The development of Large Vision-Language Models (LVLMs) in autonomous driving systems leverages their advanced multimodal reasoning capabilities for crucial tasks such as perception, prediction, and control mechanisms. However, these models are vulnerable to adversarial attacks, raising concerns about their reliability and safety in real-world applications. To explore more critical corner cases in autonomous driving systems and the vulnerabilities of LVLMs, we propose Uni-Attack, a unified framework for black-box adversarial attacks against LVLMs in autonomous driving. Uni-Attack comprises three components: (1) open-vocabulary object detection module which flexibly extracts the candidate attacked target blocks. (2) gradient noise-based module which attacks the alignment embeddings among different modalities; (3) typographic-based module which takes responsibility for attacking the downstream tasks on both image-level and region-level reasoning. Uni-Attack is a dataset-agnostic and task-agnostic framework for generating misleading responses that can compromise the reasoning abilities of LVLMs. Our empirical study evaluates the effectiveness, transferability, and practical implementation of this unified framework in realistic traffic scenarios. The results reveal the significant threat to LVLMs such as LLaVA, Qwen-VL, VILA, and Imp, highlighting the necessity for increased awareness and improved defenses against such vulnerabilities in autonomous driving systems. Our findings aim to inform the community about the potential risks and encourage the development of more robust LVLMs for safe and reliable autonomous driving.

错误:搜索内容不能为空,请输入英文关键词
错误:关键词超出字数限制,请精简
高级检索

Uni-Attack: A Unified Framework for Black-Box Adversarial Attacks Against LVLMs in Autonomous Driving

  • Hongda Chen,
  • Rui Zhang,
  • Baogen Xu,
  • Yongquan Zhang

摘要

The development of Large Vision-Language Models (LVLMs) in autonomous driving systems leverages their advanced multimodal reasoning capabilities for crucial tasks such as perception, prediction, and control mechanisms. However, these models are vulnerable to adversarial attacks, raising concerns about their reliability and safety in real-world applications. To explore more critical corner cases in autonomous driving systems and the vulnerabilities of LVLMs, we propose Uni-Attack, a unified framework for black-box adversarial attacks against LVLMs in autonomous driving. Uni-Attack comprises three components: (1) open-vocabulary object detection module which flexibly extracts the candidate attacked target blocks. (2) gradient noise-based module which attacks the alignment embeddings among different modalities; (3) typographic-based module which takes responsibility for attacking the downstream tasks on both image-level and region-level reasoning. Uni-Attack is a dataset-agnostic and task-agnostic framework for generating misleading responses that can compromise the reasoning abilities of LVLMs. Our empirical study evaluates the effectiveness, transferability, and practical implementation of this unified framework in realistic traffic scenarios. The results reveal the significant threat to LVLMs such as LLaVA, Qwen-VL, VILA, and Imp, highlighting the necessity for increased awareness and improved defenses against such vulnerabilities in autonomous driving systems. Our findings aim to inform the community about the potential risks and encourage the development of more robust LVLMs for safe and reliable autonomous driving.