SensorAD: Cross-Modal Physical Consistency for Sensor Attack Detection in Autonomous Vehicle
Abstract
Autonomous vehicles fuse cameras, LiDAR, event cameras and GPS/IMU to perceive and act safely. Each of these sensors is individually attackable, but an adversary who compromises one cannot easily forge physically consistent signals across the rest. SensorAD turns this asymmetry into a detector: on normal driving data we mask an entire sensor modality and train a unified transformer to predict it from the remaining ones, so that the error minimized in training with a modality masked is the score read at deployment and no attack labels are used for training or threshold calibration. We pre-train on real-world nuScenes data, fine-tune on CARLA to incorporate the event camera, and evaluate on a 132-episode benchmark spanning ten attack types along six axes. Against nine baselines from five paradigms, SensorAD is strongest on physics-grounded attacks, averaging 0.843 AUROC versus 0.738 for the best cross-modal baseline; it localizes the compromised sensor at 67.0% top-1 / 79.5% top-2 accuracy, and its timing advantage over that baseline is specific to stealthy attacks: it flags a gradual GPS drift after 3.4±0.4 m of accumulated offset against 12.6±1.4 m. Detection degrades gradually under coordinated, spatially aligned and white-box adaptive attackers and costs at most 0.028 AUROC on unseen towns and weather. On real nuScenes streams with the same threat models injected, the CARLA-fine-tuned detector reaches 0.735 mean AUROC on the five expressible attacks (0.793 in CARLA), though its threshold must be recalibrated on real data. Per-sensor visual detectors remain stronger on weakly cross-modal attacks: the two families fail on largely disjoint attack classes, and a simple late-fusion stack outperforms either alone on average.
est. 32% chance this paper gets accepted at ICLR 2027.
What do you think this paper will get?
All positions stay anonymous.