Shadow-catcher: looking into shadows to detect ghost objects in autonomous vehicle 3D sensing

Title: Shadow-catcher: looking into shadows to detect ghost objects in autonomous vehicle 3D sensing
Authors: Hau, Z
Demetriou, S
Muñoz-González, L
Lupu, EC
Item Type: Chapter
Abstract: LiDAR-driven 3D sensing allows new generations of vehicles to achieve advanced levels of situation awareness. However, recent works have demonstrated that physical adversaries can spoof LiDAR return signals and deceive 3D object detectors to erroneously detect “ghost" objects. Existing defenses are either impractical or focus only on vehicles. Unfortunately, it is easier to spoof smaller objects such as pedestrians and cyclists, but harder to defend against and can have worse safety implications. To address this gap, we introduce Shadow-Catcher, a set of new techniques embodied in an end-to-end prototype to detect both large and small ghost object attacks on 3D detectors. We characterize a new semantically meaningful physical invariant (3D shadows) which Shadow-Catcher leverages for validating objects. Our evaluation on the KITTI dataset shows that Shadow-Catcher consistently achieves more than 94% accuracy in identifying anomalous shadows for vehicles, pedestrians, and cyclists, while it remains robust to a novel class of strong “invalidation” attacks targeting the defense system. Shadow-Catcher can achieve real-time detection, requiring only between 0.003 s–0.021 s on average to process an object in a 3D point cloud on commodity hardware and achieves a 2.17x speedup compared to prior work.
Issue Date: 2021
DOI: 10.1007/978-3-030-88418-5_33
Publisher: Springer International Publishing
Start Page: 691
End Page: 711
Journal / Book Title: Computer Security – ESORICS 2021
Copyright Statement: © Springer Nature Switzerland AG 2021
Keywords: cs.CR
Artificial Intelligence & Image Processing
Publication Status: Published
Open Access location:
Online Publication Date: 2021-09-30
Appears in Collections:Computing