Automatic driving system safety testing device, method and electronic equipment
Patent Information
- Application Number
- CN202611311215.4
- Authority / Receiving Office
- CN · China
- Patent Type
- Applications(China)
- Current Assignee / Owner
- Filing Date
- 2026-08-27
- Publication Date
- 2026-09-29
AI Technical Summary
[0004]本申请提供了一种自动驾驶系统安全测试装置、方法及电子设备,以至少解决攻击信号容易被融合算法识别并过滤,难以对目标自动驾驶系统形成有效威胁的技术问题
[0039]需要说明的是,第二方面至第六方面中的任一种实现方式所带来的技术效果可参见第一方面中对应实现方式所带来的技术效果,此处不再赘述。
Smart Images

Figure CN122835767A_ABST
Abstract
Description
Technical Field
[0001] This application relates to the field of autonomous driving technology, and more particularly to the field of intelligent driving safety testing technology, specifically to an autonomous driving system safety testing device, method, and electronic device. Background Technology
[0002] With the rapid development of autonomous driving technology, environmental perception systems, as the first line of defense for the safe operation of autonomous vehicles, are receiving increasing attention for their reliability and safety. Currently, most mainstream autonomous vehicles adopt a multi-sensor fusion perception architecture, utilizing the collaborative work of various sensors such as LiDAR, visual cameras, millimeter-wave radar, and ultrasonic sensors to achieve comprehensive perception of the road environment, obstacles, and pedestrians. Multi-sensor fusion solutions significantly improve the robustness and safety of the perception system through data complementarity and redundancy verification between different sensors.
[0003] However, while multi-sensor fusion perception systems enhance security, they also face new security challenges. Attack testing of autonomous driving perception systems has become a crucial means of verifying system security. Most existing attack testing schemes target only a single type of sensor, such as attacking LiDAR point clouds by emitting jamming signals or tampering with camera images by infiltrating the vision system. When facing fusion perception systems with multi-sensor cross-validation mechanisms, these single-sensor attack schemes are easily identified and filtered by the fusion algorithm, making it difficult to pose an effective threat to the target autonomous driving system. Therefore, how to effectively test multi-sensor fusion perception systems has become an urgent technical problem to be solved. Summary of the Invention
[0004] This application provides a safety testing apparatus, method, and electronic device for autonomous driving systems, aiming to at least address the technical problem that attack signals are easily identified and filtered by fusion algorithms, making it difficult for them to pose an effective threat to the target autonomous driving system. The technical solution adopted in this application is as follows: In a first aspect, this application provides an autonomous driving system security testing device, comprising: an attack module and a test module; the attack module and the test module are communicatively connected; the attack module is used to apply a multi-dimensional attack signal to the multi-dimensional sensor based on the perception parameter values of the core operating parameters of the multi-dimensional sensor; and, after applying the multi-dimensional attack signal, to send a test command to the test module; wherein the multi-dimensional sensor is multiple sensors in the target autonomous driving system of the target vehicle; the test module is used to, in response to the test command, observe the driving video stream of the target vehicle under the multi-dimensional attack signal; and determine the anti-attack performance of the autonomous driving system based on the driving video stream.
[0005] Based on the aforementioned technical means, the attack module in this application can simultaneously apply attack signals to multiple sensors in the target autonomous driving system based on the core operating parameters of each sensor. This multi-dimensional attack method can break through the security redundancy mechanism established by cross-validation in multi-sensor fusion perception algorithms, allowing the attack effect to be transmitted to the decision-making and planning layer of the target vehicle and ultimately manifest as abnormal changes in vehicle driving behavior. This effectively verifies the true vulnerability of the fusion perception architecture under cooperative interference conditions. Simultaneously, the test module directly observes the driving video stream in physical space and determines the anti-attack performance accordingly. Compared to the method of intruding into the vehicle system to read internal logs, this not only avoids data interface incompatibility issues caused by vehicle model differences but also avoids uncontrollable risks to the normal driving safety of the target vehicle, providing a reliable testing foundation for the iterative upgrade of autonomous driving defense algorithms.
[0006] In one possible implementation, the attack module includes: a perception and reconnaissance unit, a generation unit, and an attack unit; the generation unit is communicatively connected to both the perception and reconnaissance unit and the attack unit; the perception and reconnaissance unit is used to determine perception parameter values and send the perception parameter values to the generation unit; the generation unit is used to determine the model information of the multidimensional sensor based on the perception parameter values; determine the multidimensional attack signal of the multidimensional sensor based on the model information; and send the multidimensional attack signal to the attack unit; the attack unit is used to apply the multidimensional attack signal to the multidimensional sensor.
[0007] Based on the aforementioned technical means, the perception and reconnaissance unit of this application can determine the perception parameter values of the core operating parameters of the sensor, and the generation unit can determine the specific model information of the multi-dimensional sensor. Then, based on the model information, a corresponding attack signal is matched and executed by the attack unit. This eliminates the reliance on a factory-preset static mapping table for attack parameters, instead dynamically acquiring the actual operating characteristics of the target sensor before each test. Even if the actual parameters of the same model sensor deviate due to firmware version, environmental aging, or vehicle configuration differences, the attack signal can still track and adjust, thereby avoiding attack failure due to parameter mismatch and improving the adaptability of the testing device to different vehicles and sensor states.
[0008] In one possible implementation, the multidimensional sensor includes a light wave detection type sensor; the generation unit includes a first determining subunit; the first determining subunit is used to determine the model information of the light wave detection type sensor based on the sensor parameter library and the sensing parameter values of the core operating parameters of the light wave detection type sensor; wherein, the sensor parameter library includes the reference parameter values of the core operating parameters of each sensor in the sensor dataset.
[0009] Based on the above technical means, the first determining subunit in this application uses the reference parameter values of various light wave detection type sensors stored in the sensor parameter library to match the real-time acquired sensing parameter values, thereby automatically determining the model information of the target sensor, improving the automation level of the testing process and cross-vehicle versatility.
[0010] In one possible implementation, the multidimensional sensor includes a visual perception sensor; the generation unit includes a second determining subunit; the second determining subunit is used to determine the model information of the visual perception sensor based on the manufacturing model of the visual perception sensor in the target vehicle.
[0011] Based on the above-mentioned technical means, the second determining subunit in the testing device of this application determines the model of the target vehicle by recognizing the appearance features of the target vehicle or reading the body markings, and then determines the factory model corresponding to the visual perception sensor. This eliminates the need for intermediate steps such as parameter acquisition, feature extraction and comparison matching, making the entire model determination process simpler, more reliable and easier to deploy and maintain.
[0012] In one possible implementation, the generation unit includes a generation subunit; a first determining subunit and a second determining subunit, both communicatively connected to the generation subunit; the generation subunit is used to determine the attack value of the core operating parameter of the multidimensional sensor based on the mapping relationship set and the model information uploaded by the first determining subunit and the second determining subunit; and to determine the multidimensional attack signal of the multidimensional sensor based on the attack value; wherein, the mapping relationship set includes the baseline attack value of the core operating parameter of each sensor model in the sensor model set; the attack value of the core operating parameter of any sensor is the configuration value of the core operating parameter in the attack signal of any sensor.
[0013] Based on the aforementioned technical means, the sub-unit generation in this application is based on a mapping relationship set. Upon receiving the model information uploaded by the first or second determined sub-unit, the core operating parameter attack value of the corresponding sensor model can be obtained directly by looking up the table, and a multi-dimensional attack signal can be generated accordingly. Since the benchmark attack value in the mapping relationship set is pre-set for the physical characteristics of different sensor models, it has stronger stability and predictability compared to dynamic estimation or online learning methods.
[0014] In one possible implementation, the multidimensional sensor includes a light wave detection sensor and a visual perception sensor; the generation subunit is specifically used to: for the target sensor in the multidimensional sensor, determine the corrected attack value of the core operating parameter of the target sensor based on the first parameter value, the second parameter value, and the absolute parameter difference between the first parameter value and the second parameter value; wherein, the first parameter value is the perceived parameter value of the core operating parameter of the target sensor; the second parameter value is the attack value of the core operating parameter of the target sensor; when the target sensor is a visual perception sensor, the first parameter value is equal to the second parameter value by default.
[0015] Based on the aforementioned technical means, for optical wave detection sensors, this application generates a modified attack value based on the first parameter value, the second parameter value, and the absolute parameter difference between them. This ensures that the final output attack parameters are closer to the actual operating state of the target sensor, guaranteeing the frequency matching accuracy between the interference signal and the target sensor. For visual perception sensors, since physical drift similar to that of optical wave detection sensors does not occur during actual operation, the first parameter value is assumed to be equal to the second parameter value. Therefore, the baseline attack value from the mapping relationship set can be directly used to meet the attack requirements.
[0016] In one possible implementation, the attack unit includes: a target sensor attack subunit corresponding to the target sensor; the target sensor is each sensor in the multi-dimensional sensor; and a generation unit, specifically used to: send an attack command to the target sensor attack subunit; wherein the attack command includes an attack signal corresponding to the target sensor; and the target sensor attack subunit is used to apply the attack signal to the target sensor in response to the attack command.
[0017] Based on the above technical means, each type of sensor in this application is configured with its own corresponding target sensor attack subunit. This one-to-one independent configuration structure allows the attack signal of each sensor to be generated and transmitted independently according to the physical characteristics, installation position and sensitive frequency band of the corresponding sensor. Different attack subunits are not coupled to each other, so that synchronous attacks can be carried out on each sensor according to the test requirements to simulate multimodal cooperative interference scenarios without affecting the normal operation of other sensor attack subunits.
[0018] In one possible implementation, the generation unit further includes a coordination subunit and a reconnaissance subunit; the coordination subunit is communicatively connected to the reconnaissance subunit and the target sensor attack subunit, respectively; the reconnaissance subunit and the target sensor attack subunit are communicatively connected; the coordination subunit is used to send a test command to the target sensor attack subunit and a reconnaissance command to the reconnaissance subunit; the test command is used to instruct the transmission of a test signal to the target reconnaissance device and to indicate the transmission time of the test signal; the reconnaissance command is used to instruct the arrival time of the reconnaissance test signal to the target reconnaissance device; the target sensor attack subunit is used to send a test signal to the target reconnaissance device at the transmission time in response to the test command; the reconnaissance subunit is used to determine the arrival time in response to the reconnaissance command and to return the arrival time to the coordination subunit; the coordination subunit is also used to determine the attack delay of the target sensor based on the transmission time and the arrival time; and to send the attack delay to the attack unit so that the attack unit applies a multidimensional attack signal to the multidimensional sensor based on the attack delay, thereby causing the multidimensional sensor to be attacked simultaneously.
[0019] Based on the aforementioned technical means, this application, through the cooperation of the collaborative subunit and the reconnaissance subunit, measures the actual transmission delay between each target sensor attack subunit and the target reconnaissance device using test signals before the formal attack. Then, compensation is applied to each attack subunit based on the measured delay, ensuring that all attack signals arrive at their corresponding target sensors simultaneously. This ensures that attack signals from all dimensions act synchronously on their respective sensors, preventing the target vehicle from identifying and filtering attack interference based on time differences, thereby improving the effectiveness of multimodal attacks and the reliability of test results.
[0020] In one possible implementation, the autonomous driving system safety testing device is positioned in a concealed location on the roadside. The device also includes a trigger module, which is communicatively connected to an attack module. The trigger module is configured to: upon observing a target vehicle entering the attack range, send a trigger command to the attack module to trigger the generation of a multi-dimensional attack signal. Specifically, the testing module is configured to: determine the attack confidence level of the target vehicle based on the driving video stream; if the attack confidence level is greater than a first preset attack confidence level, prompt the attack module to continue applying the multi-dimensional attack signal; if the attack confidence level is not greater than the first preset attack confidence level but greater than a second preset attack confidence level, prompt the attack module to increase the attack power of the multi-dimensional attack signal and continue applying the multi-dimensional attack signal with increased power; if the attack confidence level is not greater than the second preset attack confidence level, prompt the attack module to regenerate the multi-dimensional attack signal.
[0021] Based on the aforementioned technical means, the triggering module in this application automatically triggers the attack module to generate a multi-dimensional attack signal when the target vehicle enters the attack range. This eliminates the need for testers to continuously observe the vehicle's position and manually initiate the attack, thus automating the testing process. Furthermore, a tiered response is executed based on different threshold ranges of attack confidence. When the confidence level is high, the current attack strength is maintained to ensure stable interference. When the confidence level is medium, the attack power is increased to enhance the interference effect. When the confidence level is low, the multi-dimensional attack signal is regenerated to fundamentally adjust the attack strategy. This avoids the problem of interference attenuation or failure before the target vehicle leaves the attack range due to fixed attack parameters, thereby improving the sustained effectiveness of the test under a single trigger.
[0022] In one possible implementation, the testing module is specifically used to: determine the longitudinal deceleration of the target vehicle body, the optical flow velocity difference, and the heading angle of the vehicle head based on the driving video stream; determine the abnormal braking quantization value, the abnormal speed control quantization value, and the abnormal steering behavior quantization value of the target vehicle based on the longitudinal deceleration of the vehicle body, the optical flow velocity difference, and the heading angle of the vehicle head, respectively; and determine the attack confidence level based on the abnormal braking quantization value, the abnormal speed control quantization value, and the abnormal steering behavior quantization value.
[0023] Based on the aforementioned technical means, the testing module in this application extracts three physical quantities from the driving video stream: longitudinal deceleration of the vehicle body, optical flow velocity difference, and vehicle heading angle. It then uses the abnormal values of the three core execution dimensions—vehicle braking, speed control, and steering control—to infer whether the attack has truly breached the target vehicle's defenses. Furthermore, the testing module integrates the abnormal values of braking, speed control, and steering behavior into an attack confidence score, enabling the attack confidence score to comprehensively reflect the overall effect of the multimodal collaborative attack.
[0024] Secondly, this application provides a method for testing the safety of an autonomous driving system, applied to the autonomous driving system safety testing apparatus as described in the first aspect; the method includes: applying a multidimensional attack signal to a multidimensional sensor based on the perception parameter values of the core operating parameters of the multidimensional sensor; and sending a test command after applying the multidimensional attack signal; wherein the multidimensional sensor is multiple sensors in the target autonomous driving system of the target vehicle; in response to the test command, observing the driving video stream of the target vehicle under the multidimensional attack signal; and determining the anti-attack performance of the autonomous driving system based on the driving video stream.
[0025] In one possible implementation, applying a multidimensional attack signal to a multidimensional sensor includes: determining sensing parameter values; determining the model information of the multidimensional sensor based on the sensing parameter values; determining the multidimensional attack signal of the multidimensional sensor based on the model information; and applying the multidimensional attack signal to the multidimensional sensor.
[0026] In one possible implementation, the model information of the multi-dimensional sensor is determined based on the sensing parameter values, including: determining the model information of the light wave detection sensor based on the sensing parameter values of the core operating parameters of the sensor parameter library and the light wave detection sensor; wherein, the sensor parameter library includes the reference parameter values of the core operating parameters of each sensor in the sensor dataset.
[0027] In one possible implementation, the model information of the multi-dimensional sensor is determined based on the perception parameter values, including: determining the model information of the visual perception sensor based on the factory model of the visual perception sensor in the target vehicle.
[0028] In one possible implementation, determining the multidimensional attack signal of a multidimensional sensor based on model information includes: determining the attack value of the core operating parameter of the multidimensional sensor based on a mapping relationship set and model information; determining the multidimensional attack signal of the multidimensional sensor based on the attack value; wherein, the mapping relationship set includes the baseline attack value of the core operating parameter of each sensor model in the sensor model set; the attack value of the core operating parameter of any sensor is the configuration value of the core operating parameter in the attack signal of any sensor.
[0029] In one possible implementation, the multidimensional sensor includes a light wave detection sensor and a visual perception sensor. Based on a mapping set and model information, the attack value of the core operating parameters of the multidimensional sensor is determined, including: for a target sensor in the multidimensional sensor, a corrected attack value of the core operating parameters of the target sensor is determined based on a first parameter value, a second parameter value, and the absolute parameter difference between the first parameter value and the second parameter value; wherein, the first parameter value is the perceived parameter value of the core operating parameters of the target sensor; the second parameter value is the attack value of the core operating parameters of the target sensor; when the target sensor is a visual perception sensor, the first parameter value is equal to the second parameter value by default.
[0030] In one possible implementation, the target sensor is each of the multi-dimensional sensors; applying a multi-dimensional attack signal to the multi-dimensional sensors includes: applying an attack signal to the target sensor in response to an attack command; wherein the attack command includes the attack signal corresponding to the target sensor.
[0031] In one possible implementation, applying a multidimensional attack signal to a multidimensional sensor includes: in response to a test command, sending a test signal to a target reconnaissance device at a transmission time; the test command instructing the transmission of the test signal to the target reconnaissance device and indicating the transmission time of the test signal; in response to a reconnaissance command, determining an arrival time; the reconnaissance command instructing the arrival time of the reconnaissance test signal to the target reconnaissance device; determining an attack delay of the target sensor based on the transmission time and the arrival time; and applying a multidimensional attack signal to the multidimensional sensor based on the attack delay, thereby causing the multidimensional sensor to be attacked simultaneously.
[0032] In one possible implementation, the method further includes: upon observing that a target vehicle has entered the attack range, determining a trigger command to trigger the generation of a multidimensional attack signal.
[0033] In one possible implementation, the method further includes: determining the attack confidence of the target vehicle based on the driving video stream; prompting the attack module to continue applying the multidimensional attack signal if the attack confidence is greater than a first preset attack confidence; prompting the attack module to increase the attack power of the multidimensional attack signal and continue applying the multidimensional attack signal with increased power if the attack confidence is not greater than the first preset attack confidence but greater than a second preset attack confidence; and prompting the attack module to regenerate the multidimensional attack signal if the attack confidence is not greater than the second preset attack confidence.
[0034] In one possible implementation, determining the attack confidence of the target vehicle based on the driving video stream includes: determining the longitudinal deceleration of the target vehicle body, the optical flow velocity difference, and the heading angle of the vehicle front based on the driving video stream; determining the abnormal braking quantization value, the abnormal speed control quantization value, and the abnormal steering behavior quantization value of the target vehicle based on the longitudinal deceleration of the vehicle body, the optical flow velocity difference, and the heading angle of the vehicle front, respectively; and determining the attack confidence based on the abnormal braking quantization value, the abnormal speed control quantization value, and the abnormal steering behavior quantization value.
[0035] Thirdly, this application provides a vehicle including a target autonomous driving system, the attack resistance performance of which is determined based on the autonomous driving system security testing apparatus as described in the first aspect.
[0036] Fourthly, this application provides an electronic device, including: a processor and a memory, wherein the memory stores at least one computer program, and the at least one computer program is loaded and executed by the processor to implement the method described in the second aspect above and any possible implementation thereof.
[0037] Fifthly, this application provides a computer-readable storage medium that, when the instructions in the computer-readable storage medium are executed by a processor of an electronic device, enables the electronic device to perform the methods described in the second aspect and any possible implementation thereof.
[0038] In a sixth aspect, this application provides a computer program product comprising computer instructions that, when executed on an electronic device, cause the electronic device to perform the method described in the second aspect and any of its possible implementations.
[0039] It should be noted that the technical effects of any of the implementation methods in aspects two through six can be found in the technical effects of the corresponding implementation methods in aspect one, and will not be repeated here.
[0040] It should be understood that the above general description and the following detailed description are exemplary and explanatory only, and do not limit this application. Attached Figure Description
[0041] The accompanying drawings, which are incorporated in and form part of this specification, illustrate embodiments consistent with this application and, together with the description, serve to explain the principles of this application, and do not constitute an undue limitation of this application.
[0042] Figure 1 This is a schematic diagram of the structure of a safety testing device for an autonomous driving system, as shown in an embodiment of this application. Figure 2 This is a schematic diagram of the structure of an attack module shown in an embodiment of this application; Figure 3 This is a schematic diagram of the structure of another safety testing device for an autonomous driving system shown in the embodiments of this application; Figure 4 This is a schematic diagram illustrating a safety testing process for an autonomous driving system according to an embodiment of this application; Figure 5 This is a schematic diagram illustrating another safety testing process for an autonomous driving system, as shown in an embodiment of this application. Figure 6 This is a block diagram illustrating an electronic device according to an embodiment of this application. Detailed Implementation
[0043] To enable those skilled in the art to better understand the technical solutions of this application, the technical solutions in the embodiments of this application will be clearly and completely described below with reference to the accompanying drawings.
[0044] It should be noted that the terms "first," "second," etc., used in the specification, claims, and accompanying drawings of this application are used to distinguish similar objects and are not necessarily used to describe a specific order or sequence. It should be understood that such data can be interchanged where appropriate so that the embodiments of this application described herein can be implemented in orders other than those illustrated or described herein. The embodiments described in the following exemplary embodiments do not represent all embodiments consistent with this application. Rather, they are merely examples of apparatuses and methods consistent with some aspects of this application as detailed in the appended claims.
[0045] In the embodiments of this application, the words "exemplary," "for example," or "for instance" are used to indicate that something is an example, illustration, or description. Any embodiment or design described as "exemplary," "for example," or "for instance" in the embodiments of this application should not be construed as being more preferred or advantageous than other embodiments or designs. Specifically, the use of the words "exemplary," "for example," or "for instance" is intended to present the relevant concepts in a specific manner.
[0046] The technical solutions of the embodiments of this application will be described below with reference to the accompanying drawings. Obviously, the described embodiments are only some embodiments of this application, and not all embodiments.
[0047] The autonomous driving system safety testing device provided in this application embodiment is used to test the autonomous driving system of a target vehicle. The vehicle can also be referred to as a vehicle, mobile carrier, electric vehicle (EV), hybrid electric vehicle (HEV), plug-in hybrid electric vehicle (PHEV), fuel cell vehicle (FCV), autonomous vehicle, intelligent and connected vehicle (ICV), driverless vehicle, etc.
[0048] In this application embodiment, the vehicle can be a sedan, bus, sport utility vehicle (SUV), truck, special vehicle, driverless taxi, intelligent connected bus, autonomous logistics vehicle, electric truck, etc. In addition, the method is also applicable to other mobile vehicles equipped with vehicle communication terminals, such as tricycles, two-wheeled vehicles, trains and other transportation devices that carry people or goods, or other types of vehicles powered by power batteries, etc. This application does not impose specific limitations on these.
[0049] Please see Figure 1 , Figure 1 This is a schematic diagram illustrating the structure of a safety testing device for an autonomous driving system according to an embodiment of this application. The device includes an attack module 11 and a testing module 12. The attack module 11 and the testing module 12 can communicate with each other via wired or wireless means; this embodiment does not impose any limitations on this.
[0050] It should be understood that the specific implementation of the attack module 11 in this application embodiment is not limited. The attack module 11 includes at least one of fixed attack devices, mobile attack devices, and vehicle-mounted attack devices. Technicians can deploy the attack module 11 on both sides of the road, traffic sign poles, temporary test vehicles, or handheld portable carriers according to different test scenario requirements to achieve multi-dimensional attack tests on different target vehicles.
[0051] In some embodiments, because fixed attack devices can provide stable attack signal output, they are suitable for fixed-point testing scenarios (such as closed test fields or fixed road test sections) and can be disguised as roadside facilities such as road warning signs, guardrails, and traffic sign poles to achieve concealed deployment and reduce interference with normal traffic flow. Therefore, as a feasible implementation method, in order to meet the needs of long-term and continuous security testing, attack module 11 is a fixed attack device.
[0052] For example, when the attack module 11 is a fixed attack device, the attack module 11 can be disguised as a road warning sign, road guardrail, traffic signal pole or roadside unit (RSU). Its outer shell is reserved with light transmission holes and signal transmission holes to ensure normal transmission and reception of attack signals. At the same time, it integrates various attack sub-modules and power supply units to achieve independent operation.
[0053] In this embodiment of the application, when the attack module 11 is in operation, it can apply a multidimensional attack signal to the multidimensional sensor based on the perception parameter value of the core working parameters of the multidimensional sensor.
[0054] Multi-dimensional sensors refer to multiple sensors within the target vehicle's autonomous driving system. These sensors can include LiDAR, vision cameras, millimeter-wave radar, and ultrasonic sensors. By simultaneously applying attack signals to multiple types of sensors, a real-world multimodal cooperative attack scenario can be simulated, effectively verifying the robustness of the autonomous driving fusion perception system.
[0055] For example, the core operating parameters may include at least one of the following: the operating wavelength, scanning frequency, and pulse width of the lidar; the image acquisition frame rate, exposure time, and dynamic range of the vision camera; the operating frequency band and modulation method of the millimeter-wave radar; and the operating frequency of the ultrasonic sensor. The attack module 11 can collect the perceived parameter values of the above-mentioned core operating parameters in real time through non-contact reconnaissance or obtain them through a preset parameter library.
[0056] As another feasible implementation, the attack module 11 may include a lidar attack submodule, a camera attack submodule, a millimeter-wave attack submodule, and an ultrasonic attack submodule.
[0057] The LiDAR attack submodule is used to apply interference signals to the LiDAR of the target vehicle. The interference signals include at least one of electromagnetic interference signals and pulsed laser interference signals. The camera attack submodule is used to apply light interference signals to the visual camera of the target vehicle. The light interference signals include at least one of visible light interference signals and near-infrared light interference signals. The millimeter-wave attack submodule is used to apply radio frequency interference signals to the millimeter-wave radar of the target vehicle. The ultrasonic attack submodule is used to apply acoustic interference signals to the ultrasonic sensor of the target vehicle.
[0058] For example, the multidimensional attack signal is an adaptive attack signal dynamically generated by the attack module 11 based on the perceived parameter values. For instance, when the attack module 11 detects that the target vehicle's lidar operates at a wavelength of 905 nanometers (nm) and a scanning frequency of 20 Hertz (Hz), the attack module 11 can generate a pulsed laser interference signal with a wavelength in the range of 903nm to 907nm and a pulse frequency in the range of 19Hz to 21Hz to achieve precise interference with the target lidar.
[0059] In one possible implementation, after applying the multidimensional attack signal, the attack module 11 is also used to send a test command to the test module 12. The test module, in response to the test command, observes the driving video stream of the target vehicle under the multidimensional attack signal.
[0060] The test instruction may include at least one of the following parameters: attack start timestamp, attack duration, attack signal type, and attack strength, so that the test module 12 can synchronously start observation and recording according to the test instruction.
[0061] In one possible implementation, test module 12 is used to determine the attack resistance performance of the autonomous driving system based on the driving video stream.
[0062] Among them, the anti-attack performance is a comprehensive indicator used to characterize the ability of an autonomous driving system to maintain safe driving capability and the accuracy of perception and decision-making when subjected to interference from multi-dimensional attack signals. The higher the anti-attack performance, the stronger the autonomous driving system's ability to resist multi-dimensional attack signals, and the more it can maintain normal perception, decision-making, and control functions under attack conditions, thereby ensuring driving safety.
[0063] Specifically, the test module 12 can analyze the driving video stream using target detection and trajectory tracking algorithms to extract the changes in the target vehicle's driving state before and after the attack. Then, based on these changes, the test module can determine the anti-attack performance of the target vehicle's autonomous driving system.
[0064] The change in driving status includes at least one of the following: change in speed, change in acceleration, change in lateral offset, and change in braking behavior.
[0065] For example, the testing module 12 can use the normal driving state before the attack as a baseline to calculate the behavioral anomaly increment after the attack. The behavioral anomaly increment may include at least one of the emergency braking anomaly increment, speed control anomaly increment, and steering behavior anomaly increment. The testing module 12 can obtain the overall attack confidence score by weighted summation based on the behavioral anomaly increments. The overall attack confidence score is used to characterize the effectiveness of the multi-dimensional attack signal in interfering with the target autonomous driving system.
[0066] In one possible implementation, the testing module 12 is also used to generate a test report based on the overall attack confidence level. The test report includes at least one evaluation metric among attack success rate, attack duration, target vehicle response latency, and system recovery time. The test report can be used to evaluate the anti-attack performance level of the target autonomous driving system and provide data support for the iterative upgrade of the defense algorithm.
[0067] It should be pointed out that, Figure 1 The structure shown does not constitute a limitation on the safety testing device for autonomous driving systems. The safety testing device for autonomous driving systems may include fewer or more components than shown, or combine certain components, or have different component arrangements. This application embodiment does not impose any limitations in this regard.
[0068] As can be seen, in this embodiment, the attack module can simultaneously apply attack signals to multiple sensors in the target autonomous driving system based on the core operating parameters of each sensor. This multi-dimensional attack method can break through the security redundancy mechanism established by cross-validation in multi-sensor fusion perception algorithms, allowing the attack effect to be transmitted to the decision-making and planning layer of the target vehicle and ultimately manifest as abnormal changes in vehicle driving behavior. This effectively verifies the true vulnerability of the fusion perception architecture under cooperative interference conditions. Simultaneously, the test module directly observes the driving video stream in physical space and determines the anti-attack performance accordingly. Compared to the method of intruding into the vehicle system to read internal logs, this not only avoids data interface incompatibility issues caused by vehicle model differences but also avoids uncontrollable risks to the normal driving safety of the target vehicle, providing a reliable testing basis for the iterative upgrade of autonomous driving defense algorithms.
[0069] In some embodiments, such as Figure 2 As shown, the attack module 11 may include: a perception and reconnaissance unit 111, a generation unit 112, and an attack unit 113. The generation unit 112 can be communicatively connected to both the perception and reconnaissance unit 111 and the attack unit 113. To generate a multi-dimensional attack signal, the attack module can perform the following steps through the perception and reconnaissance unit, the generation unit, and the attack unit: Step 1: The perception and reconnaissance unit 111 is used to determine the perception parameter values and send the perception parameter values to the generation unit.
[0070] For example, the sensing and reconnaissance unit 111 may adopt a non-contact reconnaissance mode, and incorporate at least one of the following: light wave detection type sensor reconnaissance subunit and visual perception type sensor, to collect the core operating parameters of the multi-dimensional sensor in real time.
[0071] The optical wave detection sensor reconnaissance subunit may include at least one of a lidar reconnaissance component, a millimeter-wave radar reconnaissance component, and an ultrasonic sensor reconnaissance component. The lidar reconnaissance component can be used to acquire core operating parameters of the target vehicle's lidar, such as operating wavelength, scanning frequency, pulse width, and pulse repetition period. For example, the lidar reconnaissance component can employ an avalanche photodiode array in conjunction with a narrowband filter component, utilizing a high-speed acousto-optic tunable filter to perform rapid spectral analysis of the light signal emitted by the target lidar, and locking the operating wavelength through a peak detection algorithm; simultaneously, a high-speed timing circuit is used to capture the pulse sequence, and the periodic envelope characteristics of the pulse sequence are analyzed through an autocorrelation algorithm to determine the lidar's scanning frequency and pulse repetition period.
[0072] Millimeter-wave radar reconnaissance components are used to acquire core operating parameters of the target vehicle's millimeter-wave radar, such as operating frequency band, modulation method, sweep bandwidth, and transmit power. For example, a millimeter-wave radar reconnaissance component can use a broadband superheterodyne radio frequency reconnaissance receiver as its core device. Its receiving frequency band covers the mainstream operating frequency band of vehicle-mounted millimeter-wave radar. It intercepts the signal transmitted by the target millimeter-wave radar through a high-gain directional antenna, and sends the radio frequency signal to a digital signal processor for fast Fourier transform spectrum analysis to determine the operating frequency band, modulation method, and sweep bandwidth.
[0073] The ultrasonic sensor reconnaissance component is used to collect the core operating parameters of the ultrasonic sensor of the target vehicle, such as operating frequency, pulse repetition period, and emitted sound pressure level.
[0074] The visual perception sensor reconnaissance subunit may include an observation camera and an image recognition module. The observation camera is used to acquire external images of the target vehicle, and the image recognition module is used to perform target detection and recognition on the external images to help determine the vehicle model, sensor configuration information, and the installation location and appearance characteristics of the visual perception sensor (e.g., a visual camera). The observation camera can be installed on high poles on both sides of the road or inside the camouflaged shell of the attack module, and its acquisition angle can be adjusted according to testing requirements, including at least one of a top-down view, a side view, and a rear-view view.
[0075] In one possible implementation, after completing reconnaissance, the perception and reconnaissance unit 111 can format and encapsulate the collected perception parameter values and send them to the generation unit 112 via a data transmission interface. The perception parameter values can be transmitted in the form of structured data, including sensor type identifier, parameter name, parameter value, acquisition timestamp, and reconnaissance confidence level, so that the generation unit 112 can accurately determine the model information of the multidimensional sensor based on the perception parameter values and generate the corresponding multidimensional attack signal.
[0076] Step 2: Generation unit 112 is used to determine the model information of the multi-dimensional sensor based on the sensing parameter values.
[0077] In one possible implementation, the generation unit 112 may include a first determining subunit. The first determining subunit is used to determine the model information of the light wave detection sensor based on the sensor parameter library and the sensing parameter values of the core operating parameters of the light wave detection sensor.
[0078] The sensor parameter library includes baseline parameter values for the core operating parameters of each sensor in the sensor dataset. For example, the sensor parameter library is a pre-built structured parameter library containing standard characteristic values of the core operating parameters of various automotive optical wave detection sensors (such as LiDAR, millimeter-wave radar, and ultrasonic sensors) from mainstream manufacturers. Taking LiDAR as an example, the parameters stored in the sensor parameter library may include the operating wavelength, scanning frequency, scanning method (mechanical, hybrid solid-state, or solid-state), field of view (horizontal and vertical field of view), angular resolution, detection range, pulse width, and pulse repetition frequency of each LiDAR model. Taking millimeter-wave radar as an example, the parameters stored in the sensor parameter library may include the operating frequency band, modulation method, sweep bandwidth, sweep period, transmit power, and antenna configuration of each millimeter-wave radar model. Taking ultrasonic sensors as an example, the parameters stored in the sensor parameter library may include the operating frequency, pulse repetition period, transmitted sound pressure level, received sensitivity, and detection angle of each ultrasonic sensor model.
[0079] As a feasible implementation method, after receiving the real-time operating parameters of the target optical wave detection sensor collected by the sensing and reconnaissance unit 111, the first determining subunit can extract the feature vector of the real-time operating parameters and perform similarity matching with the standard feature vector of each model in the sensor parameter library to determine the model information of the target sensor.
[0080] For example, the feature vector extracted by the first determined subunit may include dimensions such as operating wavelength, scanning frequency, and pulse width (taking LiDAR as an example). Similarity matching can employ a cosine similarity algorithm, and this application does not impose specific limitations on this.
[0081] For example, when the perception and reconnaissance unit 111 detects that the target lidar has an operating wavelength of 905nm, a scanning frequency of 20Hz, and a pulse width of 5 nanoseconds (ns), the first determination subunit extracts the feature vector [905, 20, 5] and performs cosine similarity calculations with the standard feature vectors of each model in the sensor parameter library. If the similarity with the standard feature [905, 20, 5] of model A reaches 100%, the target lidar is determined to be model A. If the similarity with the standard feature [1550, 10, 8] of model B is only 15%, model B is excluded. When the similarity with all known models is less than 80%, it is determined to be an unknown model, and the default attack parameters are loaded.
[0082] Alternatively, similarity matching can also employ other distance metrics such as Euclidean distance, Manhattan distance, or Mahalanobis distance, and this application embodiment does not impose any limitations on this.
[0083] Furthermore, after completing the model matching, the first determining subunit can send the determined model information to the generating subunit, so that the generating subunit can search for the corresponding benchmark attack value from the mapping relationship set based on the model information, thereby generating an attack signal against the optical wave detection sensor.
[0084] In one possible implementation, the generation unit 112 may further include a second determining subunit. The second determining subunit is used to determine the model information of the visual perception sensor based on its manufacturer's model number in the target vehicle. Since visual perception sensors (e.g., visual cameras) are typically deployed externally to the vehicle (e.g., behind the windshield, below the rearview mirror, or around the vehicle body), their model information can be obtained through vehicle appearance identification (e.g., the physical dimensions of the camera module, lens layout, and nameplate markings) or by reading it through an on-board diagnostic interface. Therefore, the second determining subunit can directly determine the specific model of the visual perception sensor based on its manufacturer's model number information without requiring parameter matching.
[0085] For example, the second determining subunit can determine the manufacturer's model of the visual perception sensor by observing the image of the target vehicle captured by the camera and recognizing the model identification text on the camera module. Alternatively, the second determining subunit can determine the model information of the visual perception sensor by recognizing the vehicle model of the target vehicle and based on the configuration information corresponding to the vehicle model.
[0086] Furthermore, after determining the model information of the visual perception sensor, the second determining subunit also sends the model information to the generating subunit so that the generating subunit can search for the corresponding baseline attack value from the mapping relationship set based on the model information, thereby generating an attack signal against the visual perception sensor.
[0087] Step 3: Generation unit, used to determine the multidimensional attack signal of the multidimensional sensor based on the model information, and send the multidimensional attack signal to the attack unit.
[0088] In one possible implementation, the generation unit 112 includes a generation subunit. Both the first determining subunit and the second determining subunit are communicatively connected to the generation subunit. The generation subunit is used to determine the attack values of the core operating parameters of the multidimensional sensor based on the mapping relationship set and the model information uploaded by the first and second determining subunits; and to determine the multidimensional attack signal of the multidimensional sensor based on the attack values.
[0089] The mapping set includes the baseline attack values of the core operating parameters for each sensor model in the sensor model set. The attack value of the core operating parameter of any sensor is the configuration value of the core operating parameter in the attack signal of that sensor. The mapping set is a pre-constructed structured attack parameter mapping table, including the attack parameters corresponding to each sensor model, such as attack frequency band, initial power, pulse width, modulation method, interference signal waveform, and other attack configurations.
[0090] For example, for lidar model A, the baseline attack values stored in the mapping relationship include: interference wavelength offset ranging from -2nm to +2nm, interference pulse frequency offset ranging from -1Hz to +1Hz, and pulse width of 5ns. After the generation subunit obtains the above baseline attack values from the table based on the target sensor model A, it can determine the core operating parameter configuration of the attack signal for that lidar.
[0091] As a feasible implementation method, multidimensional sensors include optical wave detection sensors and visual perception sensors. The generation subunit is specifically used to: for the target sensor in the multidimensional sensor, determine the corrected attack value of the target sensor's core operating parameters based on the first parameter value, the second parameter value, and the absolute parameter difference between the first and second parameter values.
[0092] The first parameter value is the perceived parameter, a core operating parameter of the target sensor. The second parameter value is the attack value, also a core operating parameter of the target sensor. When the target sensor is a visual perception sensor, the first parameter value is equal to the second parameter value by default.
[0093] For example, the formula for calculating the modified attack value is as follows: ; .
[0094] in, To correct the attack value. This is the value of the first parameter. This is the value of the second parameter. This is the parameter deviation correction value. , These are the weighting coefficients.
[0095] For example, when the perception and reconnaissance unit 111 detects that the target lidar's operating wavelength is 903nm (standard value is 905nm) and its scanning frequency is 19.8Hz (standard value is 20Hz), the first determination subunit determines the target lidar model as A. The generation subunit looks up the interference wavelength offset in the reference attack parameters of model A from the mapping relationship set and finds it to be +2nm (i.e., the reference attack wavelength is 907nm). Then, the generation subunit calculates the corrected attack wavelength as follows: .
[0096] That is, the generated sub-unit determines the optimal attack wavelength after correction as 903.8nm, instead of directly using the reference attack wavelength of 907nm or the reconnaissance wavelength of 903nm, in order to achieve a precise attack on the target lidar.
[0097] In one possible implementation, the multidimensional attack signal includes lidar attack signals, camera attack signals, millimeter-wave attack signals, and ultrasonic attack signals.
[0098] For example, a lidar attack signal can be a pulsed laser interference signal with a wavelength close to the target lidar's operating wavelength (within ±2nm), used to inject false point clouds or cause point cloud defects; a camera attack signal can be a dual-band visible light and near-infrared light interference signal, combined with polarization adjustment, used to cause global overexposure of the camera or failure of feature extraction. A millimeter-wave attack signal can be a radio frequency interference signal in the corresponding frequency band, used to suppress or deceive the target millimeter-wave radar. An ultrasonic attack signal can be a sound wave interference signal of a specific frequency, used to interfere with the ranging function of the target's ultrasonic sensor.
[0099] Step 4: Attack unit, used to apply multidimensional attack signals to the multidimensional sensor.
[0100] In one possible implementation, the attack unit 113 includes a target sensor attack subunit corresponding to the target sensor. The target sensor is each sensor in the multi-dimensional sensor. The generation unit 112 is specifically used to send attack commands to the target sensor attack subunit.
[0101] The attack command includes the attack signal corresponding to the target sensor (e.g., interference waveform parameters, transmission power, pulse width, modulation method, etc.). The target sensor attack subunit is used to apply the attack signal to the target sensor in response to the attack command.
[0102] For example, the attack unit 113 may include at least one of a lidar attack subunit, a camera attack subunit, a millimeter-wave attack subunit, and an ultrasonic attack subunit. The lidar attack subunit is used to apply pulsed laser interference signals or electromagnetic interference signals to the lidar of the target vehicle; the camera attack subunit is used to apply visible light and / or near-infrared light interference signals to the visual camera of the target vehicle; the millimeter-wave attack subunit is used to apply radio frequency interference signals of the corresponding frequency band to the millimeter-wave radar of the target vehicle; and the ultrasonic attack subunit is used to apply acoustic interference signals to the ultrasonic sensor of the target vehicle. Each attack subunit can independently or collaboratively apply attack signals to the corresponding target sensor according to the attack command sent by the generation unit 112.
[0103] In one possible implementation, prior to step 4, the generation unit 112 further performs an attack delay calibration operation. Specifically, the generation unit 112 also includes a coordination subunit and a reconnaissance subunit. The coordination subunit is communicatively connected to both the reconnaissance subunit and the target sensor attack subunit. The reconnaissance subunit and the target sensor attack subunit are also communicatively connected.
[0104] As one feasible implementation, the cooperative subunit is used to send test commands to the target sensor attack subunit and reconnaissance commands to the reconnaissance subunit. The test command instructs the transmission of a test signal to the target reconnaissance device (e.g., the lidar receiving window of a target vehicle or a specific reflective surface of the vehicle body), and indicates the timing of the test signal transmission. The reconnaissance command instructs the arrival time of the reconnaissance test signal at the target reconnaissance device.
[0105] The target sensor attack subunit is used to send a test signal (e.g., a short-pulse laser or radio frequency pulse) to the target reconnaissance device at the transmission time in response to a test command. The reconnaissance subunit (e.g., an avalanche photodiode detector or a radio frequency reconnaissance receiver) is used to determine the arrival time of the test signal in response to a reconnaissance command and return the arrival time to the coordination subunit.
[0106] The collaborative subunit is also used to determine the attack delay of the target sensor based on the transmission time and arrival time, and send the attack delay to the attack unit 113 so that the attack unit 113 applies a multidimensional attack signal to the multidimensional sensor based on the attack delay, thereby causing the multidimensional sensor to be attacked at the same time.
[0107] For example, the collaborative subunit can use a synchronous triggering marking method for timing calibration. Before the attack is initiated, the collaborative subunit simultaneously sends a calibration trigger signal to all attack subunits. The narrow pulse marking signals output by each attack subunit are uniformly received by the reconnaissance subunit, and the arrival time difference of each marking signal is measured to obtain the actual time delay difference. Then, based on the measured time delay difference, the collaborative subunit dynamically adjusts the pre-trigger offset of each attack subunit, using the attack subunit with the fastest transmission as the benchmark, and adding corresponding delay compensation to other attack subunits to complete the timing calibration. Through the above calibration, the time delay difference of multi-module attacks can be eliminated, ensuring multi-sensor synchronization distortion, making the multi-sensor fusion algorithm free of verification redundancy space, and improving the attack effect.
[0108] In one possible implementation, the autonomous driving system safety testing device can be deployed in a concealed location on the roadside. The autonomous driving system safety testing device also includes a trigger module. The trigger module is communicatively connected to the attack module 11. When the trigger module observes a target vehicle entering the attack range, it sends a trigger command to the attack module 11 to trigger the attack module 11 to generate a multi-dimensional attack signal.
[0109] For example, the triggering module may include at least one of a geomagnetic sensor, an infrared beam sensor, a lidar trigger, or a visual recognition trigger, for detecting whether a target vehicle has entered a preset attack area (e.g., within a range of 10 to 100 meters from the attack module).
[0110] In another possible implementation, when the triggering module detects that the target vehicle has left the effective attack range, the attack module immediately terminates the attack signal output and enters a low-power standby state, waiting for the next attack to be triggered.
[0111] For example, through the above-mentioned standby mechanism, the autonomous driving system safety testing device can realize unattended automated continuous testing. When the target vehicle enters the attack range, the attack is automatically triggered and the test evaluation is performed. When the target vehicle leaves, it automatically enters the standby state to save energy. The cyclic testing of multiple target vehicles can be completed without human intervention.
[0112] In one possible implementation, after the attack unit 113 applies a multidimensional attack signal to the multidimensional sensor, the attack module 11 sends a test command to the test module 12. In response to the test command, the test module 12 observes the driving video stream of the target vehicle under the multidimensional attack signal and determines the anti-attack performance of the autonomous driving system based on the driving video stream.
[0113] Specifically, test module 12 is used to determine the attack confidence level of the target vehicle based on the driving video stream. The attack confidence level is used to characterize the effectiveness of the multi-dimensional attack signal in interfering with the target autonomous driving system.
[0114] In one possible implementation, the test module 12 is also used to execute the following feedback control strategy based on the attack confidence level: (1) If the attack confidence level is greater than the first preset attack confidence level, the attack module 11 is prompted to continue to apply the multidimensional attack signal (i.e., maintain the current attack power and timing parameters to ensure the stability of the attack effect).
[0115] (2) If the attack confidence is not greater than the first preset attack confidence but greater than the second preset attack confidence, the attack module is prompted to increase the attack power of the multidimensional attack signal and continue to apply the multidimensional attack signal with increased power.
[0116] (3) If the attack confidence level is not greater than the second preset attack confidence level, prompt the attack module to regenerate the multidimensional attack signal.
[0117] Optionally, the first preset attack confidence level and the second preset attack confidence level can be set according to actual needs. For example, the first preset attack confidence level can be 0.8, and the second preset attack confidence level can be 0.4. This application does not impose specific limitations in this regard.
[0118] Optionally, the testing module 12 can recalculate the attack confidence level every preset period. When the overall attack confidence level remains greater than the first preset attack confidence level for multiple consecutive detection periods, it enters a continuous attack maintenance state, where the attack power remains stable with only minor adjustments. The preset period can be set according to actual needs. For example, the preset period can be 100 milliseconds. This application does not impose specific limitations on this.
[0119] In one possible implementation, when test module 12 instructs attack module 11 to increase attack power, the attack power adopts a gradual boost mode using an S-shaped curve (Sigmoid curve). The formula for power variation over time is as follows: .
[0120] in, Let t be the attack power at time t. denoted as Target attack power. k is the rate-of-rise control coefficient (slope of the control curve). The center point of the curve (corresponding to the moment when the power rises to 50% of the target value). The S-curve has a smooth transition characteristic with a slow initial voltage increase (e.g., power increases to 20% of the target value), a rapid increase in the middle stage (e.g., increases to 80% of the target value), and a slow approach to the target value at the end stage (e.g., reaching the target power).
[0121] By adopting an S-curve gradual boost mode, the attack signal is not applied in a step-like abrupt manner, but rather gradually enhanced in a smooth and progressive manner. This can effectively prevent the target vehicle's abnormal detection mechanism from triggering a security redundancy alarm due to signal abrupt changes, thereby achieving a traceless, continuous, and covert attack effect.
[0122] In one possible implementation, to determine the attack confidence level, the testing module 12 can be used to determine the target vehicle's longitudinal deceleration, optical flow velocity difference, and heading angle based on the driving video stream. Then, based on the longitudinal deceleration, optical flow velocity difference, and heading angle, the target vehicle's braking anomaly quantification value, speed control anomaly quantification value, and steering behavior anomaly quantification value are determined, respectively. Furthermore, based on the braking anomaly quantification value, speed control anomaly quantification value, and steering behavior anomaly quantification value, the attack confidence level is determined.
[0123] It is understandable that the final control output of an autonomous driving system is directly reflected in the coordinated control of the vehicle's longitudinal (speed / braking) and lateral (steering) directions. When a multi-dimensional attack signal successfully breaks through its fusion perception redundancy verification mechanism, the interference to the target vehicle's perception layer may lead to abnormal behavior at the target vehicle's execution layer. Therefore, inferring the attack effect by observing the vehicle's actual driving behavior is the most direct and reliable evaluation path.
[0124] Among these, longitudinal deceleration refers to the rate at which the vehicle's speed decreases in the direction of travel; an abnormal increase in this value directly reflects whether the attack triggered an incorrect emergency braking decision. Optical flow velocity difference refers to the degree of difference in vehicle speed between different regions, calculated by analyzing the motion vector field of image feature points in the video stream; abnormal changes in optical flow velocity difference reflect whether the attack caused disturbances in visual odometry or speed estimation. The vehicle heading angle is the angle between the vehicle's longitudinal axis and a preset reference direction on the ground (such as lane line direction); abnormal deflection or jitter in this angle reflects whether the attack caused deviations in lane keeping or steering control.
[0125] For example, the attack confidence level satisfies the following formula: ; ; ; .
[0126] in, This is the quantification value for braking anomalies. This is the quantization value for speed control anomalies. This is a quantitative value for abnormal steering behavior. , , is the weighting coefficient. C is the attack confidence level. This refers to the longitudinal deceleration of the vehicle body. This is due to the difference in optical flow velocity. This is the heading angle of the train.
[0127] As can be seen, the perception and reconnaissance unit of this application can determine the perception parameter values of the core operating parameters of the sensor, and the generation unit can determine the specific model information of the multi-dimensional sensor. Then, based on the model information, the corresponding attack signal is matched and executed by the attack unit. This makes the attack parameters no longer dependent on the factory-preset static mapping table, but dynamically acquires the actual operating characteristics of the target sensor before each test. Even if the actual parameters of the same model sensor deviate due to differences in firmware version, environmental aging, or vehicle configuration, the attack signal can be tracked and adjusted, thereby avoiding attack failure due to parameter mismatch and improving the adaptability of the testing device to different vehicles and different sensor states.
[0128] In some embodiments, such as Figure 3 As shown, Figure 3 The autonomous driving system safety testing device includes a perception and reconnaissance unit, a generation unit, an attack unit, and a concealment and camouflage module. Exemplarily, the attack unit may include a lidar attack subunit, a camera attack subunit, a millimeter-wave attack subunit, and an ultrasonic attack subunit. This application does not impose specific limitations on this.
[0129] The perception and reconnaissance unit is used to non-contactly collect core operating parameters of the multi-dimensional sensors on the target autonomous vehicle to determine the perception parameter values of the target sensors. These collected perception parameter values are then sent to the generation unit to provide a data basis for the generation of subsequent attack signals. Simultaneously, the perception and reconnaissance unit also includes an observation camera to collect video streams of the target vehicle's movement after interference.
[0130] The generation unit receives the sensing parameter values sent by the sensing and reconnaissance unit, determines the model information of the multi-dimensional sensor based on the sensor parameter library and the sensing parameter values, and searches for the corresponding benchmark attack value from the preset mapping relationship set according to the model information to generate a multi-dimensional attack signal.
[0131] The attack unit receives multi-dimensional attack signals from the generation unit and applies corresponding physical attack signals to the multi-dimensional sensors of the target vehicle. Specifically, the lidar attack subunit applies pulsed laser interference or electromagnetic interference signals to the lidar of the target vehicle; the camera attack subunit applies visible light and / or near-infrared light interference signals to the visual camera of the target vehicle; the millimeter-wave attack subunit applies radio frequency interference signals in the corresponding frequency band to the millimeter-wave radar of the target vehicle; and the ultrasonic attack subunit applies acoustic interference signals to the ultrasonic sensors of the target vehicle. Each attack subunit can independently or collaboratively apply attack signals to its corresponding target sensor according to the attack commands sent by the generation unit.
[0132] The concealment and camouflage module is used to disguise the entire or some components of the test device as at least one of the following forms: road warning signs, guardrails, traffic sign poles, vehicle ornaments, or roadside facilities. It has pre-reserved mounting slots that match each attack subunit and has light-transmitting holes to ensure that the sensor acquisition of the perception and reconnaissance unit and the signal transmission of the attack unit are not obstructed, thus achieving concealed deployment.
[0133] Regarding the above Figure 3 The specific methods by which each module performs its operations in the aforementioned embodiments have been described in detail and will not be elaborated upon here.
[0134] In some embodiments, please refer to Figure 4 The autonomous driving system safety testing method provided in this application embodiment can be implemented by testers using the autonomous driving system safety testing device in a closed test field or selected road test section through the following steps: a1. Deploy the safety testing device for the autonomous driving system and complete the system initialization.
[0135] In one possible approach, testers would place the safety testing equipment for the autonomous driving system in a concealed location on the roadside.
[0136] It should be understood that placing the testing device in a concealed location on the roadside can effectively reduce interference with normal traffic flow, while ensuring that the attack signal can accurately cover the target vehicle's perception area.
[0137] a2. The trigger module detects whether the target vehicle has entered the attack range.
[0138] In one possible implementation, the triggering module sends a trigger command to the attack module upon observing that the target vehicle has entered the effective attack range, thereby inducing the attack module to generate a multi-dimensional attack signal. If the target vehicle has not entered the attack range, the system remains in a low-power standby state, waiting for the next trigger.
[0139] For example, the triggering module may include at least one of a geomagnetic sensor, an infrared beam sensor, a lidar trigger, or a visual recognition trigger, for detecting whether a target vehicle has entered a preset attack area.
[0140] a3. The perception and reconnaissance unit performs adaptive reconnaissance based on perception parameters.
[0141] In one possible implementation, the perception and reconnaissance unit determines the perception parameter values and sends them to the generation unit.
[0142] For example, the perception and reconnaissance unit employs a non-contact reconnaissance mode to collect core operating parameters of the multi-dimensional sensors on the target vehicle in real time. The multi-dimensional sensors are multiple sensors within the target vehicle's autonomous driving system. The perception and reconnaissance unit determines the perception parameter values of the target sensors' core operating parameters, such as operating wavelength, scanning frequency, pulse width, frame rate, and exposure time. The perception and reconnaissance unit also includes an observation camera for acquiring a video stream of the target vehicle's movement after interference.
[0143] It should be understood that the purpose of adaptive reconnaissance of sensing parameters is to dynamically adapt to the sensing characteristics of different types of sensors, so that the attack signal can accurately match the working parameters of the target sensor.
[0144] a4. The generation unit determines the model information of the multi-dimensional sensor and generates a multi-dimensional attack signal.
[0145] In one possible implementation, the generation unit determines the model information of the multidimensional sensor based on the sensing parameter values, determines the multidimensional attack signal of the multidimensional sensor based on the model information, and sends the multidimensional attack signal to the attack unit.
[0146] Specifically, the multidimensional sensor includes a light wave detection sensor, and the generation unit includes a first determining subunit. The first determining subunit determines the model information of the light wave detection sensor based on the sensor parameter library and the sensing parameter values of the core operating parameters of the light wave detection sensor.
[0147] The sensor parameter library includes baseline parameter values for the core operating parameters of each sensor in the sensor dataset. The multi-dimensional sensor also includes a visual perception sensor, and the generation unit includes a second determining subunit. This second determining subunit determines the model information of the visual perception sensor based on its manufacturer's model number in the target vehicle.
[0148] The generation unit also includes a generation subunit, with both the first determination subunit and the second determination subunit communicatively connected to the generation subunit. Based on the mapping relationship set and the model information uploaded by the first and second determination subunits, the generation subunit determines the attack values of the core operating parameters of the multidimensional sensor, and determines the multidimensional attack signal of the multidimensional sensor based on the attack values. The mapping relationship set includes the baseline attack values of the core operating parameters for each sensor model in the sensor model set. The attack value of the core operating parameters of any sensor is the configuration value of the core operating parameters in the attack signal of any sensor.
[0149] For the target sensor in a multi-dimensional sensor, the generation sub-unit determines the corrected attack value for the core operating parameters of the target sensor based on the first parameter value, the second parameter value, and the absolute parameter difference between the first and second parameter values. Here, the first parameter value is the perceived parameter value of the target sensor's core operating parameters, and the second parameter value is the attack value of the target sensor's core operating parameters. When the target sensor is a visual perception sensor, the first parameter value is equal to the second parameter value by default.
[0150] a5. The generation unit performs collaborative timing calibration.
[0151] In one possible implementation, the generation unit further includes a coordination subunit and a reconnaissance subunit. The coordination subunit is communicatively connected to both the reconnaissance subunit and the target sensor attack subunit, and the reconnaissance subunit is also communicatively connected to the target sensor attack subunit.
[0152] The coordinating subunit sends test commands to the target sensor attack subunit and reconnaissance commands to the reconnaissance subunit. The test command instructs the transmission of a test signal to the target reconnaissance device and specifies the transmission time. The reconnaissance command instructs the arrival time of the reconnaissance test signal at the target reconnaissance device. In response to the test commands, the target sensor attack subunit transmits the test signal to the target reconnaissance device at the transmission time. In response to the reconnaissance commands, the reconnaissance subunit determines the arrival time and returns it to the coordinating subunit. Based on the transmission and arrival times, the coordinating subunit determines the attack delay of the target sensor and sends the attack delay to the attack unit, enabling the attack unit to apply a multi-dimensional attack signal to the multi-dimensional sensor based on the attack delay, thereby causing the multi-dimensional sensor to be attacked simultaneously.
[0153] a6. The attack unit applies a multidimensional attack signal to the multidimensional sensor.
[0154] In one possible implementation, the generation unit sends an attack command to the target sensor attack subunit, the attack command including an attack signal corresponding to the target sensor. In response to the attack command, the target sensor attack subunit applies the attack signal to the target sensor.
[0155] a7. The test module observes the driving video stream and determines the attack confidence level.
[0156] In one possible implementation, after the attack unit applies a multidimensional attack signal to the multidimensional sensor, the attack module sends a test command to the test module. In response to the test command, the test module observes the driving video stream of the target vehicle under the multidimensional attack signal. Then, the test module determines the attack confidence level of the target vehicle based on the driving video stream.
[0157] Specifically, the testing module determines the target vehicle's longitudinal deceleration, optical flow velocity difference, and heading angle based on the driving video stream. Then, based on these parameters, it determines the target vehicle's braking anomaly quantification values, speed control anomaly quantification values, and steering behavior anomaly quantification values. Finally, based on these values, the attack confidence level is determined.
[0158] a8. Implement feedback control strategies based on confidence levels.
[0159] In one possible implementation, the testing module executes the following feedback control strategy based on the attack confidence level: If the attack confidence level is greater than the first preset attack confidence level, the test module prompts the attack module to continue applying multi-dimensional attack signals, i.e., maintaining the current attack power and timing parameters to ensure stable attack effects. When the overall attack confidence level is greater than or equal to the first preset attack confidence level and remains stable for multiple consecutive detection cycles, it is determined to enter the continuous attack maintenance state, where the power remains stable with only minor adjustments.
[0160] When the attack confidence level is no greater than the first preset attack confidence level but greater than the second preset attack confidence level, the test module prompts the attack module to increase the attack power of the multi-dimensional attack signal and continues to apply the multi-dimensional attack signal with increased power. The attack power adopts a gradual boost mode, which does not apply it in a step-like manner, but gradually increases it in a smooth and progressive manner. This can effectively avoid the target vehicle's anomaly detection mechanism from triggering a safety redundancy alarm due to signal abrupt changes, thereby achieving a traceless, continuous, and covert attack effect.
[0161] If the attack confidence level is not greater than the second preset attack confidence level, the test module prompts the attack module to regenerate the multidimensional attack signal, that is, to end the current attack, restart the perception parameter detection and timing calibration, and trigger the attack again after resetting the attack parameters.
[0162] a9. Detect whether the target vehicle has moved out of the attack range.
[0163] In one possible implementation, when the triggering module detects that the target vehicle has left the effective attack range, the attack module immediately terminates the attack signal output, the attack unit stops working, and the autonomous driving system safety test device enters a low-power standby state, waiting for the next attack trigger.
[0164] It should be understood that, through the aforementioned standby mechanism, the autonomous driving system safety testing device can achieve unattended automated continuous testing: when the target vehicle enters the attack range, the attack is automatically triggered and the test evaluation is performed; when the target vehicle leaves, it automatically enters standby mode to save energy, and can complete the cyclic testing of multiple target vehicles without human intervention.
[0165] a10. Test completed, anti-attack performance determined and test report generated.
[0166] Among them, anti-attack performance is a comprehensive indicator characterizing the ability of a target autonomous driving system to maintain safe driving capability and perception and decision-making accuracy when subjected to interference from multi-dimensional attack signals. Higher anti-attack performance indicates a stronger ability of the autonomous driving system to resist multi-dimensional attack signals, maintaining normal perception, decision-making, and control functions even under attack conditions, thereby ensuring driving safety. Anti-attack performance is quantitatively evaluated using at least one of the following indicators: degree of perception failure, degree of abnormal decision-making behavior, system response time, and system recovery capability after an attack.
[0167] After the test, the testing module generates a test report based on the anti-attack performance. The test report includes at least one of the following: basic information about the target vehicle, attack parameter configuration for multi-dimensional attack signals, summary information of the driving video stream, quantitative values of various evaluation indicators, a comprehensive score for anti-attack performance, and test conclusions. The test report is output in text, chart, or visualization format for review by testers or system developers, providing data support for the iterative upgrade of autonomous driving defense algorithms.
[0168] In some embodiments, to enhance the versatility and deployment flexibility of the testing device, the autonomous driving system safety testing device can adopt a modular design. The functional modules communicate with each other through standardized interfaces, allowing for flexible combination and expansion according to different testing needs. Each attack subunit within the attack unit can be selectively activated based on the actual sensor configuration of the target vehicle. For example, when the target vehicle is only equipped with LiDAR and a camera, only the LiDAR and camera attack subunits can be activated, while the millimeter-wave and ultrasonic attack subunits can be disabled to save energy and improve testing efficiency. Test personnel can also monitor and adjust parameters of the testing device in real time through a remote control platform, enabling remote test management.
[0169] In some embodiments, such as Figure 5 As shown, Figure 5 The safety testing process for autonomous driving systems includes: The autonomous driving system safety testing device acquires a sensor parameter library.
[0170] The autonomous driving system safety testing device collects the core operating parameters of the multi-dimensional sensors on the target vehicle in real time to determine the perception parameter values of the multi-dimensional sensors.
[0171] The autonomous driving system safety testing device determines the attack values of the core operating parameters of multi-dimensional sensors based on perception parameter values and sensor parameter libraries.
[0172] The safety testing device for autonomous driving systems determines whether the attack triggering conditions are met.
[0173] The autonomous driving system safety testing device triggers an attack module to generate a multi-dimensional attack signal to attack the multi-dimensional sensors of the target vehicle when the attack triggering conditions are met. If the attack triggering conditions are not met, the device re-evaluates whether the attack triggering conditions are met.
[0174] The autonomous driving system security testing device calculates the attack confidence level.
[0175] The autonomous driving system safety testing device determines the attack confidence level. If the attack confidence level exceeds a first preset attack confidence level, the device prompts the attack module to continue applying multi-dimensional attack signals.
[0176] When the attack confidence level of the autonomous driving system is not greater than the first preset attack confidence level but greater than the second preset attack confidence level, the safety testing device prompts the attack module to increase the attack power of the multi-dimensional attack signal and continues to apply the multi-dimensional attack signal with increased power.
[0177] When the attack confidence level is no greater than the second preset attack confidence level, the autonomous driving system safety testing device prompts the attack module to regenerate the multidimensional attack signal and collects the core working parameters of the multidimensional sensors on the target vehicle in real time to determine the perception parameter values of the multidimensional sensors.
[0178] Among them, the attack power is gradually controlled by amplitude, for example, by using an S-curve gradually increasing boost mode.
[0179] The autonomous driving system security testing device determines whether the target vehicle has left the attack range. If it has left the attack range, the device enters low-power standby mode and terminates the process. If it has not left the attack range, the attack confidence level is recalculated.
[0180] Figure 6 This is a block diagram illustrating an electronic device according to an embodiment of this application. Figure 6 As shown, the electronic device includes, but is not limited to, a processor 601 and a memory 602.
[0181] The aforementioned memory 602 is used to store the executable instructions of the aforementioned processor 601. It is understood that the aforementioned processor 601 is configured to execute instructions to implement the autonomous driving system safety testing method in the above embodiments.
[0182] It should be noted that those skilled in the art will understand that Figure 6 The electronic device structure shown does not constitute a limitation on the electronic device; the electronic device may include, but is not limited to, other electronic devices. Figure 6 This may indicate more or fewer components, or combinations of certain components, or different component arrangements.
[0183] Processor 601 is the control center of the electronic device. It connects various parts of the electronic device via various interfaces and lines. By running or executing software programs and / or modules stored in memory 602, and by calling data stored in memory 602, it performs various functions and processes data, thereby providing overall monitoring of the electronic device. Processor 601 may include one or more processing units. Processor 601 may integrate an application processor and a modem processor. The application processor mainly handles the operating system, user interface, and applications, while the modem processor mainly handles wireless communication. It is understood that the modem processor may not be integrated into processor 601.
[0184] The memory 602 can be used to store software programs and various data. The memory 602 may primarily include a program storage area and a data storage area. The program storage area may store the operating system, application programs required by at least one functional module (such as deterministic components, integrated components, etc.), etc. Furthermore, the memory 602 may include high-speed random access memory, and may also include non-volatile memory, such as at least one disk storage device, flash memory device, or other volatile solid-state storage device.
[0185] In an exemplary embodiment, a computer-readable storage medium including instructions is also provided, such as a memory 602 including instructions, which can be executed by a processor 601 of an electronic device to implement the methods in the above embodiments.
[0186] In actual implementation, Figure 1 The functions of attack module 11 and test module 12 can both be provided by Figure 6 The processor 601 calls the computer program stored in the memory 602 to implement the process. The specific execution process can be found in the description of the method section in the previous embodiment, and will not be repeated here.
[0187] Optionally, the computer-readable storage medium may be a non-transitory computer-readable storage medium, such as a read-only memory (ROM), random access memory (RAM), compact disc read-only memory (CD-ROM), magnetic tape, floppy disk, and optical data storage device. In an exemplary embodiment, this application also provides a computer program product including one or more instructions, which can be executed by the processor 601 of an electronic device to perform the methods in the above embodiments.
[0188] It should be noted that when one or more instructions in the computer-readable storage medium or computer program product are executed by the processor of an electronic device, they implement the various processes of the above method embodiments and achieve the same technical effect as the above method. To avoid repetition, they will not be described again here.
[0189] Through the above description of the embodiments, those skilled in the art can clearly understand that, for the sake of convenience and brevity, only the division of the above functional modules is used as an example. In actual applications, the above functions can be assigned to different functional modules as needed, that is, the internal structure of the device can be divided into different functional modules to complete all or part of the functions described above.
[0190] In the several embodiments provided in this application, it should be understood that the disclosed apparatus and methods can be implemented in other ways. For example, the apparatus embodiments described above are merely illustrative; for instance, the division of modules or units is only a logical functional division, and in actual implementation, there may be other division methods. For example, multiple units or components may be combined or integrated into another apparatus, or some features may be ignored or not executed. Furthermore, the mutual coupling or direct coupling or communication connection shown or discussed may be through some interfaces; the indirect coupling or communication connection between apparatuses or units may be electrical, mechanical, or other forms.
[0191] The units described as separate components may or may not be physically separate. A component shown as a unit can be one or more physical units; that is, it can be located in one place or distributed in multiple different locations. Some or all of the units can be selected to achieve the purpose of this embodiment according to actual needs.
[0192] Furthermore, the functional units in the various embodiments of this application can be integrated into one processing unit, or each unit can exist physically separately, or two or more units can be integrated into one unit. The integrated unit can be implemented in hardware or as a software functional unit.
[0193] If the integrated unit is implemented as a software functional unit and sold or used as an independent product, it can be stored in a readable storage medium. Based on this understanding, the technical solutions of the embodiments of this application, essentially, or the parts that contribute to the prior art, or all or part of the technical solutions, can be embodied in the form of a software product. This software product is stored in a storage medium and includes several instructions to cause a device (which may be a microcontroller, chip, etc.) or processor to execute all or part of the steps of the methods of the various embodiments of this application. The aforementioned storage medium includes various media capable of storing program code, such as USB flash drives, portable hard drives, ROM, RAM, magnetic disks, or optical disks.
[0194] This application provides a computer program product containing instructions that, when run on a computer, cause the computer to perform the methods described in the above method embodiments.
[0195] This application also provides a computer-readable storage medium storing instructions that, when executed on a computer, cause the computer to perform the method in the method flow shown in the above method embodiments.
[0196] The computer-readable storage medium can be, for example, but not limited to, an electrical, magnetic, optical, electromagnetic, infrared, or semiconductor system, apparatus, or device, or any combination thereof. More specific examples of computer-readable storage media (a non-exhaustive list) include: an electrical connection having one or more wires, a portable computer disk, a hard disk, a random access memory, a read-only memory, an erasable programmable read-only memory, a register, a hard disk, an optical fiber, a portable compact disk read-only memory, an optical storage device, a magnetic storage device, or any suitable combination thereof, or any other form of computer-readable storage medium known in the art. An exemplary storage medium is coupled to a processor, enabling the processor to read information from and write information to the storage medium. Of course, the storage medium can also be a component of the processor. The processor and the storage medium can reside in an application-specific integrated circuit (ASIC). In embodiments of this application, the computer-readable storage medium can be any tangible medium containing or storing a program that can be used by or in conjunction with an instruction execution system, apparatus, or device.
[0197] Since the autonomous driving system safety testing device, computer-readable storage medium, and computer program product in the embodiments of this application can be applied to the above methods, the technical effects that can be obtained can also be referred to the above method embodiments. The embodiments of this application will not be repeated here.
[0198] The above are merely specific embodiments of this application, but the scope of protection of this application is not limited thereto. Any changes or substitutions within the technical scope disclosed in this application should be included within the scope of protection of this application. Therefore, the scope of protection of this application should be determined by the scope of the claims.
Claims
1. A safety testing device for an autonomous driving system, characterized in that, The autonomous driving system security testing device includes an attack module and a test module; the attack module and the test module are communicatively connected. The attack module is used to apply a multidimensional attack signal to the multidimensional sensor based on the perception parameter value of the core operating parameters of the multidimensional sensor; and after applying the multidimensional attack signal, send a test command to the test module; wherein the multidimensional sensor is multiple sensors in the target autonomous driving system of the target vehicle; The testing module is used to respond to the test command, observe the driving video stream of the target vehicle under the multidimensional attack signal, and determine the anti-attack performance of the autonomous driving system based on the driving video stream.
2. The safety testing device for an autonomous driving system according to claim 1, characterized in that, The attack module includes: a perception and reconnaissance unit, a generation unit, and an attack unit; the generation unit is communicatively connected to the perception and reconnaissance unit and the attack unit, respectively. The perception and reconnaissance unit is used to determine the perception parameter value and send the perception parameter value to the generation unit; The generation unit is configured to determine the model information of the multidimensional sensor based on the sensing parameter values; determine the multidimensional attack signal of the multidimensional sensor based on the model information; and send the multidimensional attack signal to the attack unit. The attack unit is used to apply the multidimensional attack signal to the multidimensional sensor.
3. The safety testing device for an autonomous driving system according to claim 2, characterized in that, The multidimensional sensor includes a light wave detection type sensor; the generation unit includes a first determination subunit; The first determining subunit is used to determine the model information of the light wave detection sensor based on the sensor parameter library and the sensing parameter values of the core operating parameters of the light wave detection sensor; The sensor parameter library includes baseline parameter values for the core operating parameters of each sensor in the sensor dataset.
4. The safety testing device for an autonomous driving system according to claim 2, characterized in that, The multidimensional sensor includes a visual perception sensor; the generation unit includes a second determination subunit; The second determining subunit is used to determine the model information of the visual perception sensor based on the manufacturing model of the visual perception sensor in the target vehicle.
5. The safety testing apparatus for an autonomous driving system according to any one of claims 2-4, characterized in that, The generation unit includes a generation subunit, a first determination subunit, and a second determination subunit; both the first determination subunit and the second determination subunit are communicatively connected to the generation subunit. The generating subunit is used to determine the attack value of the core operating parameters of the multidimensional sensor based on the mapping relationship set and the model information uploaded by the first determining subunit and the second determining subunit. The multidimensional attack signal of the multidimensional sensor is determined based on the attack value; wherein, the mapping relationship set includes the baseline attack value of the core operating parameter of each sensor model in the sensor model set; the attack value of the core operating parameter of any sensor is the configuration value of the core operating parameter in the attack signal of any sensor.
6. The safety testing device for an autonomous driving system according to claim 5, characterized in that, The multidimensional sensor includes a light wave detection sensor and a visual perception sensor; the generation subunit is specifically used for: For the target sensor in the multi-dimensional sensor, the corrected attack value of the core working parameter of the target sensor is determined based on the first parameter value, the second parameter value, and the absolute parameter difference between the first parameter value and the second parameter value. Wherein, the first parameter value is the perception parameter value of the core operating parameter of the target sensor; the second parameter value is the attack value of the core operating parameter of the target sensor; When the target sensor is the visual perception sensor, the first parameter value is equal to the second parameter value by default.
7. The safety testing apparatus for an autonomous driving system according to any one of claims 2-4, characterized in that, The attack unit includes: a target sensor attack subunit corresponding to the target sensor; the target sensor is each sensor in the multi-dimensional sensor; The generation unit is specifically configured to: send an attack command to the target sensor attack subunit; wherein the attack command includes an attack signal corresponding to the target sensor; The target sensor attack subunit is used to apply the attack signal to the target sensor in response to the attack command.
8. The safety testing device for an autonomous driving system according to claim 7, characterized in that, The generation unit further includes a coordination subunit and a reconnaissance subunit; the coordination subunit is communicatively connected to the reconnaissance subunit and the target sensor attack subunit, respectively; the reconnaissance subunit and the target sensor attack subunit are communicatively connected. The coordination subunit is used to send test commands to the target sensor attack subunit and to send reconnaissance commands to the reconnaissance subunit; the test command is used to instruct the transmission of a test signal to the target reconnaissance device and to instruct the transmission time of the test signal; the reconnaissance command is used to instruct the reconnaissance device to detect the arrival time of the test signal at the target reconnaissance device. The target sensor attack subunit is configured to send the test signal to the target reconnaissance device at the sending time in response to the test command; The reconnaissance subunit is configured to, in response to the reconnaissance command, determine the arrival time and return the arrival time to the coordination subunit; The collaborative subunit is further configured to determine the attack delay of the target sensor based on the transmission time and the arrival time; and to send the attack delay to the attack unit so that the attack unit applies the multidimensional attack signal to the multidimensional sensor based on the attack delay, thereby causing the multidimensional sensor to be attacked simultaneously.
9. The safety testing device for an autonomous driving system according to claim 2, characterized in that, The autonomous driving system safety testing device is located in a concealed position on the roadside; the autonomous driving system safety testing device also includes a triggering module; the triggering module is communicatively connected to the attack module. The triggering module is used for: Upon observing that the target vehicle has entered the attack range, a trigger command is sent to the attack module to trigger the attack module to generate the multidimensional attack signal; The test module is specifically used for: The attack confidence level of the target vehicle is determined based on the driving video stream; If the attack confidence level is greater than the first preset attack confidence level, the attack module is prompted to continue applying the multidimensional attack signal; If the attack confidence level is not greater than the first preset attack confidence level but greater than the second preset attack confidence level, the attack module is prompted to increase the attack power of the multidimensional attack signal and continue to apply the multidimensional attack signal with increased power. If the attack confidence level is not greater than the second preset attack confidence level, the attack module is prompted to regenerate the multidimensional attack signal.
10. The safety testing apparatus for an autonomous driving system according to claim 9, characterized in that, The test module is specifically used for: The longitudinal deceleration of the target vehicle body, the difference in optical flow velocity, and the heading angle of the vehicle are determined based on the driving video stream. Based on the longitudinal deceleration of the vehicle body, the optical flow velocity difference, and the heading angle of the vehicle front, the abnormal braking quantification value, abnormal speed control quantification value, and abnormal steering behavior quantification value of the target vehicle are determined respectively. The attack confidence level is determined based on the braking anomaly quantification value, the speed control anomaly quantification value, and the steering behavior anomaly quantification value.
11. A safety testing method for an autonomous driving system, characterized in that, The method is applied to the safety testing apparatus for an autonomous driving system as described in any one of claims 1-10; the method includes: Based on the perception parameter values of the core operating parameters of the multidimensional sensor, a multidimensional attack signal is applied to the multidimensional sensor; and after applying the multidimensional attack signal, a test command is sent; wherein, the multidimensional sensor is multiple sensors in the target autonomous driving system of the target vehicle; In response to the test command, observe the driving video stream of the target vehicle under the multidimensional attack signal; The anti-attack performance of the autonomous driving system is determined based on the driving video stream.
12. An electronic device, characterized in that, include: A processor and a memory, wherein the memory stores at least one computer program, which is loaded and executed by the processor to implement the safety testing method for an autonomous driving system as described in claim 11.