RASP: Response-Aware Spatial and Pose Manipulation Attacks for Collaborative Perception
Abstract
Collaborative perception improves the sensing capability of individual agents through feature sharing, but malicious feature messages can also introduce false detections, missed detections, and localization errors. Existing attacks often allocate perturbations using coarse regional labels, without accounting for whether selected responses remain distinct after non-maximum suppression or whether the poses of retained objects can be redirected under detection and shape constraints. To address these limitations, we propose RASP, a response-aware framework for spatial and pose manipulation attacks against collaborative perception. RASP consists of Spatial Response Allocation (SRA) and Constrained Pose Redirection (CPR). SRA uses bounded response probes to prioritize candidate locations under a fixed spatial budget, applies NMS-aware greedy selection to diversify spoofed detections, and suppresses residual responses around removal targets. CPR fixes dense output correspondences and redirects selected high-confidence objects toward prescribed positions and orientations, while enforcing a generation-stage score floor, regularizing unintended shape changes, and bounding the feature perturbation. Experiments on OPV2V and V2XSet show that RASP consistently reduces detection performance under no defense, ROBOSAC, and FLD, demonstrating effective manipulation attacks of collaborative predictions across different datasets and defense settings. The code and model will be publicly available.
est. 32% chance this paper gets accepted at ICLR 2027.
What do you think this paper will get?
All positions stay anonymous.