Deviated Intermediate Representations for Secure V2V Model Training

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

Existing autonomous vehicle technologies face challenges in effectively communicating and aggregating intermediate representations of environments between vehicles, which can lead to inaccuracies in object detection and prediction, and are vulnerable to adversarial attacks.

Innovation Solution

A computer-implemented method for vehicle-to-vehicle communications that involves obtaining sensor data, generating intermediate representations, determining deviations based on machine-learned models, and communicating modified representations to improve autonomous operations and defend against adversarial attacks.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Measurement precision

If intermediate representations are communicated between autonomous vehicles, then the accuracy of object detection and prediction is improved through aggregation, but the system becomes vulnerable to adversarial attacks

Engineering Contradiction:
Improveaccuracy of object detection and predictionVSAvoidvulnerability to adversarial attacks
Core Design Contradiction:
Measurement precisionVSObject-affected harmful factors

Solution Approach 1:

The system performs preliminary actions by training the machine-learned model with deviated intermediate representations before deployment. This advance preparation enables the model to recognize and resist adversarial attacks when intermediate representations are communicated between vehicles, thus improving detection accuracy while maintaining security.

Inventive Principle:
Principle #10Preliminary action

Solution Approach 2:

The system applies preliminary anti-action by introducing deviated intermediate representations during training to counteract potential adversarial attacks. This creates a form of immunization where the model learns to identify and reject malicious inputs, thereby protecting the accuracy of object detection and prediction when aggregating data from multiple vehicles.

Inventive Principle:
Principle #9Preliminary anti-action

2Measurement precision

If intermediate representations are aggregated from multiple vehicles, then detection accuracy is enhanced, but the complexity of inter-system communication increases

Engineering Contradiction:
Improvedetection accuracyVSAvoidcomplexity of inter-system communication
Core Design Contradiction:
Measurement precisionVSDevice complexity

Solution Approach 1:

The system extracts only the essential intermediate representations needed for object detection and prediction from multiple vehicles, rather than transmitting all sensor data. This selective extraction enhances detection accuracy through aggregation while reducing communication complexity by transmitting only relevant features.

Inventive Principle:
Principle #2Taking out (Extraction)

3Reliability

If machine-learned models are trained with deviated intermediate representations, then security against adversarial attacks is improved, but the training process becomes more complex

Engineering Contradiction:
Improvesecurity against adversarial attacksVSAvoidcomplexity of training process
Core Design Contradiction:
ReliabilityVSDevice complexity

Solution Approach 1:

The system converts the potential harm of adversarial attacks into a training benefit by deliberately introducing deviated intermediate representations during the training process. This transforms security threats into useful training data that strengthens the model's ability to detect and resist attacks, improving reliability while managing training complexity through purposeful distortion.

Inventive Principle:
Principle #22Blessing in disguise (Convert harm into benefit)

Data Source

PatentUS12223734B2Systems and methods for training machine-learned models with deviating intermediate representations
Publication Date: 2025.02.11 AURORA OPERATIONS INC
  • US12223734B2 patent drawing
  • US12223734B2 patent drawing
  • US12223734B2 patent drawing

AI summary

Systems and methods for vehicle-to-vehicle communications are provided. An adverse system can obtain sensor data representative of an environment proximate to a targeted system. The adverse system can generate an intermediate representation of the environment and a representation deviation for the intermediate representation. The representation deviation can be designed to disrupt a machine-learned model associated with the target system. The adverse system can communicate the intermediate representation modified by the representation deviation to the target system. The target system can train the machine-learned model associated with the target system to detect the modified intermediate representation. Detected modified intermediate representations can be discarded before disrupting the machine-learned model.