Pith. sign in

REVIEW 5 major objections 5 minor 181 references

A Survey on Adversarial Robustness of LiDAR-based Machine Learning Perception in Autonomous Vehicles

T0 review · 5 major / 5 minor · reviewed 2026-08-12 · deepseek-v4-flash

Pith's one-line read This survey maps adversarial threats to LiDAR perception and concludes that existing defenses are rarely validated for autonomous driving and leave a significant research gap.

desk verdict A useful, readable LiDAR-specific survey that is undercut by a few editorial defects and an overclaimed comprehensiveness, but definitely worth a referee's time. read the letter →

arxiv 2411.13778 v1 pith:CGSUY53N submitted 2024-11-21 cs.LG cs.AIcs.CR

classification cs.LGcs.AIcs.CR
keywords adversarialmachinelearningautonomousvehiclesLiDARpointcloudrobustness3Dobjectdetectionsensorspoofingbackdoorpoisoningdefensivestrategies
verification ladder T0 review T1 audit T2 compute T3 formal

The pith

A machine-rendered reading of the paper's core claim, the machinery that carries it, and where it could break.

The reading

This survey sets out to close a gap in the autonomous-driving security literature by treating LiDAR-based machine perception, rather than image-based classification, as the central object of study. It assembles the main 3D LiDAR perception models, organizes adversarial threats into attacks on sensors and attacks on machine learning models, and reviews the defensive strategies proposed against each. Its conclusion is that existing defenses are often evaluated outside the autonomous-driving context and fall short of effective countermeasures, leaving a significant research gap. A sympathetic reader would take the survey's contribution to be a structured map of the threat landscape and a demonstration that robustness for LiDAR perception is still an open problem.

What carries the argument

The organizing machinery is a two-axis taxonomy: the attack surface (sensor-level cyber-physical attacks versus ML-level adversarial attacks) crossed with the position in the AV pipeline, with the ML perception module identified as the most exposed component because it directly ingests sensor data. The survey also uses the LiDAR point cloud itself as the central object, explaining how sparsity, irregularity, and lack of structure make both attacks and defenses different from the image domain. Around this axis it groups the widely used 3D perception architectures, including PointNet, PointNet++, VoxelNet, SECOND, PointPillars, PIXOR, and PointRCNN, and uses them as the reference targets when assessing whether a defense actually works in the driving context. The defense analysis then proceeds by checking each proposed countermeasure against the attack categories, which is the mechanism that produces the survey's central finding of a research gap.

What would settle it

A reader could test the survey's central gap claim by performing a systematic literature search with explicit inclusion criteria and looking for a defense that has been empirically validated on LiDAR-based 3D object detection in realistic autonomous-driving settings against more than one attack category; finding even one such defense would weaken the claim that existing defenses fall short, while confirming the survey's map would require showing that no such defense exists.

Watch

Extended reading notes

Core claim

The paper's central claim is that the combination of LiDAR sensing and deep learning creates a distinct adversarial surface that prior surveys have not covered in one place: the sensor channel can be spoofed, replayed, or flooded with fake identities, while the ML models on top of it can be evaded, poisoned, or stolen, and the two channels interact. The authors argue that LiDAR-based perception is harder to attack than image perception but far from immune, and that most published defenses were designed for image classifiers or for toy point-cloud settings, so they do not transfer reliably to 3D object detectors inside a driving pipeline. They further claim that no existing defensive strategy covers the full range of attacks described, and that next-generation LiDAR security features such as timing randomization and pulse fingerprinting reduce but do not eliminate spoofing. The upshot is that securing LiDAR perception against adversarial threats remains an open research problem with safety-critical consequences.

Load-bearing premise

The load-bearing premise is that the papers and models selected for the survey fairly represent the full landscape of LiDAR adversarial attacks and defenses, because no systematic search strategy or inclusion criteria are stated in the text.

Editorial extensions

If this is right

  • A practitioner should not assume that defenses validated on image classifiers will protect a LiDAR object detector; the survey indicates most such defenses have not been tested in that setting.
  • Sensor-level mitigations such as laser-timing randomization and pulse fingerprinting reduce spoofing risk but still allow partial point injection, so residual risk needs monitoring.
  • Physical invariants such as shadows, occlusion patterns, and temporal motion consistency offer a promising class of defenses because they exploit properties of the physical world rather than model internals.
  • The reuse of pretrained models and public datasets introduces a poisoning surface that current LiDAR defenses largely do not address.
  • Because attacks on the perception module cascade into decision-making, robustness of perception is a safety property of the whole vehicle, not just an ML performance issue.

Reading between the lines

Editorial extensions of the paper, not claims the author makes directly.

  • Editorial inference: The survey's own framing suggests that the field would benefit from a standardized benchmark that evaluates defenses against sensor spoofing, evasion, poisoning, and physical attacks on the same LiDAR object detectors and real driving datasets; the authors do not propose such a benchmark.
  • Editorial inference: Since most cited attacks assume white-box knowledge, the real-world risk may be lower than the threat landscape implies, but transferable attacks are explicitly understudied, so this apparent safety could erode as transfer methods improve.
  • Editorial inference: A testable extension is to quantify how much defense strength comes from hardware changes such as timing randomization and pulse fingerprinting versus algorithmic changes, which could guide where future investment should go.
  • Editorial inference: The survey's limitation analysis implies that defense evaluation should include physical realizability constraints and temporal consistency across frames, not just perturbation norms in point-cloud space.
Share X Bluesky LinkedIn Reddit HN

Editorial analysis

A structured set of objections, weighed in public.

Desk editor's note, referee report, and a circularity audit.

Referee Report

5 major / 5 minor

Summary. The paper presents a survey of adversarial attacks and defenses for LiDAR-based machine learning perception in autonomous vehicles. It introduces the AV pipeline and LiDAR point cloud properties, reviews common 3D object detection models (PointNet, VoxelNet, SECOND, PointPillars, PIXOR, PointRCNN, etc.), and then categorizes attacks into sensor-level attacks (spoofing, replay, Sybil) and ML-level attacks (evasion, poisoning, model stealing). It reviews defensive measures for both categories, often with critical assessments of their limitations, and concludes that none of the surveyed defenses covers the full range of attacks, indicating a significant research gap in the field.

Significance. If its coverage and summaries are reliable, the survey offers a useful structured entry point into a fragmented literature, particularly through its taxonomy of LiDAR-specific attacks and its critical evaluation of defense limitations (e.g., shadow-based detection, temporal consistency checks, and next-generation LiDAR security features). The paper includes specific attack success rates and scenario details that help ground the discussion. The survey's value is nonetheless contingent on reproducible and accurate literature coverage; at present, the absence of a documented selection methodology and several citation/paraphrase defects prevent me from endorsing the comprehensiveness claim.

major comments (5)
  1. [Sections I and IV-B] The paper's central claim to provide a 'comprehensive overview' and the conclusion that 'none of them has covered the range of possible adversarial attacks described in Section III' are not reproducible because the survey does not state its search strategy, databases, inclusion/exclusion criteria, or screening process. The gap conclusion is therefore an argument from absence. Please add a methodology subsection describing how papers were selected, or explicitly reframe the scope as 'selected works' and support the gap claim with a coverage table listing the attacks and defenses considered.
  2. [Section III-B2, first paragraph] The sentence 'particularly vulnerability to adversarial poisoning attacks [ ?], [111]' contains an unresolved placeholder citation marker, which is unacceptable in a survey whose value depends on accurate citation. Please replace the placeholder with the correct reference and verify that citation [111] (a poisoning attacks survey) is the intended source for the claim about pretrained model supply chain risks.
  3. [Section II-C, PIXOR paragraph] The text states that 'PIXOR operates on 2D camera images, specifically focusing on LiDAR-camera fusion for 3D object detection from BEV.' This is factually incorrect: PIXOR is a LiDAR-based bird's-eye-view detector (Yang et al., CVPR 2018) that does not operate on camera images. Because the overview of ML models underpins the later attack and defense discussion, this mischaracterization should be corrected and the surrounding model summaries should be checked for similar errors.
  4. [Reference list, [49]] Reference [49] (Hau et al., Shadow-Catcher) appears twice verbatim in the bibliography. This creates ambiguity about which entry is intended when [49] is cited in the text, and it suggests the reference list has not been carefully deduplicated. Please collapse the duplicate and renumber the references consistently.
  5. [Section III-B2, Bishoff et al. [122]] The sentence describing Bishoff et al. [122] is garbled and appears to conflate two different topics: 'quantification of adversarial robustness of multispectral segmentation models against data poisoningin a universal black-box backdoor sample detection method tailored for 3D point clouds without any prior knowledge or assumption of the triggers and victim models.' The cited work is on multispectral segmentation robustness, not on 3D point cloud backdoor detection. Please rewrite this summary accurately based on the actual paper, or remove the claim.
minor comments (5)
  1. [Section III-A1] The discussion of Park et al. [53]'s spoofing attack on medical infusion pumps is not connected to LiDAR or autonomous driving; please clarify its relevance to the LiDAR context or remove it.
  2. [Section III-B1] The sentence 'Both attacks [50], [51], necessitate precise pulse injection...' contains an unnecessary comma before 'necessitate'; please proofread for punctuation.
  3. [Section IV-B] The phrase 'In a study conducted by Cao et al. [94], they examined...' is a subject-verb disagreement; consider rewriting as 'Cao et al. [94] examined...'.
  4. [Section II-C, PIXOR++ citation] The text 'PIXOR is one of the fastest LiDAR object detection models and is further improved in PIXOR++ [32]' cites reference [32], which is HDNet, not PIXOR++; please verify and correct this citation.
  5. [Section V] The statement 'Also, there are no robust and effective solutions against all possible adversarial threats' is very strong; please cite supporting analyses or soften it to 'no surveyed approach provides robust and effective solutions against all possible adversarial threats.'

Circularity Check

0 steps flagged · score 0.0 of 10

No circular reasoning: the survey synthesizes external results and its research-gap conclusion is an independent literature-assessment claim, not a derivation from its own inputs.

full rationale

This paper is a literature survey rather than a derivation or empirical study. It introduces no mathematical quantities, no fitted parameters, and no predictive model; its content summarizes externally published attacks and defenses. The central claim that existing defensive strategies often fall short and that there remains a significant research gap is an assessment of the surveyed corpus, not a consequence of a definition or a fitted input. The authors do not cite their own prior work, and no load-bearing argument rests on a self-citation chain. The statement in Section IV-B that none of them has covered the range of possible adversarial attacks depends on the completeness and accuracy of the literature selection, which is a correctness and reproducibility concern rather than circularity. The internal citation defects (the unresolved placeholder in Section III-B2, the duplicated reference [49], and the garbled description of Bishoff et al.) affect verifiability and quality but do not make any claimed result reduce to its own assumptions. Therefore no significant circularity is present, and the circularity score is 0.

Assumptions & free parameters 0 free parameters · 3 assumptions · 0 invented entities

This survey introduces no new formal entities, parameters, or derivations. The central claims rest on the representativeness of the selected literature and on stated assumptions about LiDAR sensors and the AV pipeline.

assumptions (3)
  • domain assumption LiDAR point clouds are less susceptible to adversarial attacks compared to images (based on [24]-[26]).
    Adopted in Section II-C and used to frame attack complexity; the paper relies on cited studies for this claim.
  • domain assumption The described models (PointNet, VoxelNet, SECOND, PointPillars, etc.) are representative of state-of-the-art LiDAR perception.
    Section II-C selects these models as the main targets; this selection determines the scope of the attack and defense review.
  • domain assumption Sensors are trusted components, so sensor-level falsification directly affects downstream ML decisions.
    Used in Section III-A to motivate sensor spoofing, replay, and Sybil threats.

how reviews work

0 comments
Cite this review

Pith. "Pith review of A Survey on Adversarial Robustness of LiDAR-based Machine Learning Perception in Autonomous Vehicles." pith.science (2026). https://pith.science/paper/CGSUY53N

@misc{pith2026241113778,
  author       = {Pith},
  title        = {Pith review of: A Survey on Adversarial Robustness of LiDAR-based Machine Learning Perception in Autonomous Vehicles},
  year         = {2026},
  howpublished = {\url{https://pith.science/paper/CGSUY53N}},
  note         = {Machine review of arXiv:2411.13778}
}
read the original abstract

In autonomous driving, the combination of AI and vehicular technology offers great potential. However, this amalgamation comes with vulnerabilities to adversarial attacks. This survey focuses on the intersection of Adversarial Machine Learning (AML) and autonomous systems, with a specific focus on LiDAR-based systems. We comprehensively explore the threat landscape, encompassing cyber-attacks on sensors and adversarial perturbations. Additionally, we investigate defensive strategies employed in countering these threats. This paper endeavors to present a concise overview of the challenges and advances in securing autonomous driving systems against adversarial threats, emphasizing the need for robust defenses to ensure safety and security.

Figures

Figures reproduced from arXiv: 2411.13778 by the authors.

Figure 1
Figure 1. SAE Driving Automation Levels [3] Sensors, such as cameras, LiDAR, GPS devices, etc., collect raw data from the environment. These sensors capture and relay information about the AV’s surroundings in which the AV operates, including road infrastructure, traffic dynam￾ics, environmental conditions, etc. for the AV’s process. In this survey, we focus on AV systems using LiDAR sensors since LiDAR sensors offer a signif… view at source ↗
Figure 2
Figure 2. A Pipeline of Autonomous Vehicle System Once the perception system has gathered and processed sensor data, the next key step is decision-making. This module is dedicated to making important decisions on how to interact with the environment, based on the perceived environment. Here, the ML algorithm determines the vehicle’s actions, including lane changes, yielding to other road users, and managing emergency scenario… view at source ↗

Discussion (0). Continue with ORCID to comment.

Reference graph

Works this paper leans on

181 extracted references · 62 canonical work pages

  1. [111]

    Threats to Training: A Survey of Poisoning Attacks and Defenses on Machine Learning Systems,

    Z. Wang, J. Ma, X. Wang, J. Hu, Z. Qin and K. Ren, “Threats to Training: A Survey of Poisoning Attacks and Defenses on Machine Learning Systems,” ACM Computing Surveys , vol. 55, p. 1–36, 2022

  2. [49]

    Shadow- catcher: Looking into shadows to detect ghost objects in autonomous vehicle 3d sensing,

    Z. Hau, S. Demetriou, L. Mu ˜noz-Gonz´alez and E. C. Lupu, “Shadow- catcher: Looking into shadows to detect ghost objects in autonomous vehicle 3d sensing,” in ESORICS 2021: 26th European Symposium on Research in Computer Security, Darmstadt, Germany, October 4–8, 2021, Part I 26, 2021. Hau, Zhongyuan, Soteris Demetriou, Luis Mu ˜noz-Gonz´alez, and Emil C...

  3. [122]

    Quantifying the robustness of deep multispectral segmentation models against natural perturbations and data poisoning,

    E. Bishoff, C. Godfrey, M. McKay and E. Byler, “Quantifying the robustness of deep multispectral segmentation models against natural perturbations and data poisoning,” in Algorithms, Technologies, and Applications for Multispectral and Hyperspectral Imaging XXIX , 2023

  4. [1]

    Adversarial Machine Learning: A Taxonomy and Terminology of Attacks and Miti- gations,

    A. Vassilev, A. Oprea, A. Fordyce and H. Anderson, “Adversarial Machine Learning: A Taxonomy and Terminology of Attacks and Miti- gations,” NIST, 2024

  5. [2]

    Poisoning and evasion attacks against deep learning algorithms in autonomous vehicles,

    W. Jiang, H. Li, S. Liu, X. Luo and R. Lu, “Poisoning and evasion attacks against deep learning algorithms in autonomous vehicles,” IEEE transactions on vehicular technology , vol. 69, p. 4439–4449, 2020

  6. [3]

    Definitions for terms related to driving automation systems for on-road motor vehicles. Publication J3016 202104,

    T. SAE, “Definitions for terms related to driving automation systems for on-road motor vehicles. Publication J3016 202104,” Society of Automo- tive Engineers, 2021

  7. [4]

    Level-5 autonomous driving—are we there yet? A review of research literature,

    M. A. Khan, H. E. Sayed, S. Malik, T. Zia, J. Khan, N. Alkaabi and H. Ignatious, “Level-5 autonomous driving—are we there yet? A review of research literature,” ACM Computing Surveys (CSUR) , vol. 55, p. 1–38, 2023

  8. [5]

    A review of sensor technologies for perception in automated driving,

    E. Marti, M. A. De Miguel, F. Garcia and J. Perez, “A review of sensor technologies for perception in automated driving,” IEEE Intelligent Transportation Systems Magazine, vol. 11, p. 94–108, 2019

Show all 181 references
  1. [6]

    Introduction to lidar,

    U. Wandinger, “Introduction to lidar,” in Lidar: range-resolved optical remote sensing of the atmosphere , ed. by C. Weitkamp, Springer, 2005, p. 1–18

  2. [7]

    Review of ladar: a historic, yet emerging, sensor technology with rich phenomenology,

    P. F. McManamon, “Review of ladar: a historic, yet emerging, sensor technology with rich phenomenology,” Optical Engineering, vol. 51, no. 6, 2012

  3. [8]

    LiDAR remote sensing,

    J. C. Fernandez Diaz, W. E. Carter, R. L. Shrestha and C. L. Glennie, “LiDAR remote sensing,” In: Pelton, J.N., Madry, S., Camacho-Lara, S. (eds) Handbook of Satellite Applications. , Springer, New York, NY ., p. 757-808, 2013

  4. [9]

    Lidar for autonomous driving: The princi- ples, challenges, and trends for automotive lidar and perception systems,

    Y . Li and J. Ibanez-Guzman, “Lidar for autonomous driving: The princi- ples, challenges, and trends for automotive lidar and perception systems,” IEEE Signal Processing Magazine , vol. 37, p. 50–61, 2020

  5. [10]

    Positioning and perception in LIDAR point clouds,

    C. Benedek, A. Majdik, B. Nagy, Z. Rozsa and T. Sziranyi, “Positioning and perception in LIDAR point clouds,” Digital Signal Processing , vol. 119, p. 103193, 2021

  6. [11]

    Deep learning on point clouds and its application: A survey,

    W. Liu, J. Sun, W. Li, T. Hu and P. Wang, “Deep learning on point clouds and its application: A survey,” in Sensors 19, no. 19, 2019

  7. [12]

    Deep learning for 3d point clouds: A survey,

    Y . Guo, H. Wang, Q. Hu, H. Liu, L. Liu and M. Bennamoun, “Deep learning for 3d point clouds: A survey,” in IEEE transactions on pattern analysis and machine intelligence 43 , no. 12, 2020

  8. [13]

    A survey on deep-learning-based lidar 3d object detection for autonomous driving,

    S. Y . Alaba and J. E. Ball, “A survey on deep-learning-based lidar 3d object detection for autonomous driving,” Sensors 22, 2022

  9. [14]

    A survey of robust 3d object detection methods in point clouds,

    W. Zimmer, E. Ercelik, X. Zhou, X. J. D. Ortiz and A. Knoll, “A survey of robust 3d object detection methods in point clouds,” arXiv preprint arXiv:2204.00106, 2022

  10. [15]

    A survey on misbehavior detection for connected and autonomous vehicles,

    M. L. Bouchouia, H. Labiod, O. Jelassi, J.-P. Monteuuis, W. B. Jaballah, J. Petit and Z. Zhang, “A survey on misbehavior detection for connected and autonomous vehicles,” Vehicular Communications, vol. 41, 2023

  11. [16]

    LiDAR based perception system: Pioneer technology for safety driving,

    Z. Luo, “LiDAR based perception system: Pioneer technology for safety driving,” PhD Thesis, McMaster University, 2017

  12. [17]

    Autonomous vehicle self-localization based on abstract map and multi-channel LiDAR in urban area,

    E. Javanmardi, Y . Gu, M. Javanmardi, and S. Kamijo, “Autonomous vehicle self-localization based on abstract map and multi-channel LiDAR in urban area,” IATSS Research, vol. 43, no. 1, p. 1–13, 2019

  13. [18]

    Potential use of near, mid and far infrared laser diodes in automotive LIDAR applications,

    A. Samman, L. Rimai, J. R. McBride, R. O. Carter, W. H. Weber, C. Gmachl, F. Capasso, A. L. Hutchinson, D. L. Sivco and A. Y . Cho, “Potential use of near, mid and far infrared laser diodes in automotive LIDAR applications,” in Vehicular Technology Conference Fall 2000 . IEEE ...

  14. [19]

    Pointpillars: Fast encoders for object detection from point clouds,

    A. H. Lang, S. V ora, H. Caesar, L. Zhou, J. Yang and O. Beijbom, “Pointpillars: Fast encoders for object detection from point clouds,” in Proceedings of the IEEE/CVF conference on computer vision and pattern recognition, 2019

  15. [20]

    V oxelnet: End-to-end learning for point cloud based 3d object detection,

    Y . Zhou and O. Tuzel, “V oxelnet: End-to-end learning for point cloud based 3d object detection,” in Proceedings of the IEEE conference on computer vision and pattern recognition 2018

  16. [21]

    Second: Sparsely embedded convolutional detection,

    Y . Yan, Y . Mao and B. Li, “Second: Sparsely embedded convolutional detection,” Sensors, vol. 18, p. 3337, 2018

  17. [22]

    Detection, classification and tracking of moving objects in a 3D environment,

    A. Azim and O. Aycard, “Detection, classification and tracking of moving objects in a 3D environment,” in 2012 IEEE Intelligent Vehicles Symposium, 2012

  18. [23]

    Pointnet: Deep learning on point sets for 3d classification and segmentation,

    C. R. Qi, H. Su, K. Mo and L. J. Guibas, “Pointnet: Deep learning on point sets for 3d classification and segmentation,” in Proceedings of the IEEE conference on computer vision and pattern recognition , 2017a

  19. [24]

    Generating 3d adversarial point clouds,

    C. Xiang, C. R. Qi and B. Li, “Generating 3d adversarial point clouds,” in Proceedings of the IEEE/CVF Conference on Computer Vision and Pattern Recognition, 2019

  20. [25]

    Adversarial attacks against lidar semantic segmentation in autonomous driving,

    Y . Zhu, C. Miao, F. Hajiaghajani, M. Huai, L. Su and C. Qiao, “Adversarial attacks against lidar semantic segmentation in autonomous driving,” in Proceedings of the 19th ACM Conference on Embedded Networked Sensor Systems , 2021

  21. [26]

    Exploring Adversarial Robustness of Multi- sensor Perception Systems in Self Driving,

    J. Tu, H. Li, X. Yan, M. Ren, Y . Chen, M. Liang, E. Bitar, E. Yumer and R. Urtasun, “Exploring Adversarial Robustness of Multi- sensor Perception Systems in Self Driving,” in 5th Annual Conference on Robot Learning , 2021

  22. [27]

    Deep learning on 3D point clouds,

    S. A. Bello, S. Yu, C. Wang, J. M. Adam and J. Li, “Deep learning on 3D point clouds,” Remote Sensing, vol. 12, p. 1729, 2020

  23. [28]

    Pointnet++: Deep hierarchical feature learning on point sets in a metric space,

    C. R. Qi, L. Yi, H. Su and L. J. Guibas, “Pointnet++: Deep hierarchical feature learning on point sets in a metric space,” Advances in neural information processing systems , vol. 30, 2017

  24. [29]

    Frustum pointnets for 3d object detection from rgb-d data,

    C. R. Qi, W. Liu, C. Wu, H. Su and L. J. Guibas, “Frustum pointnets for 3d object detection from rgb-d data,” in Proceedings of the IEEE conference on computer vision and pattern recognition , 2018

  25. [30]

    Frustum convnet: Sliding frustums to aggregate local point-wise features for amodal 3d object detection.,

    Z. Wang and K. Jia, “Frustum convnet: Sliding frustums to aggregate local point-wise features for amodal 3d object detection.,” IEEE/RSJ International Conference on Intelligent Robots and Systems (IROS) , pp. 1742-1749, 2019

  26. [31]

    Pixor: Real-time 3d object detection from point clouds,

    B. Yang, W. Luo and R. Urtasun, “Pixor: Real-time 3d object detection from point clouds,” in Proceedings of the IEEE conference on Computer Vision and Pattern Recognition , 2018a

  27. [32]

    Hdnet: Exploiting hd maps for 3d object detection,

    B. Yang, M. Liang and R. Urtasun, “Hdnet: Exploiting hd maps for 3d object detection,” Conference on Robot Learning. PMLR , 2018b

  28. [33]

    Pointrcnn: 3d object proposal generation and detection from point cloud,

    S. Shi, X. Wang and H. Li, “Pointrcnn: 3d object proposal generation and detection from point cloud,” in Proceedings of the IEEE/CVF conference on computer vision and pattern recognition , 2019

  29. [34]

    MotionNet: Joint Perception and Motion Prediction for Autonomous Driving Based on Bird’s Eye View Maps,

    P. Wu, S. Chen and D. N. Metaxas, “MotionNet: Joint Perception and Motion Prediction for Autonomous Driving Based on Bird’s Eye View Maps,” in Proceedings of the IEEE/CVF Conference on Computer Vision and Pattern Recognition, 2020

  30. [35]

    Joint 3d proposal generation and object detection from view aggregation,

    J. Ku, M. Mozifian, J. Lee, A. Harakeh and S. L. Waslander, “Joint 3d proposal generation and object detection from view aggregation,” IEEE/RSJ International Conference on Intelligent Robots and Systems (IROS), pp. 1-8, 2018

  31. [36]

    Epnet: Enhancing point features with image semantics for 3d object detection,

    T. Huang, Z. Liu, X. Chen and X. Bai, “Epnet: Enhancing point features with image semantics for 3d object detection,” Computer Vision–ECCV 2020: 16th European Conference , pp. 35-52, 2020

  32. [37]

    An lstm approach to temporal 3d object detection in 17 lidar point clouds,

    R. Huang, W. Zhang, A. Kundu, C. Pantofaru, D. A. Ross, T. Funkhouser and A. Fathi, “An lstm approach to temporal 3d object detection in 17 lidar point clouds,” in Computer Vision–ECCV 2020: 16th European Conference, pp. 266-282. 2020

  33. [38]

    3DYOLO: Real-time 3D Object Detection in 3D Point Clouds for Autonomous Driving,

    M. V . Priya and D. S. Pankaj, “3DYOLO: Real-time 3D Object Detection in 3D Point Clouds for Autonomous Driving,” in 2021 IEEE International India Geoscience and Remote Sensing Symposium (InGARSS) , 2021

  34. [39]

    Ad- versarial Classification,

    N. Dalvi, P. Domingos, Mausam, S. Shanghai and D. Verma, “Ad- versarial Classification,” in Proceedings of the tenth ACM SIGKDD international conference on Knowledge discovery and data mining , 2004

  35. [40]

    Attack models and scenarios for networked control systems,

    A. Teixeira, D. P ´erez, H. Sandberg and K. H. Johansson, “Attack models and scenarios for networked control systems,” in Proceedings of the 1st international conference on High Confidence Networked Systems , 2012

  36. [41]

    Potential cyberattacks on automated vehicles,

    J. Petit and S. E. Shladover, “Potential cyberattacks on automated vehicles,” IEEE Transactions on Intelligent transportation systems , vol. 16, p. 546–556, 2014

  37. [42]

    Bibli- ographical review on cyber attacks from a control oriented perspective,

    H. S. S ´anchez, D. Rotondo, T. Escobet, V . Puig and J. Quevedo, “Bibli- ographical review on cyber attacks from a control oriented perspective,” Annual Reviews in Control , vol. 48, p. 103–128, 2019

  38. [43]

    A survey on authentication schemes in V ANETs for secured communication,

    S. S. Manvi and S. Tangade, “A survey on authentication schemes in V ANETs for secured communication,” Vehicular Communications, vol. 9, p. 19–30, 2017

  39. [44]

    Cybersecurity attacks in vehicular sensors,

    Z. El-Rewini, K. Sadatsharan, N. Sugunaraj, D. F. Selvaraj, S. J. Plathot- tam and P. Ranganathan, “Cybersecurity attacks in vehicular sensors,” IEEE Sensors Journal , vol. 20, p. 13752–13767, 2020

  40. [45]

    Autonomous Vehicles: So- phisticated Attacks, Safety Issues, Challenges, Open Topics, Blockchain, and Future Directions,

    A. Giannaros, A. Karras, L. Theodorakopoulos, C. Karras, P. Kranias, N. Schizas, G. Kalogeratos and D. Tsolis, “Autonomous Vehicles: So- phisticated Attacks, Safety Issues, Challenges, Open Topics, Blockchain, and Future Directions,” Journal of Cybersecurity and Privacy , vol....

  41. [46]

    Cybersecurity of Autonomous Vehicles: A Systematic Literature Review of Adversarial Attacks and Defense Models,

    M. Girdhar, J. Hong and J. Moore, “Cybersecurity of Autonomous Vehicles: A Systematic Literature Review of Adversarial Attacks and Defense Models,” IEEE Open Journal of Vehicular Technology , 2023

  42. [47]

    Remote attacks on automated vehicles sensors: Experiments on camera and lidar,

    J. Petit, B. Stottelaar, M. Feiri and F. Kargl, “Remote attacks on automated vehicles sensors: Experiments on camera and lidar,” Black Hat Europe, vol. 11, p. 995, 2015

  43. [48]

    You can’t see me: physical removal attacks on LiDAR- based autonomous vehicles driving frameworks,

    Y . Cao, S. H. Bhupathiraju, P. Naghavi, T. Sugawara, Z. M. Mao and S. Rampazzi, “You can’t see me: physical removal attacks on LiDAR- based autonomous vehicles driving frameworks,” 32nd USENIX Security Symposium (USENIX Security 23) , pp. 2993-3010, 2023

  44. [50]

    Adversarial sensor attack on lidar-based perception in autonomous driving,

    Y . Cao, C. Xiao, B. Cyr, Y . Zhou, W. Park, S. Rampazzi, Q. A. Chen, K. Fu and Z. M. Mao, “Adversarial sensor attack on lidar-based perception in autonomous driving,” in Proceedings of the 2019 ACM SIGSAC conference on computer and communications security , 2019a

  45. [51]

    Towards robust lidar- based perception in autonomous driving: General black-box adversarial sensor attack and countermeasures,

    J. S. Sun, Y . C. Cao, Q. A. Chen and Z. M. Mao, “Towards robust lidar- based perception in autonomous driving: General black-box adversarial sensor attack and countermeasures,” in USENIX Security Symposium (Usenix Security’20), 2020

  46. [52]

    Illusion and dazzle: Adversarial optical channel exploits against lidars for automotive applications,

    H. Shin, D. Kim, Y . Kwon and Y . Kim, “Illusion and dazzle: Adversarial optical channel exploits against lidars for automotive applications,” in Cryptographic Hardware and Embedded Systems–CHES 2017: 19th International Conference, Taipei, Taiwan, September 25-28, 2017, 2017

  47. [53]

    This ain’t your dose: Sensor spoofing attack on medical infusion pump,

    Y . Park, Y . Son, H. Shin, D. Kim and Y . Kim, “This ain’t your dose: Sensor spoofing attack on medical infusion pump,” in 10th USENIX workshop on offensive technologies (WOOT 16) , 2016

  48. [54]

    Revisiting LiDAR Spoofing Attack Capabilities against Object Detection: Improvements, Measurement, and New Attack,

    T. Sato, Y . Hayakawa, R. Suzuki, Y . Shiiki, K. Yoshioka and Q. A. Chen, “Revisiting LiDAR Spoofing Attack Capabilities against Object Detection: Improvements, Measurement, and New Attack,” arXiv preprint arXiv:2303.10555, 2023

  49. [55]

    Secure control against replay attacks,

    Y . Mo and B. Sinopoli, “Secure control against replay attacks,” in 2009 47th annual Allerton conference on communication, control, and computing (Allerton), 2009

  50. [56]

    Detecting generalized replay attacks via time-varying dynamic watermarking,

    M. Porter, P. Hespanhol, A. Aswani, M. Johnson-Roberson and R. Va- sudevan, “Detecting generalized replay attacks via time-varying dynamic watermarking,” IEEE Transactions on Automatic Control , vol. 66, p. 3502–3517, 2021

  51. [57]

    Securing Autonomous Vehicles Un- der Partial-Information Cyber Attacks on LiDAR Data,

    R. S. Hallyburton and M. Pajic, “Securing Autonomous Vehicles Un- der Partial-Information Cyber Attacks on LiDAR Data,” arXiv preprint arXiv:2303.03470, 2023

  52. [58]

    Practical cyber-attacks on autonomous vehicles,

    B. G. B. Stottelaar, “Practical cyber-attacks on autonomous vehicles,” Stottelaarfinals.pdf, Master Essay, University of Twente, 2015. [Online] Available: http://essay.utwente.nl/66766/

  53. [59]

    Exploiting social navigation,

    M. B. Sinai, N. Partush, S. Yadid and E. Yahav, “Exploiting social navigation,” arXiv preprint arXiv:1410.0151 , 2014

  54. [60]

    Internet of autonomous vehicles communications security: overview, issues, and directions,

    A. Nanda, D. Puthal, J. J. P. C. Rodrigues and S. A. Kozlov, “Internet of autonomous vehicles communications security: overview, issues, and directions,” IEEE Wireless Communications, vol. 26, p. 60–65, 2019

  55. [61]

    A review on safety failures, security attacks, and available countermeasures for autonomous vehicles,

    J. Cui, L. S. Liew, G. Sabaliauskaite and F. Zhou, “A review on safety failures, security attacks, and available countermeasures for autonomous vehicles,” Ad Hoc Networks , vol. 90, p. 101823, 2019

  56. [62]

    The sybil attack,

    J. R. Douceur, “The sybil attack,” in International workshop on peer- to-peer systems, 2002

  57. [63]

    Survey on sybil attack defense mechanisms in wireless ad hoc networks,

    A. Vasudeva and M. Sood, “Survey on sybil attack defense mechanisms in wireless ad hoc networks,” Journal of Network and Computer Appli- cations, vol. 120, pp. 78-118, 2018

  58. [64]

    Cross-layer scheme for detecting large-scale colluding Sybil attack in V ANETs,

    K. Rabieh, M. M. Mahmoud, T. N. Guo and M. Younis, “Cross-layer scheme for detecting large-scale colluding Sybil attack in V ANETs,” in IEEE International Conference on Communications (ICC) , 2015

  59. [65]

    Sybil attack resilient traffic networks: A physics-based trust propagation approach,

    Y . Shoukry, S. Mishra, Z. Luo and S. Diggavi, “Sybil attack resilient traffic networks: A physics-based trust propagation approach,” 2018 ACM/IEEE 9th International Conference on Cyber-Physical Systems (ICCPS), pp. 43-54, 2018

  60. [66]

    A Sybil attack detec- tion scheme based on ADAS sensors for vehicular networks,

    K. Lim, T. T. Islam, H. Kim and J. Joung, “A Sybil attack detec- tion scheme based on ADAS sensors for vehicular networks,” in 2020 IEEE 17th Annual Consumer Communications & Networking Conference (CCNC), 2020

  61. [67]

    A Tutorial and Review of Automobile Direct ToF LiDAR SoCs: Evolution of Next-Generation LiDARs,

    K. Yoshioka, “A Tutorial and Review of Automobile Direct ToF LiDAR SoCs: Evolution of Next-Generation LiDARs,” IEICE Transactions on Electronics, vol. E105, p. 534–543, 2022

  62. [68]

    Intriguing properties of neural networks,

    C. Szegedy, W. Zaremba, I. Sutskever, J. Bruna, D. Erhan, I. Goodfellow and R. Fergus, “Intriguing properties of neural networks,” arXiv preprint arXiv:1312.6199, 2013

  63. [69]

    Adversarial objects against lidar-based autonomous driving systems,

    Y . Cao, C. Xiao, D. Yang, J. Fang, R. Yang, M. Liu and B. Li, “Adversarial objects against lidar-based autonomous driving systems,” arXiv preprint arXiv:1907.05418 , 2019b

  64. [70]

    A backdoor attack against 3d point cloud classifiers,

    Z. Xiang, D. J. Miller, S. Chen, X. Li and G. Kesidis, “A backdoor attack against 3d point cloud classifiers,” in Proceedings of the IEEE/CVF International Conference on Computer Vision , 2021

  65. [71]

    Play the Imitation Game: Model Extraction Attack against Autonomous Driving Localization,

    Q. Zhang, J. Shen, M. Tan, Z. Zhou, Z. Li, Q. A. Chen and H. Zhang, “Play the Imitation Game: Model Extraction Attack against Autonomous Driving Localization,” in Proceedings of the 38th Annual Computer Security Applications Conference , 2022

  66. [72]

    Explaining and harnessing adversarial examples,

    I. J. Goodfellow, J. Shlens and C. Szegedy, “Explaining and harnessing adversarial examples,” arXiv preprint arXiv:1412.6572 , 2014

  67. [73]

    Practical black-box attacks against machine learning,

    N. Papernot, P. McDaniel, I. Goodfellow, S. Jha, Z. B. Celik and A. Swami, “Practical black-box attacks against machine learning,” in Proceedings of the 2017 ACM on Asia conference on computer and communications security, 2017

  68. [74]

    Secu- rity Analysis of Camera-LiDAR Fusion Against Black-Box Attacks on Autonomous Vehicles.,

    R. S. Hallyburton, Y . Liu, Y . Cao, Z. M. Mao and M. Pajic, “Secu- rity Analysis of Camera-LiDAR Fusion Against Black-Box Attacks on Autonomous Vehicles.,” in 31st USENIX Security Symposium (USENIX Security 22), 2022

  69. [75]

    You only look once: Unified, real-time object detection,

    J. Redmon, S. Divvala, R. Girshick and A. Farhadi, “You only look once: Unified, real-time object detection,” in Proceedings of the IEEE conference on computer vision and pattern recognition, 2016

  70. [76]

    A comprehensive study of the robustness for lidar-based 3d object detectors agaisnt adversarial attacks,

    Y . Zhang, J. Hou and Y . Yuan, “A comprehensive study of the robustness for lidar-based 3d object detectors agaisnt adversarial attacks,” Interna- tional Journal of Computer Vision , vol. 132, no. 5, pp. 1592-1624, 2024

  71. [77]

    PointBA: Towards Backdoor Attacks in 3D Point Cloud,

    X. Li, Z. Chen, Y . Zhao, Z. Tong, Y . Zhao, A. Lim and J. T. Zhou, “PointBA: Towards Backdoor Attacks in 3D Point Cloud,” in 2021 IEEE/CVF International Conference on Computer Vision (ICCV) , 2021

  72. [78]

    3D-VField: Adversarial Augmentation of Point Clouds for Domain Generalization in 3D Object Detection,

    A. Lehner, S. Gasperini, A. Marcos-Ramiro, M. Schmidt, M.-A. N. Mahani, N. Navab, B. Busam and F. Tombari, “3D-VField: Adversarial Augmentation of Point Clouds for Domain Generalization in 3D Object Detection,” in 2022 IEEE/CVF Conference on Computer Vision and Pattern Recogni...

  73. [79]

    Deep learning-based autonomous driving systems: A survey of attacks and defenses,

    Y . Deng, T. Zhang, G. Lou, X. Zheng, J. Jin and Q.-L. Han, “Deep learning-based autonomous driving systems: A survey of attacks and defenses,” IEEE Transactions on Industrial Informatics , vol. 17, p. 7897–7912, 2021

  74. [80]

    Natural Adversarial Examples,

    D. Hendrycks, K. Zhao, S. Basart, J. Steinhardt and D. Song, “Natural Adversarial Examples,” in 2021 IEEE/CVF Conference on Computer Vision and Pattern Recognition (CVPR) , 2021. 18

  75. [81]

    Towards analyzing semantic robustness of deep neural networks,

    A. Hamdi and B. Ghanem, “Towards analyzing semantic robustness of deep neural networks,” in Computer Vision–ECCV 2020 Workshops: Glasgow, UK, August 23–28, 2020, Part I 16, 2020

  76. [82]

    Towards evaluating the robustness of neural networks,

    N. Carlini and D. Wagner, “Towards evaluating the robustness of neural networks,” in 2017 ieee symposium on security and privacy (sp) , 2017

  77. [83]

    Adversarial shape perturbations on 3d point clouds,

    D. Liu, R. Yu and H. Su, “Adversarial shape perturbations on 3d point clouds,” in Computer Vision–ECCV 2020 Workshops: Glasgow , UK, August 23–28, 2020, Part I 16, 2020

  78. [84]

    LG-GAN: Label Guided Adversarial Network for Flexible Targeted Attack of Point Cloud Based Deep Networks,

    H. Zhou, D. Chen, J. Liao, K. Chen, X. Dong, K. Liu, W. Zhang, G. Hua and N. Yu, “LG-GAN: Label Guided Adversarial Network for Flexible Targeted Attack of Point Cloud Based Deep Networks,” in 2020 IEEE/CVF Conference on Computer Vision and Pattern Recognition (CVPR), 2020

  79. [85]

    Learning saliency maps for adversarial point-cloud generation,

    T. Zheng, C. Chen, K. Ren and others, “Learning saliency maps for adversarial point-cloud generation,” arXiv preprint arXiv:1812.01687 , 2018

  80. [86]

    Adversarial Attack and Defense on Point Sets,

    J. Yang, Q. Zhang, R. Fang, B. Ni, J. Liu and Q. Tian, “Adversarial Attack and Defense on Point Sets,” arXiv preprint arXiv:1902.10899 , 2019

  81. [87]

    One pixel attack for fooling deep neural networks,

    J. Su, D. V . Vargas and K. Sakurai, “One pixel attack for fooling deep neural networks,” IEEE Transactions on Evolutionary Computation , vol. 23, p. 828–841, 2019

  82. [88]

    Robustness of 3d deep learning in an adversarial setting,

    M. Wicker and M. Kwiatkowska, “Robustness of 3d deep learning in an adversarial setting,” in Proceedings of the IEEE/CVF Conference on Computer Vision and Pattern Recognition , 2019

  83. [89]

    On isometry robustness of deep 3d point cloud models under adversarial attacks,

    Y . Zhao, Y . Wu, C. Chen and A. Lim, “On isometry robustness of deep 3d point cloud models under adversarial attacks,” in Proceedings of the IEEE/CVF Conference on Computer Vision and Pattern Recognition , 2020

  84. [90]

    A Tutorial on Thompson Sampling,

    D. Russo, B. Van Roy, A. Kazerouni, I. Osband and Z. Wen, “A Tutorial on Thompson Sampling,” Foundations and Trends in Machine Learning , vol. 11, no. 1, p. 1-96, 2018

  85. [91]

    Decoding by Linear Programming,

    E. J. Candes and T. Tao, “Decoding by Linear Programming,” IEEE TRANSACTIONS ON INFORMATION THEORY , vol. 51, p. 4203, 2005

  86. [92]

    Pointca: Evaluating the robustness of 3d point cloud completion models against adversarial examples,

    S. Hu, J. Zhang, W. Liu, J. Hou, M. Li, L. Y . Zhang, H. Jin and L. Sun, “Pointca: Evaluating the robustness of 3d point cloud completion models against adversarial examples,” in Proceedings of the AAAI conference on artificial intelligence, 2023

  87. [93]

    Physically realizable adversarial examples for lidar object detection,

    J. Tu, M. Ren, S. Manivasagam, M. Liang, B. Yang, R. Du, F. Cheng and R. Urtasun, “Physically realizable adversarial examples for lidar object detection,” in Proceedings of the IEEE/CVF Conference on Computer Vision and Pattern Recognition , 2020

  88. [94]

    Invisible for both camera and lidar: Security of multi- sensor fusion based perception in autonomous driving under physical- world attacks,

    Y . Cao, N. Wang, C. Xiao, D. Yang, J. Fang, R. Yang, Q. A. Chen, M. Liu and B. Li, “Invisible for both camera and lidar: Security of multi- sensor fusion based perception in autonomous driving under physical- world attacks,” in 2021 IEEE Symposium on Security and Privacy (SP) , 2021

  89. [95]

    Fooling lidar perception via adversarial trajectory perturbation,

    Y . Li, C. Wen, F. Juefei-Xu and C. Feng, “Fooling lidar perception via adversarial trajectory perturbation,” in Proceedings of the IEEE/CVF International Conference on Computer Vision , 2021

  90. [96]

    Towards universal physical attacks on cascaded camera-lidar 3d object detection models,

    M. Abdelfattah, K. Yuan, Z. J. Wang and R. Ward, “Towards universal physical attacks on cascaded camera-lidar 3d object detection models,” in 2021 IEEE International Conference on Image Processing (ICIP) , 2021

  91. [97]

    Generating Adversarial Point Clouds on Multi-modal Fusion Based 3D Object Detection Model,

    H. Wang, H. Shen, B. Zhang, Y . Wen and D. Meng, “Generating Adversarial Point Clouds on Multi-modal Fusion Based 3D Object Detection Model,” in Information and Communications Security: 23rd International Conference, ICICS 2021, Chongqing, China, November 19- 21, 2021, Part I 23, 2021

  92. [98]

    Deeplidar: Deep surface normal guided depth prediction for outdoor scene from sparse lidar data and single color image,

    J. Qiu, Z. Cui, Y . Zhang, X. Zhang, S. Liu, B. Zeng and M. Pollefeys, “Deeplidar: Deep surface normal guided depth prediction for outdoor scene from sparse lidar data and single color image,” in Proceedings of the IEEE/CVF Conference on Computer Vision and Pattern Recognition , 2019

  93. [99]

    Pseudo-LiDAR++: Accurate Depth for 3D Object Detection in Autonomous Driving,

    Y . You, Y . Wang, W.-L. Chao, D. Garg, G. Pleiss, B. Hariharan, M. Campbell and K. Q. Weinberger, “Pseudo-LiDAR++: Accurate Depth for 3D Object Detection in Autonomous Driving,” in International Conference on Learning Representations , 2020

  94. [100]

    Pseudo-lidar from visual depth estimation: Bridging the gap in 3d object detection for autonomous driving,

    Y . Wang, W.-L. Chao, D. Garg, B. Hariharan, M. Campbell and K. Q. Weinberger, “Pseudo-lidar from visual depth estimation: Bridging the gap in 3d object detection for autonomous driving,” in Proceedings of the IEEE/CVF Conference on Computer Vision and Pattern Recognition , 2019

  95. [101]

    Adversarial patch,

    T. B. Brown, D. Man ´e, A. Roy, M. Abadi and J. Gilmer, “Adversarial patch,” arXiv preprint arXiv:1712.09665 , 2017

  96. [102]

    Adversarial attacks on monocular depth estimation,

    Z. Zhang, X. Zhu, Y . Li, X. Chen and Y . Guo, “Adversarial attacks on monocular depth estimation,” arXiv preprint arXiv:2003.10315 , 2020

  97. [103]

    Physical attack on monocular depth estimation with optimal adversarial patches,

    Z. Cheng, J. Liang, H. Choi, G. Tao, Z. Cao, D. Liu and X. Zhang, “Physical attack on monocular depth estimation with optimal adversarial patches,” in Computer Vision–ECCV 2022: 17th European Conference , Tel Aviv, Israel, October 23–27, 2022, Part XXXVIII, 2022

  98. [104]

    Monocular depth estimators: Vulnerabilities and attacks,

    A. Mathew, A. P. Patra and J. Mathew, “Monocular depth estimators: Vulnerabilities and attacks,” arXiv preprint arXiv:2005.14302 , 2020

  99. [105]

    [Online]

    The Autoware Foundation - Open source software for self-driving vehicles. [Online]. Available: https://autoware.org/

  100. [106]

    [Online]

    Apollo Open Platform . [Online]. Available: https://developer.apollo.auto/

  101. [107]

    [Online]

    Hugging Face. [Online]. Available: https://huggingface.co/

  102. [108]

    An empirical study of artifacts and security risks in the pre-trained model supply chain,

    W. Jiang, N. Synovic, R. Sethi, A. Indarapu, M. Hyatt, T. R. Schorlem- mer, G. K. Thiruvathukal and J. C. Davis, “An empirical study of artifacts and security risks in the pre-trained model supply chain,” in Proceedings of the 2022 ACM Workshop on Software Supply Chain Offensi...

  103. [109]

    A comprehensive study of autonomous vehicle bugs,

    J. Garcia, Y . Feng, J. Shen, S. Almanee, Y . Xia, Chen and Q. Alfred, “A comprehensive study of autonomous vehicle bugs,” in Proceedings of the ACM/IEEE 42nd international conference on software engineering , 2020

  104. [110]

    Badnets: Identifying vulner- abilities in the machine learning model supply chain,

    T. Gu, B. Dolan-Gavitt and S. Garg, “Badnets: Identifying vulner- abilities in the machine learning model supply chain,” arXiv preprint arXiv:1708.06733, 2017

  105. [112]

    A comprehensive survey on poisoning attacks and countermeasures in machine learning,

    Z. Tian, L. Cui, J. Liang and S. Yu, “A comprehensive survey on poisoning attacks and countermeasures in machine learning,” ACM Computing Surveys, vol. 55, p. 1–35, 2023

  106. [113]

    Dataset security for machine learning: Data poisoning, backdoor attacks, and defenses,

    M. Goldblum, D. Tsipras, C. Xie, X. Chen, A. Schwarzschild, D. Song, A. Madry, B. Li and T. Goldstein, “Dataset security for machine learning: Data poisoning, backdoor attacks, and defenses,” IEEE Transactions on Pattern Analysis and Machine Intelligence , vol. 45, p. 1563–1580, 2022

  107. [114]

    Poisoning web-scale training datasets is practical,

    N. Carlini, M. Jagielski, C. A. Choquette-Choo, D. Paleka, W. Pearce, H. Anderson, A. Terzis, K. Thomas and F. Tram `er, “Poisoning web-scale training datasets is practical,” arXiv preprint arXiv:2302.10149 , 2023

  108. [115]

    T-bfa: Targeted bit-flip adversarial weight attack,

    A. S. Rakin, Z. He, J. Li, F. Yao, C. Chakrabarti and D. Fan, “T-bfa: Targeted bit-flip adversarial weight attack,” IEEE Transactions on Pattern Analysis and Machine Intelligence , vol. 44, p. 7928–7939, 2021

  109. [116]

    Weight poisoning attacks on pre-trained models,

    K. Kurita, P. Michel and G. Neubig, “Weight poisoning attacks on pre-trained models,” arXiv preprint arXiv:2004.06660 , 2020

  110. [117]

    Microsoft azure machine learning,

    S. Mund, “Microsoft azure machine learning,” Packt Publishing Ltd , 2015

  111. [118]

    Google Cloud AI Services Quick Start Guide: Build Intelligent Applications with Google Cloud AI Services,

    A. Ravulavaru, “Google Cloud AI Services Quick Start Guide: Build Intelligent Applications with Google Cloud AI Services,” Packt Publish- ing Ltd, 2018

  112. [119]

    Vision meets robotics: The kitti dataset,

    A. Geiger, P. Lenz, C. Stiller and R. Urtasun, “Vision meets robotics: The kitti dataset,” The International Journal of Robotics Research , vol. 32, p. 1231–1237, 2013

  113. [120]

    nuscenes: A multimodal dataset for autonomous driving,

    H. Caesar, V . Bankiti, A. H. Lang, S. V ora, V . E. Liong, Q. Xu, A. Krishnan, Y . Pan, G. Baldan and O. Beijbom, “nuscenes: A multimodal dataset for autonomous driving,” in Proceedings of the IEEE/CVF con- ference on computer vision and pattern recognition , 2020

  114. [121]

    The apolloscape dataset for autonomous driving,

    X. Huang, X. Cheng, Q. Geng, B. Cao, D. Zhou, P. Wang, Y . Lin and R. Yang, “The apolloscape dataset for autonomous driving,” in Proceedings of the IEEE conference on computer vision and pattern recognition workshops, 2018

  115. [123]

    Backdoor learning: A survey,

    Y . Li, Y . Jiang, Z. Li and S. T. Xia, “Backdoor learning: A survey,” IEEE Transactions on Neural Networks and Learning Systems , vol. 35, no. 1, pp. 5–22, Jan. 2024

  116. [124]

    A physically realizable backdoor attack on 3D point cloud deep learning: work- in-progress,

    C. Bian, W. Jiang, J. Zhan, Z. Song, X. Wen and H. Lei, “A physically realizable backdoor attack on 3D point cloud deep learning: work- in-progress,” in Proceedings of the 2021 International Conference on Hardware/Software Codesign and System Synthesis , 2021

  117. [125]

    Generative strategy based backdoor attacks to 3D point clouds: work-in-progress,

    X. Wen, W. Jiang, J. Zhan, C. Bian and Z. Song, “Generative strategy based backdoor attacks to 3D point clouds: work-in-progress,” in Pro- ceedings of the 2021 International Conference on Embedded Software , 2021

  118. [126]

    3d object detection for autonomous driving: a survey,

    R. Qian, X. Lai and X. Li, “3d object detection for autonomous driving: a survey,” Pattern Recognition, vol. 130, p. 108796, 2022

  119. [127]

    Towards backdoor attacks against LiDAR object detection in 19 autonomous driving,

    Y . Zhang, Y . Zhu, Z. Liu, C. Miao, F. Hajiaghajani, L. Su and C. Qiao, “Towards backdoor attacks against LiDAR object detection in 19 autonomous driving,” in Proceedings of the 20th ACM Conference on Embedded Networked Sensor Systems , 2022

  120. [128]

    BadFusion: 2D-Oriented Backdoor Attacks against 3D Object Detection,

    S. S. Chaturvedi, L. Zhang, W. Zhang, P. He and X. Yuan, “BadFusion: 2D-Oriented Backdoor Attacks against 3D Object Detection,” in NeurIPS 2023 Workshop on Backdoors in Deep Learning-The Good, the Bad, and the Ugly, 2023

  121. [129]

    High accuracy and high fidelity extraction of neural networks,

    M. Jagielski, N. Carlini, D. Berthelot, A. Kurakin and N. Papernot, “High accuracy and high fidelity extraction of neural networks,” in 29th USENIX security symposium (USENIX Security 20) , 2020

  122. [130]

    Stealing hyperparameters in machine learning,

    B. Wang and N. Z. Gong, “Stealing hyperparameters in machine learning,” in IEEE symposium on security and privacy (SP) , p. 36-52, 2018

  123. [131]

    A taxonomic survey of model extraction attacks,

    D. Genc ¸, M. ¨Ozuysal and E. Tomur, “A taxonomic survey of model extraction attacks,” in 2023 IEEE International Conference on Cyber Security and Resilience (CSR) , 2023

  124. [132]

    I know what you trained last summer: A survey on stealing machine learning models and defences,

    D. Oliynyk, R. Mayer and A. Rauber, “I know what you trained last summer: A survey on stealing machine learning models and defences,” ACM Computing Surveys , vol. 55, p. 1–41, 2023

  125. [133]

    Model inversion attacks that exploit confidence information and basic countermeasures,

    M. Fredrikson, S. Jha and T. Ristenpart, “Model inversion attacks that exploit confidence information and basic countermeasures,” in Proceed- ings of the 22nd ACM SIGSAC conference on computer and communica- tions security, 2015

  126. [134]

    The secret revealer: Generative model-inversion attacks against deep neural networks,

    Y . Zhang, R. Jia, H. Pei, W. Wang, B. Li and D. Song, “The secret revealer: Generative model-inversion attacks against deep neural networks,” in Proceedings of the IEEE/CVF conference on computer vision and pattern recognition , 2020

  127. [135]

    Membership inference attacks against machine learning models,

    R. Shokri, M. Stronati, C. Song and V . Shmatikov, “Membership inference attacks against machine learning models,” in IEEE symposium on security and privacy (SP) , p. 3-18, 2017

  128. [136]

    Membership inference attacks on machine learning: A survey,

    H. Hu, Z. Salcic, L. Sun, G. Dobbie, P. S. Yu and X. Zhang, “Membership inference attacks on machine learning: A survey,” ACM Computing Surveys (CSUR) , vol. 54, p. 1–37, 2022

  129. [137]

    Revealing scenes by inverting structure from motion reconstructions,

    F. Pittaluga, S. J. Koppal, S. B. Kang and S. N. Sinha, “Revealing scenes by inverting structure from motion reconstructions,” in Proceed- ings of the IEEE/CVF Conference on Computer Vision and Pattern Recognition, 2019

  130. [138]

    How You Act Tells a Lot: Privacy-Leaking Attack on Deep Reinforcement Learning.,

    X. Pan, W. Wang, X. Zhang, B. Li, J. Yi and D. Song, “How You Act Tells a Lot: Privacy-Leaking Attack on Deep Reinforcement Learning.,” in AAMAS, 2019

  131. [139]

    Towards multi-modal perception-based navigation: A deep reinforcement learning method,

    X. Huang, H. Deng, W. Zhang, R. Song and Y . Li, “Towards multi-modal perception-based navigation: A deep reinforcement learning method,” IEEE Robotics and Automation Letters , vol. 6, p. 4986–4993, 2021

  132. [140]

    An efficient identity- based batch verification scheme for vehicular sensor networks,

    C. Zhang, R. Lu, X. Lin, P.-H. Ho and X. Shen, “An efficient identity- based batch verification scheme for vehicular sensor networks,” in IEEE INFOCOM 2008-The 27th Conference on Computer Communications , 2008

  133. [141]

    A robust detection of the sybil attack in urban vanets,

    C. Chen, X. Wang, W. Han and B. Zang, “A robust detection of the sybil attack in urban vanets,” in 2009 29th IEEE International Conference on Distributed Computing Systems Workshops , 2009

  134. [142]

    Cooperative Sybil attack detection for position based applications in privacy preserved V ANETs,

    Y . Hao, J. Tang and Y . Cheng, “Cooperative Sybil attack detection for position based applications in privacy preserved V ANETs,” in2011 IEEE Global Telecommunications Conference-GLOBECOM 2011 , 2011

  135. [143]

    Securing vehicle- to-everything (V2X) communication platforms,

    M. Hasan, S. Mohan, T. Shimizu and H. Lu, “Securing vehicle- to-everything (V2X) communication platforms,” IEEE Transactions on Intelligent Vehicles, vol. 5, p. 693–713, 2020

  136. [144]

    Defending against sybil devices in crowdsourced mapping services,

    G. Wang, B. Wang, T. Wang, A. Nika, H. Zheng and B. Y . Zhao, “Defending against sybil devices in crowdsourced mapping services,” Proceedings of the 14th annual international conference on mobile systems, pp. 179-191, 2016

  137. [145]

    Security vulnerabilities of connected vehicle streams and their impact on cooperative driving,

    M. Amoozadeh, A. Raghuramu, C.-N. Chuah, D. Ghosal, H. M. Zhang, J. Rowe and K. Levitt, “Security vulnerabilities of connected vehicle streams and their impact on cooperative driving,” IEEE Communications Magazine, vol. 53, p. 126–132, 2015

  138. [146]

    Credibility enhanced temporal graph convolutional network based sybil attack detection on edge computing servers,

    B. Luo, X. Liu and Q. Zhu, “Credibility enhanced temporal graph convolutional network based sybil attack detection on edge computing servers,” in 2021 IEEE Intelligent Vehicles Symposium (IV) , 2021

  139. [147]

    Sybil Attack Prediction on Vehicle Network Using Deep Learning,

    Z. Helmi, R. Adriman, T. Y . Arif, H. Walidainy and M. Fitria, “Sybil Attack Prediction on Vehicle Network Using Deep Learning,” Jurnal RESTI (Rekayasa Sistem dan Teknologi Informasi) , vol. 6, no. 3, p. 499–504, 2022

  140. [148]

    Intrusion detection method for GPS based on deep learning for autonomous vehicle,

    B. Manale and T. Mazri, “Intrusion detection method for GPS based on deep learning for autonomous vehicle,” International Journal of Electronic Security and Digital Forensic , vol. 14, p. 37–52, 2022

  141. [149]

    Can you trust autonomous vehicles: Contactless attacks against sensors of self-driving vehicle,

    C. Yan, W. Xu and J. Liu, “Can you trust autonomous vehicles: Contactless attacks against sensors of self-driving vehicle,” Def Con, vol. 24, p. 109, 2016

  142. [150]

    Autonomous vehicle ultrasonic sensor vulnerability and impact assessment,

    B. S. Lim, S. L. Keoh and V . L. L. Thing, “Autonomous vehicle ultrasonic sensor vulnerability and impact assessment,” in 2018 IEEE 4th World Forum on Internet of Things (WF-IoT) , 2018

  143. [151]

    Using 3D Shadows to Detect Object Hiding Attacks on Autonomous Vehicle Perception,

    Z. Hau, S. Demetriou and E. C. Lupu, “Using 3D Shadows to Detect Object Hiding Attacks on Autonomous Vehicle Perception,” in IEEE Security and Privacy Workshops (SPW) , 2022

  144. [152]

    Temporal consistency checks to detect LiDAR spoofing attacks on autonomous vehicle perception.,

    C. You, Z. Hau and S. Demetriou, “Temporal consistency checks to detect LiDAR spoofing attacks on autonomous vehicle perception.,” in Proceedings of the 1st Workshop on Security and Privacy for Mobile AI , 2021

  145. [153]

    VLP-16 User Manual,

    VelodyneLiDAR, “VLP-16 User Manual,” 2016. [Online] Avail- able: https://data.ouster.io/downloads/velodyne/user-manual/vlp-16-user- manual-revf.pdf

  146. [154]

    Counteracting adversarial attacks in autonomous driving,

    Q. Sun, A. A. Rao, X. Yao, B. Yu and S. Hu, “Counteracting adversarial attacks in autonomous driving,” in Proceedings of the 39th International Conference on Computer-Aided Design , 2020

  147. [155]

    Towards Deep Learning Models Resistant to Adversarial Attacks,

    A. Madry, A. Makelov, L. Schmidt, D. Tsipras and A. Vladu, “Towards Deep Learning Models Resistant to Adversarial Attacks,” in ICLR, 2018

  148. [156]

    Adversarially robust 3d point cloud recognition using self- supervisions,

    J. Sun, Y . Cao, C. B. Choy, Z. Yu, A. Anandkumar, Z. M. Mao and C. Xiao, “Adversarially robust 3d point cloud recognition using self- supervisions,” Advances in Neural Information Processing Systems , vol. 34, p. 15498–15512, 2021

  149. [157]

    ART-Point: Improving Rotation Robustness of Point Cloud Classifiers via Adversarial Rotation,

    R. Wang, Y . Yang and D. Tao, “ART-Point: Improving Rotation Robustness of Point Cloud Classifiers via Adversarial Rotation,” in 2022 IEEE/CVF Conference on Computer Vision and Pattern Recognition (CVPR), 2022

  150. [158]

    Pointguard: Provably robust 3d point cloud classification,

    H. Liu, J. Jia and N. Z. Gong, “Pointguard: Provably robust 3d point cloud classification,” in Proceedings of the IEEE/CVF conference on Computer Vision and Pattern Recognition , 2021

  151. [159]

    Extending adversarial attacks and defenses to deep 3d point cloud classifiers,

    D. Liu, R. Yu and H. Su, “Extending adversarial attacks and defenses to deep 3d point cloud classifiers,” in 2019 IEEE International Conference on Image Processing (ICIP) , 2019

  152. [160]

    Dup-net: Denoiser and upsampler network for 3d adversarial point clouds defense,

    H. Zhou, K. Chen, W. Zhang, H. Fang, W. Zhou and N. Yu, “Dup-net: Denoiser and upsampler network for 3d adversarial point clouds defense,” in Proceedings of the IEEE/CVF International Conference on Computer Vision, 2019

  153. [161]

    Benchmarking and analyzing point cloud classification under corruptions,

    J. Ren, L. Pan and Z. Liu, “Benchmarking and analyzing point cloud classification under corruptions,” in International Conference on Machine Learning, 2022

  154. [162]

    Benchmarking the robustness of lidar-camera fusion for 3d object detection,

    K. Yu, T. Tao, H. Xie, Z. Lin, Z. Wu, Z. Xia, T. Liang, H. Sun, J. Deng, D. Hao and others, “Benchmarking the robustness of lidar-camera fusion for 3d object detection,” Proceedings of the IEEE/CVF Conference on Computer Vision and Pattern Recognitio , pp. 3188-3198. 2023

  155. [163]

    Benchmarking Robustness of 3D Point Cloud Recognition Against Common Corruptions,

    J. Sun, Q. Zhang, B. Kailkhura, Z. Yu, C. Xiao and Z. Morley Mao, “Benchmarking Robustness of 3D Point Cloud Recognition Against Common Corruptions,”arXiv preprint arXiv:2201.12296 , 2022

  156. [164]

    Privacy protection for 3D point cloud classification based on an optical chaotic encryption scheme,

    B. Liu, Y . Liu, Y . Xie, X. Jiang, Y . Ye, T. Song, J. Chai, M. Liu, M. Feng and H. Yuan, “Privacy protection for 3D point cloud classification based on an optical chaotic encryption scheme,” Optics Express, vol. 31, p. 8820–8843, 2023

  157. [165]

    Beyond Boundaries: A Comprehensive Survey of Transferable Attacks on AI Systems,

    G. Wang, C. Zhou, Y . Wang, B. Chen, H. Guo and Q. Yan, “Beyond Boundaries: A Comprehensive Survey of Transferable Attacks on AI Systems,” arXiv preprint arXiv:2311.11796 , 2023

  158. [166]

    A2d2: Audi autonomous driving dataset,

    J. Geyer, Y . Kassahun, M. Mahmudi, X. Ricou, R. Durgesh, A. S. Chung, L. Hauswald, V . H. Pham, M. M ¨uhlegg, S. Dorn and others, “A2d2: Audi autonomous driving dataset,” arXiv preprint arXiv:2004.06320, 2020

  159. [167]

    DVI: Depth Guided Video Inpainting for Autonomous Driving,

    M. Liao, F. Lu, D. Zhou, S. Zhang, W. Li and R. Yang, “DVI: Depth Guided Video Inpainting for Autonomous Driving,” in European Conference on Computer Vision , 2020

  160. [168]

    Argoverse 2: Next Generation Datasets for Self-Driving Perception and Forecasting,

    B. Wilson, W. Qi, T. Agarwal, J. Lambert, J. Singh, S. Khandelwal, B. Pan, R. Kumar, A. Hartnett, J. K. Pontes and others, “Argoverse 2: Next Generation Datasets for Self-Driving Perception and Forecasting,” in 35th Conference on Neural Information Processing Systems (NeurIPS

  161. [169]

    CARLA: An open urban driving simulator,

    A. Dosovitskiy, G. Ros, F. Codevilla, A. Lopez and V . Koltun, “CARLA: An open urban driving simulator,” in Conference on robot learning, 2017

  162. [170]

    KITTI-CARLA: a KITTI-like dataset generated by CARLA Simulator,

    J.-E. Deschaud, “KITTI-CARLA: a KITTI-like dataset generated by CARLA Simulator,” arXiv preprint arXiv:2109.00892, 2021

  163. [171]

    CarlaScenes: A synthetic dataset for odometry in autonomous driving,

    A. Kloukiniotis, A. Papandreou, C. Anagnostopoulos, A. Lalos, P. Kapsalas, D.-V . Nguyen and K. Moustakas, “CarlaScenes: A synthetic dataset for odometry in autonomous driving,” in Proceedings of the IEEE/CVF Conference on Computer Vision and Pattern Recognition , 2022

  164. [172]

    The h3d dataset for full- surround 3d multi-object detection and tracking in crowded urban scenes,

    A. Patil, S. Malla, H. Gang and Y .-T. Chen, “The h3d dataset for full- surround 3d multi-object detection and tracking in crowded urban scenes,” 20 in 2019 International Conference on Robotics and Automation (ICRA) , 2019

  165. [173]

    KAIST multi-spectral day/night data set for autonomous and assisted driving,

    Y . Choi, N. Kim, S. Hwang, K. Park, J. S. Yoon, K. An and I. S. Kweon, “KAIST multi-spectral day/night data set for autonomous and assisted driving,” IEEE Transactions on Intelligent Transportation Systems , vol. 19, p. 934–948, 2018

  166. [174]

    Complex urban dataset with multi-level sensors from highly diverse urban environments,

    J. Jeong, Y . Cho, Y .-S. Shin, H. Roh and A. Kim, “Complex urban dataset with multi-level sensors from highly diverse urban environments,” The International Journal of Robotics Research , vol. 38, p. 642–657, 2019

  167. [175]

    One thousand and one hours: Self-driving motion prediction dataset,

    J. Houston, G. Zuidhof, L. Bergamini, Y . Ye, L. Chen, A. Jain, S. Omari, V . Iglovikov and P. Ondruska, “One thousand and one hours: Self-driving motion prediction dataset,” in Conference on Robot Learning, 2021

  168. [176]

    One Million Scenes for Autonomous Driving: ONCE Dataset,

    J. Mao, M. Niu, C. Jiang, J. Chen, X. Liang, Y . Li, C. Ye, W. Zhang, Z. Li, J. Yu and others, “One Million Scenes for Autonomous Driving: ONCE Dataset,” in 35th Conference on Neural Information Processing Systems (NeurIPS 2021) Track on Datasets and Benchmarks (Round 1) , 2021

  169. [177]

    1 year, 1000 km: The oxford robotcar dataset,

    W. Maddern, G. Pascoe, C. Linegar and P. Newman, “1 year, 1000 km: The oxford robotcar dataset,” The International Journal of Robotics Research, vol. 36, p. 3–15, 2017

  170. [178]

    TorontoCity: Seeing the World with a Million Eyes,

    S. Wang, M. Bai, G. Mattyus, H. Chu, W. Luo, B. Yang, J. Liang, J. Cheverie, S. Fidler and R. Urtasun, “TorontoCity: Seeing the World with a Million Eyes,” in 2017 IEEE International Conference on Computer Vision (ICCV), 2017

  171. [179]

    Woodscape: A multi-task, multi-camera fisheye dataset for autonomous driving,

    S. Yogamani, C. Hughes, J. Horgan, G. Sistu, P. Varley, D. O’Dea, M. Uric ´ar, S. Milz, M. Simon, K. Amende and others, “Woodscape: A multi-task, multi-camera fisheye dataset for autonomous driving,” in Proceedings of the IEEE/CVF International Conference on Computer Vision, 2...

  172. [711]

    Springer International Publishing, 2021

  173. [2021]

    Track on Datasets and Benchmarks (Round 2) , 2021

Pith tools

Reviewed August 12, 2026 · model on record in the stance chip above.