Resource-Constrained Deployment-Time Defense Against Adversarial Observation Perturbations in Cooperative Autonomous Driving
Abstract
Adversarial observation perturbations pose a critical threat to cooperative autonomous driving because corrupting the observation stream received by a single connected and automated vehicle (CAV) can induce unsafe decisions whose consequences propagate through multi-vehicle interactions. Existing defenses largely rely on robust policy training or do not explicitly consider a bounded online recovery budget, limiting their applicability when a pretrained driving policy must remain unchanged and only a small number of observations can be repaired before each decision. We study this deployment-time problem under a localized compromise in which one victim CAV receives persistently corrupted observations while its identity is unknown to the defender. We propose Multi-view Evidence-guided Localization and Locking with Resource Allocation and World-Model Recovery (MELAR) for this setting. MELAR uses cross-view consistency anchored by protected ego states to localize a suspected victim CAV, abstaining when the evidence is insufficient. It then ranks surrounding-vehicle observation blocks according to corruption evidence and traffic-interaction risk, and reconstructs only the highest-priority blocks within the available per-step budget. A dual-scale gated recurrent unit (GRU) world model integrates temporal cross-view evidence to reconstruct the selected blocks before the restored observations are passed to the frozen driving policy. Under the evaluated white-box observation attack, results averaged over three evaluation seeds show that, with a per-step recovery budget of three observation blocks, MELAR reduces the collision rate from 64.0% for the undefended policy to 30.7%, a reduction of 33.3 percentage points. These results show improved closed-loop driving safety in the evaluated setting while keeping the deployed policy fixed.
est. 32% chance this paper gets accepted at ICLR 2027.
What do you think this paper will get?
All positions stay anonymous.