From Rejection to Repair: Recovering Collaborative Perception under Adversarial Attacks
Abstract
Collaborative perception (CP) improves autonomous driving by enabling connected and autonomous vehicles (CAVs) to share complementary observations, but compromised CAVs can manipulate shared features and corrupt the ego vehicle’s perception. Existing defenses largely follow a detect-and-reject paradigm, discarding suspicious CAVs or regions once corruption is detected. Such rejection indiscriminately removes benign, non-redundant information along with the adversarial content. We propose Gecko, a repair-oriented defense that selectively restores corrupted collaborative features. Our key insight is that feature-space references can guide where and how corruption should be repaired, while the resulting predictions verify the downstream effects of the repair decisions. Gecko first constructs learned and collaborative references to localize corruption and selectively restore affected regions according to cross-vehicle support. It then verifies the repaired features through their effects on the detector predictions and maps abnormal responses back to the corresponding repair decisions for correction. Extensive experiments demonstrate that Gecko consistently outperforms rejection-based defenses across diverse attacks and CP models. Compared with directly rejecting malicious CAVs, Gecko achieves relative improvements of 7.63% in [email protected] and up to 14.05% in [email protected] under MOR and TOR attacks.
est. 32% chance this paper gets accepted at ICLR 2027.
What do you think this paper will get?
All positions stay anonymous.