New 'Derail' attack hijacks generative autonomous driving planners with 50% collision rate
Adversarial perturbations exploit scoring heads, flipping safe trajectories to unsafe ones.
Deep Dive
Halima Bouzidi et al. introduce Derail, an adversarial framework that exploits the scoring head in generative end-to-end autonomous driving planners. By injecting adversarial perturbations, Derail flips trajectory selection from safe to unsafe candidates, achieving 39-80% score drops and up to 50% collision rates across multiple planner architectures.
Key Points
- Derail exploits the scoring head in generative E2E driving planners, flipping safe to unsafe trajectory selections.
- Attack achieves 39-80% score drops and up to 50% collision rates across multiple planner architectures.
- Outperforms generic loss-maximization and feature-divergence attacks, highlighting a systemic vulnerability.
Why It Matters
Critical security flaw in next-gen autonomous driving requires immediate defensive countermeasures against adversarial scoring attacks.