Intermediate Representation Training Against V2V Adversarial Attacks

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

Existing autonomous vehicle technologies face challenges in effectively communicating and aggregating intermediate representations of environments between vehicles, which can lead to inaccuracies in object detection and prediction, and are vulnerable to adversarial attacks.

Innovation Solution

A computer-implemented method and system for vehicle-to-vehicle communications that generates and communicates intermediate representations of environments between autonomous vehicles, using machine-learned models to aggregate and correct these representations, and employs adversarial training techniques to mitigate malicious attacks.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Measurement precision

If intermediate representations are communicated between autonomous vehicles, then object detection accuracy is improved, but the system becomes vulnerable to adversarial attacks

Engineering Contradiction:
Improveobject detection accuracyVSAvoidsecurity against adversarial attacks
Core Design Contradiction:
Measurement precisionVSReliability

Solution Approach 1:

The patent applies preliminary action by training the machine-learned model with adversarial examples before deployment. The adversarial training process prepares the model in advance to recognize and resist malicious attacks on intermediate representations, ensuring security is built into the model before it encounters real threats in vehicle-to-vehicle communication

Inventive Principle:
Principle #10Preliminary action

Solution Approach 2:

The patent converts the harmful effect of adversarial attacks into a beneficial training mechanism. By intentionally exposing the model to adversarial examples during training, the system transforms potential security threats into learning opportunities that strengthen the model's robustness and ability to detect malicious inputs

Inventive Principle:
Principle #22Blessing in disguise (Convert harm into benefit)

2Measurement precision

If machine-learned models aggregate intermediate representations from multiple vehicles, then environmental perception accuracy is improved, but computational complexity increases

Engineering Contradiction:
Improveenvironmental perception accuracyVSAvoidcomputational complexity
Core Design Contradiction:
Measurement precisionVSDevice complexity

Solution Approach 1:

The patent extracts only the essential intermediate representations needed for environmental perception from multiple vehicles, rather than processing all available data. This selective extraction reduces computational complexity while maintaining the accuracy benefits of aggregation by focusing on the most relevant environmental features

Inventive Principle:
Principle #2Taking out (Extraction)

Solution Approach 2:

The patent changes parameters of the intermediate representations during aggregation, such as adjusting feature dimensions, selection criteria, or transformation methods. These parameter adjustments optimize the balance between aggregation accuracy and computational efficiency by adapting the processing to the specific characteristics of the input data

Inventive Principle:
Principle #35Parameter changes

Data Source

PatentUS20250139980A1Systems and Methods for Training Machine-Learned Models with Deviating Intermediate Representations
Publication Date: 2025.05.01 AURORA OPERATIONS INC
  • US20250139980A1 patent drawing
  • US20250139980A1 patent drawing
  • US20250139980A1 patent drawing

AI summary

Systems and methods for vehicle-to-vehicle communications are provided. An adverse system can obtain sensor data representative of an environment proximate to a targeted system. The adverse system can generate an intermediate representation of the environment and a representation deviation for the intermediate representation. The representation deviation can be designed to disrupt a machine-learned model associated with the target system. The adverse system can communicate the intermediate representation modified by the representation deviation to the target system. The target system can train the machine-learned model associated with the target system to detect the modified intermediate representation. Detected modified intermediate representations can be discarded before disrupting the machine-learned model.