking. While others have proven vulnerabilities inherent in AV systems, this particular team expanded on single-sensing modality or camera-LiDAR manipulation, and tricked systems that employ Lidar, camera, and radar together. The new attack leverages mmWave reflection – the signals that provide object detection in such systems – on a smooth metal surface. They do this in a way researchers refer to as "low cost" and "easily fabricated" as it involves strategically arranging metal foil and colored patches on cardboard. "By placing a smooth metal surface between the radar and a target vehicle with a specific orientation, the transmitted mmWave signals can be deflected from the radar receiver, leading to a reduction in the energy of echo signals from the vehicle," wrote the study authors. "When the energy becomes lower than a threshold, the target vehicle will be hidden from radar perception." Meanwhile, the color patch misrepresented input image pixel values and affected Apollo's camera perception. Reflections confused its read on Lidar lasers. Thus all three sensing modalities were compromised. The boffins suggest that the attack could be carried out with drones, which serve to "hide" a secondary vehicle from the victim AV by projecting or carrying the adversarial object. Absent a drone, the trickster collage could be mounted on the front vehicle and disguised as an advertisement. Baidu robo-taxi hack by drone – Click to enlarge Baidu robo taxi hack by advert – Click to enlarge "Since the drones only hover for a few seconds during the attack and can fly away from the victim AV immediately after the attack, the attack can be performed with high stealthiness and flexibility," noted the researchers. While Baidu Apollo platforms were used in the attack, the attack strategy could theoretically be applied to other multi-sensor fusion systems. Baidu has expanded its robo-taxi operations across China. The tech giant has charged for autonomous rides in its Apollo Go cabs since November 2021 and now operates robo-taxis in more than ten Chinese cities. Its service in Wuhan alone covers 3,000 square kilometers and half the city's population. The biz expects its robo-taxi wing to be profitable next year.
Daily Brief Summary
A team of university researchers successfully tricked the sensor system of a Baidu autonomous vehicle using rudimentary materials like tinfoil and paint on cardboard.
Their experiments demonstrated that these simple objects could continuously obscure a target vehicle from the autonomous system by manipulating mmWave signals and visual input.
The attack strategy involves using drones or mounting the materials on the front of a vehicle, potentially allowing for covert operations.
This method challenges the security of multi-sensor fusion systems used in autonomous vehicles, which combine Lidar, radar, and camera data to perceive surroundings.
The vulnerability exposed by the researchers points to potential risks in the deployment of autonomous vehicles and the need for robust security measures against low-tech interferences.
The findings were detailed at The 30th Annual International Conference on Mobile Computing and Networking, highlighting the escalating concerns around AV technology security.
Baidu, using the compromised Apollo platform, operates expanding robo-taxi services across China, aiming for profitability in this division by next year despite these challenges.