论文标题

BadVertisement:使用印刷广告攻击高级驾驶员助系统

bAdvertisement: Attacking Advanced Driver-Assistance Systems Using Print Advertisements

论文作者

Nassi, Ben, Shams, Jacob, Netanel, Raz Ben, Elovici, Yuval

论文摘要

在本文中,我们提出了Badvertisement,这是一种针对先进的驾驶员辅助系统(ADASS)的新型攻击方法。 BadVertisement通过在印刷房中通过折衷的计算机作为供应链攻击,通过将“幻影”对象嵌入打印广告中。当ADA在经过的汽车中观察到折衷的印刷广告时,ADA会触发不希望的反应。我们分析了最新的对象检测器,并表明它们在对象检测中不会考虑颜色或上下文。我们对Mobileye 630 Pro上的这些发现的验证表明,此ADA也未能考虑到颜色或上下文。然后,我们展示了攻击者如何通过将幻影路标嵌入印刷广告中,从而使这些发现对商业ADA进行攻击,这导致配备了Mobileye 630 Pro的汽车触发虚假通知以减速。最后,我们讨论了可以部署的多种对策,以减轻我们提议的攻击的影响。

In this paper, we present bAdvertisement, a novel attack method against advanced driver-assistance systems (ADASs). bAdvertisement is performed as a supply chain attack via a compromised computer in a printing house, by embedding a "phantom" object in a print advertisement. When the compromised print advertisement is observed by an ADAS in a passing car, an undesired reaction is triggered from the ADAS. We analyze state-of-the-art object detectors and show that they do not take color or context into account in object detection. Our validation of these findings on Mobileye 630 PRO shows that this ADAS also fails to take color or context into account. Then, we show how an attacker can take advantage of these findings to execute an attack on a commercial ADAS, by embedding a phantom road sign in a print advertisement, which causes a car equipped with Mobileye 630 PRO to trigger a false notification to slow down. Finally, we discuss multiple countermeasures which can be deployed in order to mitigate the effect of our proposed attack.

扫码加入交流群

加入微信交流群

微信交流群二维码

扫码加入学术交流群,获取更多资源