REVIEW 4 major objections 6 minor 52 references
CP-Guard: Malicious Agent Detection and Defense in Collaborative Bird's Eye View Perception
T0 review · 4 major / 6 minor · reviewed 2026-08-11 · deepseek-v4-flash
Pith's one-line read A vehicle can detect malicious collaborators by checking whether fused perception agrees with its own view.
desk verdict The defense idea is plausible and the ROBOSAC comparison is useful, but Algorithm 1 as printed inverts its own detection rule, so the central results are unsupported until that is fixed. read the letter →
The pith
A machine-rendered reading of the paper's core claim, the machinery that carries it, and where it could break.
The reading
What carries the argument
The load-bearing mechanism is the combination of collaborative consistency loss (CCLoss) and probability-agnostic sample consensus (PASAC). CCLoss is a class-weighted overlap between the ego vehicle's own BEV segmentation map and the map produced after fusing a group of collaborators' features; values near 1 mean agreement, values near 0 mean conflict, and a threshold epsilon (set to 0.08 in experiments) decides whether a group is suspected of containing a malicious agent. PASAC recursively splits any suspected group in half, accepts a half wholesale once it passes the consensus test, and keeps splitting until all agents are classified or enough benign agents are collected. The mechanism's efficiency comes from accepting large benign groups without checking each agent, and its correctness depends on every group containing a malicious agent having a detectably low CCLoss.
What would settle it
Run PASAC on a group of 15 benign agents plus one adversarially perturbed agent with the perturbation size held at delta = 0.1, and record whether the group-level CCLoss stays above the epsilon = 0.08 threshold; if it does, the malicious agent is added to the benign set and the defense silently fails. Equivalently, optimize the perturbation to maximize segmentation loss while also maximizing CCLoss(Y0, Yfuse), and check whether a group containing only that malicious agent passes the consensus test.
Extended reading notes
Core claim
The central claim is that consensus with the ego vehicle's own perception is enough to identify malicious collaborators in intermediate-feature collaborative perception. The framework computes a collaborative consistency loss (CCLoss) between the ego-only BEV segmentation and the segmentation produced after fusing a group's features; a group whose loss falls below a threshold is treated as containing a malicious agent and is recursively split, while a group whose loss stays above the threshold is accepted wholesale as benign. This makes the defense probability-agnostic: it never needs the fraction of malicious agents. On the V2X-Sim dataset, CP-Guard achieves mIoU 39.30 against FGSM, 39.34 against PGD, and 37.95 against C&W, compared with an upper bound of 40.45 and undefended scores as low as 14.34.
Load-bearing premise
The defense assumes that any group containing a malicious agent will still look sufficiently different from the ego vehicle's own view to fail the consensus test, even when the malicious agent's feature is diluted by many benign agents in that group.
Editorial extensions
If this is right
- Each connected vehicle can run CP-Guard locally, so the defense adds no training-time burden and does not need to know the attack type in advance.
- Because PASAC accepts whole groups that pass the consensus test, verification cost grows far more slowly than checking agents one by one, scaling to large collaboration sets.
- The threshold epsilon controls a false-positive/false-negative trade-off: too small and benign collaborators are distrusted, too large and malicious agents pass as benign.
- The C&W result is the weakest of the three, indicating that stronger, fine-grained attacks narrow the gap between defended and upper-bound performance.
- If an attacker can make a malicious group's fused output agree with the ego view, the defense's consensus test is the single point of failure.
Reading between the lines
- An adaptive attacker who optimizes perturbations to keep group-level CCLoss above epsilon, rather than only maximizing segmentation loss, could plausibly bypass PASAC; this is a testable extension the paper does not consider.
- The same consensus principle could be transferred to object-level fusion for 3D detection, replacing CCLoss with box-level agreement metrics such as IoU, though calibration would differ.
- The threshold may need to adapt to scene difficulty, since the ego-only segmentation itself varies in quality, and a fixed epsilon that works on V2X-Sim may not transfer to other datasets or weather conditions.
- Recursive group acceptance assumes failures are detectable at every group size; this non-dilution property deserves explicit measurement in future work.
Editorial analysis
A structured set of objections, weighed in public.
Referee Report
Summary. The paper proposes CP-Guard, a defense for collaborative BEV perception against malicious agents that transmit adversarially perturbed intermediate feature maps. The method combines PASAC, a recursive divide-and-conquer sampling procedure that splits collaborator groups and decides whether each group contains a malicious agent, with CCLoss, a similarity measure between the ego vehicle's BEV segmentation and the fused segmentation of a group. If CCLoss is below a threshold, the group is treated as containing malicious agents and is split further; otherwise the whole group is accepted as benign. Experiments on V2X-Sim with FGSM, C&W, and PGD attacks report mIoU values close to the upper bound and lower verification counts than the prior ROBOSAC method.
Significance. If the method works as described, it offers a lightweight, probability-agnostic consensus filter for collaborative perception, which would be a practical improvement over approaches that require prior malicious-agent probabilities or per-agent checks. The paper also provides a useful angle by treating the consensus problem as recursive verification rather than individual inspection. However, the reported results currently rest on a pseudocode base case that contradicts the stated verification rule, and the threshold is tuned on the evaluation data, so the experimental claims are not yet credible as presented.
major comments (4)
- [Algorithm 1, lines 6–11] The singleton base case inverts the verification rule stated in Eq. (5) and in the surrounding text. Eq. (5) defines LCCLoss(Y0,Yk) ≤ ε as evidence that a malicious agent is present, and the recursive branches (lines 16–27) follow this rule by splitting low-CCLoss groups and accepting high-CCLoss groups. In the base case, however, line 8 adds Fk to the benign set exactly when LCCLoss(Y0,Yk) ≤ ε, and benign singletons (LCCLoss > ε) are never added. As written, PASAC therefore retains malicious agents and discards benign ones, so the mIoU values in Table 1 cannot be produced by this algorithm. The pseudocode must be corrected (for example, by reversing the condition) and the experimental pipeline must be re-run or re-verified.
- [Ablation Studies, Table 2] The threshold ε = 0.08 is selected by sweeping against PGD attack on what appears to be the same evaluation split used for the main results in Table 1. This constitutes test-set tuning for PGD, and the same threshold is then applied to FGSM and C&W in Table 1, so the claimed generalization has a circular component. The authors should select ε on a separate validation split and report detection rates, false-positive rates, and variance (for example, multiple runs or confidence intervals) for the reported mIoU values.
- [Probability-Agnostic Sample Consensus, Algorithm 1] The recursive splitting assumes that any group containing a malicious agent will produce LCCLoss(Y0,YG) ≤ ε no matter how many benign agents are in the group. If a single malicious feature is diluted by many benign features, the group may pass the consensus test and the malicious agent will be absorbed into the benign set. This non-dilution assumption is load-bearing for PASAC's correctness, but it is neither proved nor tested across group sizes. The paper should provide empirical or theoretical evidence for this assumption, or explicitly state it as a limitation.
- [Evaluation of PASAC, Fig. 2 and Table 3] The 'Verification Count' metric is not precisely defined: it is unclear whether it counts group-level evaluations, feature-map fusion operations, or individual agent checks. The paper also reports no detection accuracy or false-positive rate for the sampled subsets, so the claim that PASAC 'accurately detects and eliminates' malicious agents is not quantitatively supported. Please define the metric and add detection/false-positive statistics alongside verification counts.
minor comments (6)
- [Eq. (4)] The definition of w_j is ambiguous: as printed, the index i in p0_{i,j} and pfuse_{i,j} is not bound within the weight formula, and the denominator lacks explicit parentheses. Please rewrite the equation with clear indexing and grouping.
- [Table 1] The 'Upper-bound' and 'Lower-bound' rows are not defined in the text; please state which configurations they correspond to (for example, all-benign and ego-only settings).
- [Algorithm 1] The procedure uses {Bi} as if it were a global variable that is not initialized; please specify its initialization and scope explicitly.
- [Algorithm 1] The text says the collaborators are 'randomly split' into two groups, but the pseudocode does not include any randomization; please clarify the splitting procedure in the pseudocode.
- [Throughout] The notation 'CA Vs' and 'CAV' is used inconsistently; please standardize the terminology.
- [Reproducibility] The code repository link is given, but no code archive, configuration file, or reproducibility checklist is included; please provide the code or a detailed experimental configuration in a supplementary document.
Circularity Check
PGD defense result is the maximum of the ε-ablation grid (fitted input called prediction); Algorithm 1's singleton branch inverts the Eq. (5) malicious verdict, a correctness flaw independent of circularity.
-
fitted input called prediction
[Quantitative Evaluation / Table 1; Ablation Studies / Table 2]
"Specifically, for the FGSM and PGD attacks, setting the CCLoss threshold to ε = 0.08 proves optimal experimentally. This configuration allows CP-Guard to maximally leverage its defensive mechanisms, yielding mIoU scores of 39.30 and 39.34, respectively. ... Based on these ablation results, we determine that the optimal CCLoss threshold for CP-Guard against PGD attacks is 0.08."
The defense's only decision variable is ε in Eq. (5), which determines whether collaborators are eliminated. The paper selects ε by scanning it on the PGD evaluation data (Table 2: ε = 0.02, 0.05, 0.08, 0.10, 0.12, 0.15) and picking the value with the highest mIoU. Table 1 then reports CP-Guard's PGD mIoU (39.34) under exactly that ε, a number identical to the maximum of the ablation grid. Hence the PGD row is the result of fitting the threshold to the evaluation metric, not an independent prediction of defensive capability. The FGSM and C&W rows were not tuned in this way, so the circularity is partial.
full rationale
The main circularity is the PGD row of Table 1: ε is the threshold controlling whether a collaborator is dropped, and the ablation study chooses ε=0.08 because it maximizes PGD mIoU; reporting that same maximized number as evidence of defense against PGD reduces that claim to the fit by construction. The FGSM and C&W results provide independent (though limited) validation, since ε was not tuned on them, so the paper does not reduce entirely to its inputs. No load-bearing self-citation was found: the many self-citations in related work are contextual, and no uniqueness theorem or prior result is used to force the design. The CCLoss is essentially a weighted Dice similarity; using it as a consensus score is a design assumption, not a circular step. Separately, Algorithm 1 lines 6-10 are internally inconsistent with Eq. (5): a singleton with LCCLoss ≤ ε satisfies the Eq. (5) malicious condition yet is added to the benign set, while a singleton with LCCLoss > ε (benign per Eq. (5)) is discarded. This makes the reported Table 1 numbers non-reproducible from the published pseudocode; it is a serious correctness flaw and is flagged here, but it is not a circularity and therefore does not by itself change the circularity score.
Assumptions & free parameters
free parameters (1)
- CCLoss threshold epsilon =
0.08 (optimal per Table 2 ablation on PGD)
assumptions (3)
- domain assumption A group containing any malicious agent will produce fused output with low CCLoss, and a group of only benign agents will produce high CCLoss.
- ad hoc to paper There exists a threshold epsilon that separates benign and malicious consensus values across all group sizes and attacks.
- domain assumption The attacker is white-box, with bounded perturbation delta <= 0.1, and does not adapt to the defense.
Cite this review
Pith. "Pith review of CP-Guard: Malicious Agent Detection and Defense in Collaborative Bird's Eye View Perception." pith.science (2026). https://pith.science/paper/BOXHLCFZ
@misc{pith2026241212000,
author = {Pith},
title = {Pith review of: CP-Guard: Malicious Agent Detection and Defense in Collaborative Bird's Eye View Perception},
year = {2026},
howpublished = {\url{https://pith.science/paper/BOXHLCFZ}},
note = {Machine review of arXiv:2412.12000}
}
read the original abstract
Collaborative Perception (CP) has shown a promising technique for autonomous driving, where multiple connected and autonomous vehicles (CAVs) share their perception information to enhance the overall perception performance and expand the perception range. However, in CP, ego CAV needs to receive messages from its collaborators, which makes it easy to be attacked by malicious agents. For example, a malicious agent can send harmful information to the ego CAV to mislead it. To address this critical issue, we propose a novel method, CP-Guard, a tailored defense mechanism for CP that can be deployed by each agent to accurately detect and eliminate malicious agents in its collaboration network. Our key idea is to enable CP to reach a consensus rather than a conflict against the ego CAV's perception results. Based on this idea, we first develop a probability-agnostic sample consensus (PASAC) method to effectively sample a subset of the collaborators and verify the consensus without prior probabilities of malicious agents. Furthermore, we define a collaborative consistency loss (CCLoss) to capture the discrepancy between the ego CAV and its collaborators, which is used as a verification criterion for consensus. Finally, we conduct extensive experiments in collaborative bird's eye view (BEV) tasks and our results demonstrate the effectiveness of our CP-Guard. Code is available at https://github.com/CP-Security/CP-Guard
Figures
Reference graph
Works this paper leans on
-
[1]
, " * write output.state after.block = add.period write newline
ENTRY address archivePrefix author booktitle chapter edition editor eid eprint howpublished institution isbn journal key month note number organization pages publisher school series title type volume year label extra.label sort.label short.list INTEGERS output.state before.all mid.sentence after.sentence after.block FUNCTION init.state.consts #0 'before.a...
-
[2]
write newline
" write newline "" before.all 'output.state := FUNCTION n.dashify 't := "" t empty not t #1 #1 substring "-" = t #1 #2 substring "--" = not "--" * t #2 global.max substring 't := t #1 #1 substring "-" = "-" * t #2 global.max substring 't := while if t #1 #1 substring * t #2 global.max substring 't := if while FUNCTION word.in bbl.in capitalize " " * FUNCT...
-
[3]
Carlini, N.; and Wagner, D. 2017. Towards Evaluating the Robustness of Neural Networks. arXiv:1608.04644
arXiv 2017
-
[4]
Fang, Z.; Hu, S.; An, H.; Zhang, Y.; Wang, J.; Cao, H.; Chen, X.; and Fang, Y. Aug. 2024. PACP: P riority-Aware Collaborative Perception for Connected and Autonomous Vehicles. IEEE Transaction of Mobile Computing (DOI: 10.1109/TMC.2024.3449371)
arXiv 2024
-
[5]
Fang, Z.; Hu, S.; Wang, J.; Deng, Y.; Chen, X.; and Fang, Y. 2024 a . Prioritized Information Bottleneck Theoretic Framework with Distributed Online Learning for Edge Video Analytics. arXiv:2409.00146
work page Pith review arXiv 2024
-
[6]
Fang, Z.; Hu, S.; Yang, L.; Deng, Y.; Chen, X.; and Fang, Y. 2024 b . PIB: Prioritized Information Bottleneck Framework for Collaborative Edge Video Analytics. arXiv:2408.17047
work page Pith review arXiv 2024
-
[7]
Fang, Z.; Lin, Z.; Hu, S.; Cao, H.; Deng, Y.; Chen, X.; and Fang, Y. 2024 c . IC3M: In-Car Multimodal Multi-object Monitoring for Abnormal Status of Both Driver and Passengers. arXiv:2410.02592
arXiv 2024
-
[8]
Fang, Z.; Wang, J.; Du, J.; Hou, X.; Ren, Y.; and Han, Z. 2022. Stochastic Optimization-Aided Energy-Efficient Information Collection in Internet of Underwater Things Networks. IEEE Internet of Things Journal, 9(3): 1775--1789
work page 2022
Show all 52 references
-
[9]
Fang, Z.; Wang, J.; Jiang, C.; Zhang, Q.; and Ren, Y. 2021. AoI-Inspired Collaborative Information Collection for AUV-Assisted Internet of Underwater Things. IEEE Internet of Things Journal, 8(19): 14559--14571
2021
-
[10]
Fang, Z.; Wang, J.; Ma, Y.; Tao, Y.; Deng, Y.; Chen, X.; and Fang, Y. 2024 d . R-ACP: Real-Time Adaptive Collaborative Perception Leveraging Robust Task-Oriented Communications. arXiv:2410.04168
2024 arXiv
-
[11]
J.; Shlens, J.; and Szegedy, C
Goodfellow, I. J.; Shlens, J.; and Szegedy, C. 2015. Explaining and Harnessing Adversarial Examples. arXiv:1412.6572
2015 arXiv
-
[12]
S.; Liu, Y.; Cao, Y.; Mao, Z
Hallyburton, R. S.; Liu, Y.; Cao, Y.; Mao, Z. M.; and Pajic, M. 2022. Security Analysis of Camera-LiDAR Fusion Against Black-Box Attacks on Autonomous Vehicles. In 31st USENIX Security Symposium (USENIX Security 22), 1903--1920. Boston, MA: USENIX Association. ISBN 978-1-939133-31-1
2022
-
[13]
Han, Y.; Zhang, H.; Li, H.; Jin, Y.; Lang, C.; and Li, Y. 2023. Collaborative Perception in Autonomous Driving : Methods , Datasets and Challenges . IEEE Intelligent Transportation Systems Magazine, 15(6): 131--151. ArXiv:2301.06262 [cs]
2023 arXiv
-
[14]
Hu, S.; Fang, Z.; An, H.; Xu, G.; Zhou, Y.; Chen, X.; and Fang, Y. 2023. Adaptive Communications in Collaborative Perception with Domain Alignment for Autonomous Driving . ArXiv:2310.00013 [cs]
2023 arXiv
-
[15]
Hu, S.; Fang, Z.; Deng, Y.; Chen, X.; and Fang, Y. 2024 a . Collaborative Perception for Connected and Autonomous Driving : Challenges , Possible Solutions and Opportunities . ArXiv:2401.01544 [cs, eess]
2024 arXiv
-
[16]
Hu, S.; Fang, Z.; Deng, Y.; Chen, X.; Fang, Y.; and Kwong, S. 2024 b . Toward Full-Scene Domain Generalization in Multi-Agent Collaborative Bird's Eye View Segmentation for Connected and Autonomous Driving. IEEE Transactions on Intelligent Transportation Systems, 1--14
2024
-
[17]
Hu, S.; Fang, Z.; Fang, Z.; Deng, Y.; Chen, X.; and Fang, Y. 2024 c . AgentsCoDriver : Large Language Model Empowered Collaborative Driving with Lifelong Learning . ArXiv:2404.06345 [cs]
2024 arXiv
-
[18]
Hu, S.; Fang, Z.; Fang, Z.; Deng, Y.; Chen, X.; Fang, Y.; and Kwong, S. 2024 d . AgentsCoMerge: Large Language Model Empowered Collaborative Decision Making for Ramp Merging. arXiv:2408.03624
2024 arXiv
-
[19]
Lei, Z.; Ren, S.; Hu, Y.; Zhang, W.; and Chen, S. 2022. Latency-Aware Collaborative Perception. In Computer Vision – ECCV 2022: 17th European Conference, Tel Aviv, Israel, October 23–27, 2022, Proceedings, Part XXXII, 316–332. Berlin, Heidelberg: Springer-Verlag
2022
-
[20]
Li, Y.; Fang, Q.; Bai, J.; Chen, S.; Juefei-Xu, F.; and Feng, C. 2023. Among Us : Adversarially Robust Collaborative Perception by Consensus . In 2023 IEEE / CVF International Conference on Computer Vision ( ICCV ) , 186--195. Paris, France: IEEE. ISBN 9798350307184
2023
-
[21]
Li, Y.; Ma, D.; An, Z.; Wang, Z.; Zhong, Y.; Chen, S.; and Feng, C. 2022. V2X - Sim : Multi - Agent Collaborative Perception Dataset and Benchmark for Autonomous Driving . IEEE Robotics and Automation Letters, 7(4): 10914--10921
2022
-
[22]
Li, Y.; Wen, C.; Juefei-Xu, F.; and Feng, C. 2021. Fooling LiDAR Perception via Adversarial Trajectory Perturbation. In Proceedings of the IEEE/CVF International Conference on Computer Vision (ICCV)
2021
-
[23]
Lin, Z.; Chen, Z.; Fang, Z.; Chen, X.; Wang, X.; and Gao, Y. 2024 a . FedSN: A Federated Learning Framework over Heterogeneous LEO Satellite Networks. IEEE Transactions on Mobile Computing, 1--15
2024
-
[24]
Lin, Z.; Qu, G.; Chen, Q.; Chen, X.; Chen, Z.; and Huang, K. 2023 a . Pushing Large Language Models to the 6G Edge : Vision , Challenges , and Opportunities . ArXiv:2309.16739 [cs]
2023 arXiv
-
[25]
Lin, Z.; Qu, G.; Chen, X.; and Huang, K. 2023 b . Split Learning in 6G Edge Networks . ArXiv:2306.12194 [cs]
2023 arXiv
-
[26]
Lin, Z.; Qu, G.; Wei, W.; Chen, X.; and Leung, K. K. 2024 b . AdaptSFL : Adaptive Split Federated Learning in Resource -constrained Edge Networks . ArXiv:2403.13101 [cs]
2024 arXiv
-
[27]
Lin, Z.; Wei, W.; Chen, Z.; Lam, C.-T.; Chen, X.; Gao, Y.; and Luo, J. 2024 c . Hierarchical Split Federated Learning: Convergence Analysis and System Optimization. arXiv:2412.07197
2024 arXiv
-
[28]
Lin, Z.; Zhu, G.; Deng, Y.; Chen, X.; Gao, Y.; Huang, K.; and Fang, Y. 2024 d . Efficient Parallel Split Learning over Resource -constrained Wireless Edge Networks . IEEE Transactions on Mobile Computing, 1--16. Conference Name: IEEE Transactions on Mobile Computing
2024
-
[29]
Lu, Y.; Hu, Y.; Zhong, Y.; Wang, D.; Wang, Y.; and Chen, S. 2024. An Extensible Framework for Open Heterogeneous Collaborative Perception. In The Twelfth International Conference on Learning Representations
2024
-
[30]
Lu, Y.; Li, Q.; Liu, B.; Dianati, M.; Feng, C.; Chen, S.; and Wang, Y. 2023. Robust Collaborative 3D Object Detection in Presence of Pose Errors. In 2023 IEEE International Conference on Robotics and Automation (ICRA), 4812--4818
2023
-
[31]
Madry, A.; Makelov, A.; Schmidt, L.; Tsipras, D.; and Vladu, A. 2018. Towards Deep Learning Models Resistant to Adversarial Attacks. In International Conference on Learning Representations
2018
-
[32]
Ni, T.; Chen, Y.; Xu, W.; Xue, L.; and Zhao, Q. 2023 a . XPorter: A study of the multi-port charger security on privacy leakage and voice injection. In Proceedings of the 29th Annual International Conference on Mobile Computing and Networking, 1--15
2023
-
[33]
Ni, T.; Lan, G.; Wang, J.; Zhao, Q.; and Xu, W. 2023 b . Eavesdropping Mobile App Activity via \ Radio-Frequency \ Energy Harvesting. In 32nd USENIX Security Symposium (USENIX Security 23), 3511--3528
2023
-
[34]
Ni, T.; Li, J.; Zhang, X.; Zuo, C.; Wang, W.; Xu, W.; Luo, X.; and Zhao, Q. 2023 c . Exploiting contactless side channels in wireless charging power banks for user privacy inference via few-shot learning. In Proceedings of the 29th Annual International Conference on Mobile Com...
2023
-
[35]
Ni, T.; Zhang, X.; and Zhao, Q. 2023. Recovering Fingerprints from In-Display Fingerprint Sensors via Electromagnetic Side Channel. In Proceedings of the 2023 ACM SIGSAC Conference on Computer and Communications Security, 253--267
2023
-
[36]
Ni, T.; Zhang, X.; Zuo, C.; Li, J.; Yan, Z.; Wang, W.; Xu, W.; Luo, X.; and Zhao, Q. 2023 d . Uncovering user interactions on smartphones via contactless wireless charging side channels. In 2023 IEEE Symposium on Security and Privacy (SP), 3399--3415. IEEE
2023
-
[37]
Qu, G.; Chen, Q.; Wei, W.; Lin, Z.; Chen, X.; and Huang, K. 2024 a . Mobile edge intelligence for large language models: A contemporary survey. arXiv preprint arXiv:2407.18921
2024 arXiv
-
[38]
Qu, G.; Lin, Z.; Chen, Q.; Li, J.; Liu, F.; Chen, X.; and Huang, K. 2024 b . TrimCaching : Parameter-sharing Edge Caching for AI Model Downloading. arXiv preprint arXiv:2404.14204
2024 arXiv
-
[39]
Qu, G.; Lin, Z.; Liu, F.; Chen, X.; and Huang, K. 2024 c . TrimCaching : Parameter-sharing AI Model Caching in Wireless Edge Networks. In 2024 IEEE 44th International Conference on Distributed Computing Systems (ICDCS), 36--46
2024
-
[40]
M.; Yang, F.; Duchi, J
Raghunathan, A.; Xie, S. M.; Yang, F.; Duchi, J. C.; and Liang, P. 2020. Understanding and mitigating the tradeoff between robustness and accuracy. In Proceedings of the 37th International Conference on Machine Learning , volume 119 of ICML '20 , 7909--7919. JMLR.org
2020
-
[41]
Ren, S.; Lei, Z.; Wang, Z.; Dianati, M.; Wang, Y.; Chen, S.; and Zhang, W. 2024. Interruption-Aware Cooperative Perception for V2X Communication-Aided Autonomous Driving. IEEE Transactions on Intelligent Vehicles, 9(4): 4698--4714
2024
-
[42]
Ronneberger, O.; Fischer, P.; and Brox, T. 2015. U- Net : Convolutional Networks for Biomedical Image Segmentation . ArXiv:1505.04597 [cs]
2015 arXiv
-
[43]
A.; Bischoff, D.; Krost, J
Schiegg, F. A.; Bischoff, D.; Krost, J. R.; and Llatser, I. 2020. Analytical Performance Evaluation of the Collective Perception Service in IEEE 802.11p Networks. In 2020 IEEE Wireless Communications and Networking Conference (WCNC), 1--6
2020
-
[44]
Su, W.; Chen, L.; Bai, Y.; Lin, X.; Li, G.; Qu, Z.; and Zhou, P. 2024. What Makes Good Collaborative Views? Contrastive Mutual Information Maximization for Multi-Agent Perception. Proceedings of the AAAI Conference on Artificial Intelligence, 38(16): 17550--17558
2024
-
[45]
Tao, Y.; Hu, S.; Fang, Z.; and Fang, Y. 2024. Direct-CP: Directed Collaborative Perception for Connected and Autonomous Vehicles via Proactive Attention. arXiv:2409.08840
2024
-
[46]
Tu, J.; Ren, M.; Manivasagam, S.; Liang, M.; Yang, B.; Du, R.; Cheng, F.; and Urtasun, R. 2020. Physically Realizable Adversarial Examples for LiDAR Object Detection. In IEEE/CVF Conference on Computer Vision and Pattern Recognition (CVPR)
2020
-
[47]
Tu, J.; Wang, T.; Wang, J.; Manivasagam, S.; Ren, M.; and Urtasun, R. 2021. Adversarial Attacks On Multi - Agent Communication . In 2021 IEEE / CVF International Conference on Computer Vision ( ICCV ) , 7748--7757. ISSN: 2380-7504
2021
-
[48]
Wang, T.-H.; Manivasagam, S.; Liang, M.; Yang, B.; Zeng, W.; and Urtasun, R. 2020. V2VNet: Vehicle-to-Vehicle Communication for Joint Perception and Prediction. In Computer Vision - ECCV 2020: 16th European Conference, Glasgow, UK, August 23-28, 2020, Proceedings, Part II, 605...
2020
-
[49]
Yuan, S.; Li, H.; Han, X.; Xu, G.; Jiang, W.; Ni, T.; Zhao, Q.; and Fang, Y. 2024. ITPatch: An Invisible and Triggered Physical Adversarial Patch against Traffic Sign Recognition. arXiv preprint arXiv:2409.12394
2024
-
[50]
Zhang, J.; and Li, C. 2020. Adversarial Examples : Opportunities and Challenges . IEEE Transactions on Neural Networks and Learning Systems, 31(7): 2578--2593. Conference Name: IEEE Transactions on Neural Networks and Learning Systems
2020
-
[51]
A.; and Mao, Z
Zhang, Q.; Jin, S.; Zhu, R.; Sun, J.; Zhang, X.; Chen, Q. A.; and Mao, Z. M. 2023. On Data Fabrication in Collaborative Vehicular Perception : Attacks and Countermeasures . ArXiv:2309.12955 [cs]
2023 arXiv
-
[52]
Zhao, Y.; Xiang, Z.; Yin, S.; Pang, X.; Chen, S.; and Wang, Y. 2023. Malicious Agent Detection for Robust Multi - Agent Collaborative Perception . ArXiv:2310.11901 [cs]
2023 arXiv
Reviewed August 11, 2026 · model on record in the stance chip above.
Discussion (0). Continue with ORCID to comment.