Skip to main navigation Skip to search Skip to main content

AdvLIM-LD: Toward Cross-Task Physical Adversarial Attack via LED Illumination Modulation for Lane Detection Systems

  • You Jiang
  • , Yudong Wang
  • , Yuqiao Luo
  • , Zewei Yang
  • , Yinglong Liao
  • , Yixuan Shen
  • , Yuqun Lin
  • , Hezhong Pan*
  • , Zoe Lin Jiang
  • , Junbin Fang*
  • *Corresponding author for this work
  • Jinan University
  • University of Electronic Science and Technology of China
  • School of Computer Science and Technology, Harbin Institute of Technology
  • Ministry of Emergency Management

Research output: Contribution to journalArticlepeer-review

Abstract

The reliability and robustness of lane detection play an instrumental role in the practical deployment of autonomous driving systems. Despite previous research indicating that adversarial examples can negatively affect lane detection models, leading to erroneous lane detection, most existing adversarial attacks are designed to attack lane detection models of a single deep learning-based task. To address this issue, we propose a toward cross-task physical adversarial attack via LED illumination modulation for lane detection systems (AdvLIM-LDs) by analyzing the common critical feature response mechanisms of lane detection models of different task types. The method first introduces a critical feature disruption (CFD) module to evaluate the impact of adversarial examples on critical features contributing to various tasks. Then, it utilizes the pulse width modulation of LEDs and the rolling shutter effect of CMOS image sensor to implant imperceptible adversarial perturbations during the image acquisition process. Finally, it enhances the cross-task transferability of adversarial examples by jointly optimizing a dual objective function composed of critical feature loss and model output accuracy loss. In digital domain simulations, adversarial examples generated by AdvLIM-LD caused an average detection accuracy degradation of 74.64% across lane detection models representing different task types, including the segmentation model SCNN, the anchor-based detector LaneATT, the curve-fitting model LSTR, and the keypoint detection model GANet. For cross-task attacks, the average accuracy degradation reached 55.37%. Physical-world experiments further validated the effectiveness of AdvLIM-LD, demonstrating its ability to degrade the source models’ average detection accuracy by over 80%.

Original languageEnglish
Pages (from-to)47000-47010
Number of pages11
JournalIEEE Internet of Things Journal
Volume12
Issue number22
DOIs
StatePublished - 2025
Externally publishedYes

Keywords

  • LED modulation
  • critical feature disruption (CFD)
  • cross-task
  • lane detection
  • physical adversarial attacks

Fingerprint

Dive into the research topics of 'AdvLIM-LD: Toward Cross-Task Physical Adversarial Attack via LED Illumination Modulation for Lane Detection Systems'. Together they form a unique fingerprint.

Cite this