Visual attack method and device for autonomous vehicle, storage medium and electronic equipment

By invading the visual recognition system of the autonomous driving vehicle, replacing images and making aggressive adjustments, the problem of vulnerability of the autonomous driving vehicle model is solved, the impact on the recognition and perception of the vehicle environment is achieved, and the system safety is promoted.

CN120219930APending Publication Date: 2025-06-27TSINGHUA UNIVERSITY
View PDF 0 Cites 0 Cited by

Patent Information

Application Number
CN202510205416.5
Authority / Receiving Office
CN · China
Patent Type
Applications(China)
Current Assignee / Owner
Filing Date
2025-02-24
Publication Date
2025-06-27

AI Technical Summary

Technical Problem

Machine learning models of autonomous vehicles are vulnerable to direct attacks, which affect the vehicle's environmental recognition and perception functions, and these attacks are difficult to detect by the vehicle itself or assisted drivers.

Method used

By invading the visual recognition system of an autonomous driving vehicle, the original image is acquired and replaced, the attack category is determined using image recognition and classification technology, and the image is adjusted using target or non-target attack methods, and the replacement image is sent to affect the vehicle's decision-making.

Benefits of technology

Without direct contact with the sensors of the autonomous driving vehicle, it can affect the environmental identification and perception of the vehicle, revealing the shortcomings in the defense of the vehicle system, and promoting the application of relevant defense means and further guaranteeing system safety.

✦ Generated by Eureka AI based on patent content.

Smart Images

  • Figure CN120219930A_ABST
    Figure CN120219930A_ABST
Patent Text Reader

Abstract

The invention provides a visual attack method and device for an automatic driving vehicle, a storage medium and electronic equipment, and relates to the technical field of automatic driving safety, and the method comprises the steps: obtaining a first image collected by a visual recognition system of the automatic driving vehicle under the condition that the visual recognition system of the automatic driving vehicle is successfully invaded; performing image recognition on the first image, determining an attack category of the first image, and adjusting the first image by using an attack mode corresponding to the attack category of the first image to obtain a second image; and sending the second image to a visual identification system of the autonomous vehicle to replace the first image. The visual attack method and device for the autonomous vehicle, the storage medium and the electronic equipment provided by the invention are used for generating influence on environment recognition and perception of the autonomous vehicle under the condition that the sensor of the autonomous vehicle is not directly contacted.
Need to check novelty before this filing date? Find Prior Art

Description

Technical Field

[0001] The present application relates to the technical field of autonomous driving safety, and particularly relates to a visual attack method, device, storage medium and electronic device for autonomous driving vehicles. Background Art

[0002] Autonomous driving technology has become one of the most important topics in smart cities, which is very beneficial for building smart cities and facilitating people's travel. Autonomous driving vehicles rely on machine learning algorithms to process a large amount of data to process sensor data in real time and make decisions. Modules such as path planning, object detection and decision control are more directly related to vehicle and traffic safety. However, machine learning algorithms also bring new security problems when providing technical support for autonomous driving vehicles.

[0003] In the related art, compared with mechanical failures and human errors that are easy to avoid, attack technologies directly acting on machine learning models bring more severe challenges to autonomous driving vehicles and are also less likely to be detected by the autonomous driving vehicles themselves and auxiliary drivers.

[0004] Based on this, there is an urgent need for an attack method for autonomous driving vehicles to improve the improvement of the defense means of autonomous driving vehicles and the development of vehicle abnormal behavior monitoring technology. Summary of the Invention

[0005] The purpose of the present application is to provide a visual attack method, device, storage medium and electronic device for autonomous driving vehicles, which are used to affect the environmental recognition and perception of autonomous driving vehicles without directly contacting the sensors of autonomous driving vehicles.

[0006] The present application provides a visual attack method for autonomous driving vehicles, including: In the case of successfully invading the visual recognition system of an autonomous driving vehicle, obtaining a first image collected by the visual recognition system of the autonomous driving vehicle; performing image recognition on the first image to determine the attack category of the first image, and using an attack method corresponding to the attack category of the first image to adjust the first image to obtain a second image; sending the second image to the visual recognition system of the autonomous driving vehicle to replace the first image.

[0007] Optionally, the obtaining of the first image collected by the vision recognition system of the autonomous vehicle includes: using fishing means to trick the vision recognition system of the autonomous vehicle into leaking the to-be-attacked images collected at a preset frequency; wherein, the preset frequency is: at least one frame of image per second; the first image is any one frame of the to-be-attacked images; the to-be-attacked images include any one of the following: images in front of and on the sides of the autonomous vehicle when the autonomous vehicle turns or changes lanes, and images behind the autonomous vehicle when the autonomous vehicle reverses.

[0008] Optionally, the performing image recognition on the first image, determining the attack category of the first image, and using an attack method corresponding to the attack category of the first image to adjust the first image to obtain a second image includes: when the category of the first image is the first attack category, adjusting the first image by using a targeted attack method to obtain the second image; or, when the category of the first image is the second attack category, adjusting the first image by using a non-targeted attack method to obtain the second image; wherein, the first attack category is: among the objects recognized from the first image, there are objects that affect the autonomous driving strategy; the second attack category is: among the objects recognized from the first image, there are no objects that affect the autonomous driving strategy.

[0009] Optionally, the adjusting the first image by using a targeted attack method to obtain the second image includes: determining the type of the target object specified by the attacker, and adjusting the object to be attacked recognized from the first image to an object of the same type as the target object type to obtain the second image; wherein, the object to be attacked is: the object in the first image that affects the autonomous driving strategy.

[0010] Optionally, the adjusting the first image by using a non-targeted attack method to obtain the second image includes: adjusting the object to be attacked recognized from the first image to an object of a different type from the object type of the object to be attacked to obtain the second image; wherein, the object to be attacked is: any object in the first image.

[0011] Optionally, the using an attack method corresponding to the attack category of the first image to adjust the first image to obtain a second image includes: determining the computing resources of the attacker, and if the computing resources of the attacker are greater than a preset threshold, attacking the first image by using a black-box attack method, otherwise, attacking the first image by using a white-box attack method.

[0012] Optionally, the sending the second image to the visual recognition system of the autonomous vehicle to replace the first image includes: performing image recognition on the second image, and if the image recognition result indicates that the adjusted object type of the attacked object in the second image meets the attacker's requirements, sending the second image to the visual recognition system of the autonomous vehicle to replace the first image.

[0013] This application also provides a visual attack device for an autonomous vehicle, including: An image acquisition module, configured to acquire a first image collected by the visual recognition system of the autonomous vehicle when successfully invading the visual recognition system of the autonomous vehicle; a visual attack module, configured to perform image recognition on the first image, determine the attack category of the first image, and use an attack method corresponding to the attack category of the first image to adjust the first image to obtain a second image; the visual attack module is further configured to send the second image to the visual recognition system of the autonomous vehicle to replace the first image.

[0014] Optionally, the image acquisition module is specifically configured to use phishing means to trick the visual recognition system of the autonomous vehicle into leaking the to-be-attacked images collected at a preset frequency; wherein, the preset frequency is: at least one frame of image per second; the first image is any frame of the to-be-attacked images; the to-be-attacked images include any one of the following: images in front of and on the sides of the autonomous vehicle when the autonomous vehicle is turning or changing lanes, and images behind the autonomous vehicle when the autonomous vehicle is reversing.

[0015] Optionally, the visual attack module is specifically configured to, when the category of the first image is the first attack category, adjust the first image in a targeted attack manner to obtain the second image; the visual attack module is further specifically configured to, when the category of the first image is the second attack category, adjust the first image in a non-targeted attack manner to obtain the second image; wherein, the first attack category is: among the objects recognized from the first image, there are objects that affect the autonomous driving strategy; the second attack category is: among the objects recognized from the first image, there are no objects that affect the autonomous driving strategy.

[0016] Optionally, the visual attack module is specifically configured to determine the target object type specified by the attacker, and adjust the to-be-attacked object recognized in the first image to an object of the same type as the target object type to obtain the second image; wherein, the to-be-attacked object is: the object in the first image that affects the autonomous driving strategy.

[0017] Optionally, the visual attack module is specifically configured to adjust the object to be attacked identified in the first image to an object of a different object type from that of the object to be attacked, so as to obtain the second image; wherein, the object to be attacked is any object in the first image.

[0018] Optionally, the visual attack module is specifically configured to determine the computing resources of the attacker. If the computing resources of the attacker are greater than a preset threshold, the first image is attacked by using a black-box attack method; otherwise, the first image is attacked by using a white-box attack method.

[0019] Optionally, the visual attack module is specifically configured to perform image recognition on the second image. If the image recognition result indicates that the object type of the attacked object in the second image after adjustment meets the requirements of the attacker, the second image is sent to the visual recognition system of the autonomous driving vehicle to replace the first image.

[0020] The present application further provides a computer program product, including a computer program / instructions. When the computer program / instructions are executed by a processor, the steps of the visual attack method for an autonomous driving vehicle as described in any one of the above are implemented.

[0021] The present application further provides an electronic device, including a memory, a processor, and a computer program stored on the memory and executable on the processor. When the processor executes the program, the steps of the visual attack method for an autonomous driving vehicle as described in any one of the above are implemented.

[0022] The present application further provides a computer-readable storage medium, on which a computer program is stored. When the computer program is executed by a processor, the steps of the visual attack method for an autonomous driving vehicle as described in any one of the above are implemented.

[0023] For the visual attack method, device, storage medium, and electronic device for an autonomous driving vehicle provided by the present application, first, in the case of successfully invading the visual recognition system of the autonomous driving vehicle, the first image collected by the visual recognition system of the autonomous driving vehicle is obtained; then, image recognition is performed on the first image to determine the attack category of the first image, and the first image is adjusted by using an attack method corresponding to the attack category of the first image to obtain a second image; finally, the second image is sent to the visual recognition system of the autonomous driving vehicle to replace the first image. In this way, the environmental recognition and perception of the autonomous driving vehicle can be affected without directly contacting the sensors of the autonomous driving vehicle. Description of the Drawings

[0024] To more clearly illustrate the technical solutions in the present application or the prior art, the following will briefly introduce the drawings required for the description of the embodiments or the prior art. Obviously, the drawings in the following description are some embodiments of the present application. For those of ordinary skill in the art, without creative efforts, other drawings can also be obtained based on these drawings.

[0025] Figure 1 is one of the schematic flowcharts of the visual attack method for autonomous driving vehicles provided by the present application; Figure 2 is another schematic flowchart of the visual attack method for autonomous driving vehicles provided by the present application; Figure 3 is the detailed schematic flowchart of the visual attack method provided by the present application; Figure 4 is the structural schematic diagram of the visual attack device for autonomous driving vehicles provided by the present application; Figure 5 is the structural schematic diagram of the electronic device provided by the present application. Detailed implementation manners

[0026] To make the objectives, technical solutions, and advantages of the present application clearer, the following will clearly and completely describe the technical solutions in the present application with reference to the drawings in the present application. Obviously, the described embodiments are some, but not all, of the embodiments of the present application. Based on the embodiments in the present application, all other embodiments obtained by those of ordinary skill in the art without creative efforts belong to the scope of protection of the present application.

[0027] The terms "first", "second", etc. in the description and claims of the present application are used to distinguish similar objects, rather than to describe a specific order or sequence. It should be understood that such used data can be interchanged under appropriate circumstances so that the embodiments of the present application can be implemented in an order different from those illustrated or described herein, and the objects distinguished by "first", "second", etc. are generally of the same type, and the number of objects is not limited. For example, the first object can be one or multiple. In addition, "and / or" in the description and claims means at least one of the connected objects, and the character " / " generally indicates an "or" relationship between the associated objects before and after.

[0028] In the related art, one of the most common types of attacks against autonomous vehicles is the adversarial perturbation attack, which aims to affect the vehicle's perception system. Such attacks may deceive the model by adding perturbations or fake objects to the data monitored in the real world or by sensors. Some researchers have also tried to add stickers to specific objects to hide them and make them less detectable by relevant sensors. Compared with mechanical failures and human errors that are easier to avoid, the attack techniques directly acting on machine learning models pose more severe challenges to autonomous vehicles and are less likely to be detected by the autonomous vehicles themselves and the auxiliary drivers.

[0029] An embodiment of the present application provides a visual attack method for autonomous vehicles, which can affect the environmental recognition and perception of autonomous vehicles without directly contacting the sensors of the autonomous vehicles. As Figure 1 shown, the method includes: invading the visual recognition system of the autonomous vehicle by intercepting wireless signals or physical connections, destroying the physical security measures of the vehicle, using phishing means to trick the autonomous driving system into leaking images, etc. Capturing the images monitored by the on-vehicle camera at a frequency of at least one frame per second. Retaining the images that may have a greater impact due to misrecognition according to the current behavior of the autonomous vehicle and sending them to the attacker. Performing image recognition and classification on the currently captured images, and the recognition result determines whether the currently captured image is suitable for a targeted attack or a non-targeted attack. Conducting a white-box attack or a black-box attack on the captured images according to the size of the available resources. After the attack is completed, sending the images that can be misclassified back to the on-vehicle visual recognition system to overwrite the real images monitored by the on-vehicle camera.

[0030] An embodiment of the present application provides a visual attack method for autonomous vehicles, which can capture the pictures captured by the on-vehicle camera and replace them with the attacked noise pictures without directly contacting the autonomous vehicle, so as to affect the behavior and decision-making of the autonomous vehicle; this method reveals the defects in the current system defense of autonomous vehicles and can be tested on simulation platforms such as SUMO and CARLA. This method does not clearly point out how to invade the system to complete image capture and image replacement, and this threatening measure will be left for system security engineers and others to consider. This method provides an attack strategy, which can promote the application update of relevant defense means and further ensure the system security of autonomous vehicles while revealing the potential safety hazards of autonomous vehicles themselves.

[0031] The following will combine the accompanying drawings and elaborate on the visual attack method for autonomous vehicles provided by the embodiments of the present application through specific embodiments and their application scenarios in detail.

[0032] As Figure 2As shown, a visual attack method for autonomous vehicles provided by an embodiment of the present application may include the following steps 201 to 203: Step 201, in the case of successfully invading the visual recognition system of the autonomous vehicle, obtain the first image collected by the visual recognition system of the autonomous vehicle.

[0033] Exemplarily, in an embodiment of the present application, the visual recognition system of the autonomous vehicle can be invaded by methods such as intercepting wireless signals or physical connections, destroying the physical security measures of the vehicle, and using phishing means to trick the autonomous driving system into leaking images.

[0034] Specifically, the above step 201 may further include the following step 201a: Step 201a, use phishing means to trick the visual recognition system of the autonomous vehicle into leaking the to-be-attacked images collected at a preset frequency.

[0035] Wherein, the preset frequency is: at least one frame of image per second; the first image is any frame of the to-be-attacked images; the to-be-attacked images include any one of the following: images in front of and on the sides of the autonomous vehicle when the autonomous vehicle turns or changes lanes, images behind the autonomous vehicle when the autonomous vehicle reverses.

[0036] Exemplarily, in an embodiment of the present application, an attacker uses unencrypted communication channels, social engineering means, physical penetration (such as intercepting wireless signals or physical connections, destroying the physical security measures of the vehicle, and tricking the autonomous driving system into leaking pictures through phishing means). After that, the images monitored by the on-vehicle camera can be captured at a frequency of at least one frame per second, and according to the current behavior of the autonomous vehicle, the images that may have a greater impact due to misrecognition are retained and sent to the attacker.

[0037] It should be noted that when capturing images, only the images that have the greatest impact on the current behavior of the autonomous vehicle are captured. For example, when changing lanes or turning, only the images directly in front and on the sides are captured, and when reversing, only the images directly behind and on the sides of the vehicle are captured.

[0038] Step 202, perform image recognition on the first image, determine the attack category of the first image, and use an attack method corresponding to the attack category of the first image to adjust the first image to obtain a second image.

[0039] Exemplarily, the attacker performs image recognition on the currently captured first image and classifies the objects identified in the first image. The recognition result determines whether the currently captured image is suitable for a target attack or a non-target attack.

[0040] Specifically, step 202 above may further include the following step 202a or step 202b: Step 202a: When the category of the first image is the first attack category, adjust the first image in a targeted attack manner to obtain the second image.

[0041] Step 202b: When the category of the first image is the second attack category, adjust the first image in a non-targeted attack manner to obtain the second image.

[0042] Wherein, the first attack category is: among the objects recognized from the first image, there are objects that affect the autonomous driving strategy; the second attack category is: among the objects recognized from the first image, there are no objects that affect the autonomous driving strategy.

[0043] Exemplarily, as Figure 3 shown, after the attacker captures a real image, performs image recognition and classification, and determines whether there are objects in the image that affect the behavior of the vehicle (i.e., the above-mentioned autonomous driving vehicle). If there are objects in the recognition result that affect the autonomous driving vehicle strategy, a targeted attack is used; otherwise, a non-targeted attack is used.

[0044] Specifically, the step of performing a targeted attack in step 202a above may include the following step 202a1: Step 202a1: Determine the type of the target object specified by the attacker, and adjust the object to be attacked recognized in the first image to an object of the same type as the target object type to obtain the second image.

[0045] Wherein, the object to be attacked is: the object in the first image that affects the autonomous driving strategy.

[0046] Exemplarily, the targeted attack in the embodiments of the present application is used to disguise or alter the acquired image so that it can be misclassified as a certain specified category of attack. For example, identifying people / vehicles / road lights, etc. in the image as the object type specified by the attacker.

[0047] Specifically, the step of performing a non-targeted attack in step 202b above may include the following step 202b1: Step 202b1: Adjust the object to be attacked recognized in the first image to an object of a different type from the object type of the object to be attacked to obtain the second image.

[0048] Wherein, the object to be attacked is: any object in the first image.

[0049] For example, the non-target attack in the embodiment of the present application is used to disguise or alter the acquired image so that it can be misclassified as a non-target attack of a non-real category. For example, a person / vehicle / street lamp in the image is identified as another object type different from the original object type.

[0050] In a possible implementation, a corresponding attack method may be selected according to the size of the attacker's computing resources. When the computing resources are small, a white box attack that consumes less resources may be selected, and when the computing resources are large, a black box attack that consumes more resources may be selected.

[0051] Specifically, the above step 202 may further include the following step 202c: Step 202c: determine the attacker's computing resources. If the attacker's computing resources are greater than a preset threshold, use a black box attack to attack the first image. Otherwise, use a white box attack to attack the first image.

[0052] For example, Figure 3 As shown, after determining the attack category, white-box attack or black-box attack can be selected according to the size of currently available resources. White-box attack consumes less resources, while black-box attack requires more resources.

[0053] Step 203: Send the second image to the visual recognition system of the autonomous driving vehicle to replace the first image.

[0054] Exemplarily, inputting the second image after the attack back into the sensor of the autonomous driving car means replacing the first image actually monitored by the autonomous driving car with the second image after the attack by means of a method of invading the visual recognition system of the autonomous driving car.

[0055] Specifically, the above step 203 may further include the following step 203a: Step 203a: perform image recognition on the second image. If the image recognition result indicates that the adjusted object type of the attacked object in the second image meets the attacker's requirements, the second image is sent to the visual recognition system of the autonomous driving vehicle to replace the first image.

[0056] For example, Figure 3 As shown, after the attack is completed, the second image needs to be recognized and classified again. If the recognition and classification results meet the attacker's needs, the changed image is sent back to the visual recognition system of the autonomous vehicle.

[0057] The visual attack method for autonomous vehicles provided in the embodiment of the present application first obtains a first image captured by the visual recognition system of the autonomous vehicle when the visual recognition system of the autonomous vehicle is successfully invaded; then, image recognition is performed on the first image to determine the attack category of the first image, and the first image is adjusted using an attack method corresponding to the attack category of the first image to obtain a second image; finally, the second image is sent to the visual recognition system of the autonomous vehicle to replace the first image. In this way, the environmental recognition and perception of the autonomous vehicle can be affected without directly contacting the sensors of the autonomous vehicle.

[0058] It should be noted that the visual attack method for an autonomous vehicle provided in the embodiment of the present application can be executed by a visual attack device for an autonomous vehicle, or a control module in the visual attack device for an autonomous vehicle for executing the visual attack method for an autonomous vehicle. In the embodiment of the present application, the visual attack device for an autonomous vehicle provided in the embodiment of the present application is described by taking the visual attack method for an autonomous vehicle executed by a visual attack device for an autonomous vehicle as an example.

[0059] It should be noted that, in the embodiments of the present application, the visual attack methods for autonomous driving vehicles shown in the above-mentioned method drawings are all illustrated by taking one of the drawings in the embodiments of the present application as an example. In specific implementation, the visual attack methods for autonomous driving vehicles shown in the above-mentioned method drawings can also be implemented in combination with any other drawings that can be combined as shown in the above-mentioned embodiments, which will not be repeated here.

[0060] The visual attack device for autonomous driving vehicles provided in the present application is described below, and the visual attack method for autonomous driving vehicles described below and above can be referenced to each other.

[0061] Figure 4 A schematic diagram of the structure of a visual attack device for an autonomous driving vehicle provided in an embodiment of the present application is shown in FIG. Figure 4 As shown, specifically including: The image acquisition module 401 is used to acquire a first image captured by the visual recognition system of the autonomous driving vehicle when the visual recognition system of the autonomous driving vehicle is successfully invaded; the visual attack module 402 is used to perform image recognition on the first image, determine the attack category of the first image, and adjust the first image using an attack method corresponding to the attack category of the first image to obtain a second image; the visual attack module 402 is also used to send the second image to the visual recognition system of the autonomous driving vehicle to replace the first image.

[0062] Optionally, the image acquisition module 401 is specifically configured to use phishing means to trick the visual recognition system of the autonomous vehicle into leaking the collected images to be attacked at a preset frequency; wherein, the preset frequency is: at least one frame of image per second; the first image is any frame of the images to be attacked; the images to be attacked include any one of the following: images in front of and on the sides of the autonomous vehicle when the autonomous vehicle turns or changes lanes, and images behind the autonomous vehicle when the autonomous vehicle reverses.

[0063] Optionally, when the category of the first image is the first attack category, the visual attack module 402 is specifically configured to adjust the first image in a targeted attack manner to obtain the second image; when the category of the first image is the second attack category, the visual attack module 402 is specifically further configured to adjust the first image in a non-targeted attack manner to obtain the second image; wherein, the first attack category is: among the objects recognized from the first image, there are objects that affect the autonomous driving strategy; the second attack category is: among the objects recognized from the first image, there are no objects that affect the autonomous driving strategy.

[0064] Optionally, the visual attack module 402 is specifically configured to determine the target object type specified by the attacker, and adjust the object to be attacked recognized in the first image to an object of the same type as the target object type to obtain the second image; wherein, the object to be attacked is: an object in the first image that affects the autonomous driving strategy.

[0065] Optionally, the visual attack module 402 is specifically configured to adjust the object to be attacked recognized in the first image to an object of a different type from the object type of the object to be attacked to obtain the second image; wherein, the object to be attacked is: any object in the first image.

[0066] Optionally, the visual attack module 402 is specifically configured to determine the computing resources of the attacker. If the computing resources of the attacker are greater than a preset threshold, the first image is attacked using a black-box attack method; otherwise, the first image is attacked using a white-box attack method.

[0067] Optionally, the visual attack module 402 is specifically configured to perform image recognition on the second image. If the image recognition result indicates that the object type of the attacked object in the second image after adjustment meets the requirements of the attacker, the second image is sent to the visual recognition system of the autonomous vehicle to replace the first image.

[0068] The visual attack device for autonomous driving vehicles provided by this application, first, in the case of successfully invading the visual recognition system of the autonomous driving vehicle, obtains the first image collected by the visual recognition system of the autonomous driving vehicle; then, performs image recognition on the first image, determines the attack category of the first image, and uses an attack method corresponding to the attack category of the first image to adjust the first image to obtain a second image; finally, sends the second image to the visual recognition system of the autonomous driving vehicle to replace the first image. In this way, it is possible to affect the environmental recognition and perception of the autonomous driving vehicle without directly contacting the sensors of the autonomous driving vehicle.

[0069] Figure 5 Schematically illustrates the physical structure of an electronic device, as Figure 5 shown. The electronic device may include: a processor 510, a communication interface 520, a memory 530, and a communication bus 540. Among them, the processor 510, the communication interface 520, and the memory 530 communicate with each other through the communication bus 540. The processor 510 can call the logical instructions in the memory 530 to execute the visual attack method for autonomous driving vehicles, and the method includes: first, in the case of successfully invading the visual recognition system of the autonomous driving vehicle, obtains the first image collected by the visual recognition system of the autonomous driving vehicle; then, performs image recognition on the first image, determines the attack category of the first image, and uses an attack method corresponding to the attack category of the first image to adjust the first image to obtain a second image; finally, sends the second image to the visual recognition system of the autonomous driving vehicle to replace the first image. In this way, it is possible to affect the environmental recognition and perception of the autonomous driving vehicle without directly contacting the sensors of the autonomous driving vehicle.

[0070] In addition, when the logical instructions in the above-mentioned memory 530 can be implemented in the form of software functional units and sold or used as independent products, they can be stored in a computer-readable storage medium. Based on such an understanding, the technical solution of this application, in essence, or the part that contributes to the prior art, or a part of this technical solution, can be embodied in the form of a software product. This computer software product is stored in a storage medium and includes several instructions for causing a computer device (which can be a personal computer, a server, or a network device, etc.) to execute all or part of the steps of the methods described in various embodiments of this application. The foregoing storage medium includes: various media such as USB flash drives, mobile hard disks, read-only memories (ROM, Read-Only Memory), random access memories (RAM, Random Access Memory), magnetic disks, or optical discs that can store program codes.

[0071] On the other hand, this application also provides a computer program product. The computer program product includes a computer program stored on a computer-readable storage medium. The computer program includes program instructions. When the program instructions are executed by a computer, the computer can execute the visual attack method for autonomous driving vehicles provided by the above-mentioned various methods. The method includes: First, in the case of successfully invading the visual recognition system of an autonomous driving vehicle, obtain the first image collected by the visual recognition system of the autonomous driving vehicle; then, perform image recognition on the first image to determine the attack category of the first image, and use an attack method corresponding to the attack category of the first image to adjust the first image to obtain a second image; finally, send the second image to the visual recognition system of the autonomous driving vehicle to replace the first image. In this way, it is possible to affect the environmental recognition and perception of an autonomous driving vehicle without directly contacting the sensors of the autonomous driving vehicle.

[0072] On another aspect, this application also provides a computer-readable storage medium, on which a computer program is stored. When the computer program is executed by a processor, it is implemented to execute the visual attack method for autonomous driving vehicles provided by the above-mentioned various methods. The method includes: First, in the case of successfully invading the visual recognition system of an autonomous driving vehicle, obtain the first image collected by the visual recognition system of the autonomous driving vehicle; then, perform image recognition on the first image to determine the attack category of the first image, and use an attack method corresponding to the attack category of the first image to adjust the first image to obtain a second image; finally, send the second image to the visual recognition system of the autonomous driving vehicle to replace the first image. In this way, it is possible to affect the environmental recognition and perception of an autonomous driving vehicle without directly contacting the sensors of the autonomous driving vehicle.

[0073] The device embodiments described above are merely illustrative. The units described as separate components may or may not be physically separated. The components shown as units may or may not be physical units, that is, they may be located in one place or distributed to multiple network units. Some or all of the modules can be selected according to actual needs to achieve the purpose of the solution of this embodiment. Those of ordinary skill in the art can understand and implement it without creative effort.

[0074] Through the description of the above embodiments, those skilled in the art can clearly understand that each embodiment can be implemented by means of software plus a necessary general hardware platform, and of course, it can also be implemented by hardware. Based on such an understanding, the essence of the above technical solution, or the part that contributes to the prior art, can be embodied in the form of a software product. The computer software product can be stored in a computer-readable storage medium, such as ROM / RAM, magnetic disk, optical disk, etc., and includes several instructions to enable a computer device (which can be a personal computer, a server, or a network device, etc.) to execute the methods described in each embodiment or some parts of the embodiments.

[0075] Finally, it should be noted that the above embodiments are only used to illustrate the technical solutions of the present application, and are not intended to limit them. Although the present application has been described in detail with reference to the foregoing embodiments, those of ordinary skill in the art should understand that they can still modify the technical solutions described in the foregoing embodiments, or perform equivalent replacements for some of the technical features. However, these modifications or replacements do not cause the essence of the corresponding technical solutions to deviate from the spirit and scope of the technical solutions of the embodiments of the present application.

Claims

1. A visual attack method for an autonomous driving vehicle, characterized in that: include: In the case of successfully hacking into the visual recognition system of the autonomous driving vehicle, obtaining a first image captured by the visual recognition system of the autonomous driving vehicle; Performing image recognition on the first image to determine an attack category of the first image, and adjusting the first image using an attack method corresponding to the attack category of the first image to obtain a second image; The second image is sent to the visual recognition system of the autonomous vehicle to replace the first image.

2. The method according to claim 1, characterized in that The acquiring of a first image captured by a visual recognition system of the autonomous driving vehicle includes: Using phishing means to trick the visual recognition system of the autonomous driving vehicle into leaking the collected images to be attacked at a preset frequency; Among them, the preset frequency is: at least one frame of image per second; the first image is any frame of the image to be attacked; the image to be attacked includes any one of the following: images in front and on the sides of the autonomous driving vehicle when the autonomous driving vehicle turns or changes lanes, and images behind the autonomous driving vehicle when the autonomous driving vehicle reverses.

3. The method according to claim 1, characterized in that The performing image recognition on the first image, determining the attack category of the first image, and adjusting the first image using an attack method corresponding to the attack category of the first image to obtain a second image includes: When the category of the first image is a first attack category, adjusting the first image in a targeted attack manner to obtain the second image; or, When the category of the first image is a second attack category, adjusting the first image in a non-target attack manner to obtain the second image; Among them, the first attack category is: among the objects identified from the first image, there are objects that affect the autonomous driving strategy; the second attack category is: among the objects identified from the first image, there are no objects that affect the autonomous driving strategy.

4. The method according to claim 3, characterized in that The step of adjusting the first image by using a targeted attack method to obtain the second image includes: Determining the type of the target object specified by the attacker, and adjusting the object to be attacked identified in the first image to be an object of the same type as the target object, to obtain the second image; Among them, the object to be attacked is: the object in the first image that affects the automatic driving strategy.

5. The method according to claim 3, characterized in that: The step of adjusting the first image by adopting a non-target attack method to obtain the second image includes: Adjusting the object to be attacked identified in the first image to adjust the object to be attacked to an object of a different type from the object to be attacked, thereby obtaining the second image; The object to be attacked is: any object in the first image.

6. The method according to any one of claims 3 to 5, characterized in that The step of adjusting the first image using an attack method corresponding to the attack category of the first image to obtain a second image includes: The computing resources of the attacker are determined. If the computing resources of the attacker are greater than a preset threshold, a black box attack is used to attack the first image. Otherwise, a white box attack is used to attack the first image.

7. The method according to claim 1, characterized in that The sending the second image to the visual recognition system of the autonomous driving vehicle to replace the first image includes: Perform image recognition on the second image. If the image recognition result indicates that the adjusted object type of the attacked object in the second image meets the attacker's requirements, send the second image to the visual recognition system of the autonomous driving vehicle to replace the first image.

8. A visual attack device for an autonomous driving vehicle, characterized in that: The device comprises: An image acquisition module, configured to acquire a first image captured by the visual recognition system of the autonomous driving vehicle in the case of successfully invading the visual recognition system of the autonomous driving vehicle; a visual attack module, configured to perform image recognition on the first image, determine an attack category of the first image, and adjust the first image using an attack method corresponding to the attack category of the first image to obtain a second image; The visual attack module is also used to send the second image to the visual recognition system of the autonomous driving vehicle to replace the first image.

9. An electronic device, characterized in that: The method comprises a memory, a processor and a computer program stored in the memory and executable on the processor, wherein when the processor executes the program, the steps of the visual attack method for an autonomous driving vehicle as claimed in any one of claims 1 to 7 are implemented.

10. A computer-readable storage medium, characterized in that: A computer program is stored thereon, and when the computer program is executed by a processor, the steps of the visual attack method for an autonomous driving vehicle as described in any one of claims 1 to 7 are implemented.