From Stealthy Data Fabrication to Unsafe Driving: Realistic Scenario Attacks on Collaborative Perception
Listen
Radio episode about this paper
Transcript
Introduction to the show: ident: Security Radio. Generated commentary on the latest security and cryptography papers.
Nadia: Today's paper: "From Stealthy Data Fabrication to Unsafe Driving".
Elias: This paper investigates security vulnerabilities in collaborative perception for connected and autonomous vehicles (CAVs),
Nadia: First, who's behind it and why it matters.
Title and authors: Nadia: So, we're talking about the paper "From Stealthy Data Fabrication to Unsafe Driving: Realistic Scenario Attacks on Collaborative Perception." It seems like the core issue they are tackling is that current attacks are too easy to spot in controlled settings, which opens up a real problem for how safe these connected and autonomous vehicles actually are.
Elias: I'm looking at the title and authors, and it immediately suggests a focus on making these data fabrication attacks stealthy enough to slip past existing checks, which is interesting because it implies the attackers are trying to evade detection mechanisms.
Priya: From my side, I'm curious about what this means for privacy and measurement; does this paper suggest that small, subtle manipulations in shared sensor data could lead to unintended real-world consequences for users or other road users?
Nadia: Exactly, Priya, because the paper points out that existing attacks are evaluated in manually constructed scenarios, which doesn't reflect how small errors actually propagate through the system in a busy environment.
Elias: And reading the abstract again, it mentions they are presenting a stealthy attack that manipulates object poses within shared perception results to keep those perturbations below detection thresholds while still causing unsafe driving behaviors.
Priya: That's what caught my attention; the idea that these small errors accumulate over time in trajectory prediction, leading to things like unnecessary braking or evasive maneuvers, sounds like a very tangible safety concern for any vehicle operating in traffic.
Nadia: It is, and the authors are showing how these small per-frame shifts can gradually shift a nearby vehicle toward the ego lane until it triggers an incorrect decision from the victim's trajectory predictor.
Elias: The paper details their attack mechanism, PosePert, which uses a two-stage process involving scaled multi-view ray casting for initialization and then a lightweight neural network called PertNet to predict feature corrections based on local context.
Priya: That sounds complex; what does that specific approach mean for the underlying data integrity when multiple sensors are feeding into one collaborative perception system?
Nadia: The key part is the scaling factor, beta, which they use to amplify features so that the shifted signal dominates fusion and isn't just absorbed by layers like batch normalization.
Elias: That scaling step is a clever way to ensure the perturbation has enough magnitude to matter during data fusion without completely distorting the overall feature representation outside of what's expected in training.
Priya: So, if this method can keep the perturbations subtle while still causing a safety issue, it suggests that defenses focused only on large anomalies might be insufficient for catching these sophisticated manipulations.
Nadia: Precisely; and that leads us into their proposed mitigation strategy called PoseGuard, which they present as an object-level defense rather than a global feature-level one.
Title and authors: Elias: The PoseGuard approach seems to focus on detecting anomalies in localized, safety-critical regions by looking at three stages: identifying objects whose predicted trajectories threaten the ego vehicle's path, comparing fused detections with the ego vehicle's own sensor data, and then performing localized anomaly detection on their feature regions.
Priya: That localization sounds much more practical for real-time systems than trying to scan the entire scene for global inconsistencies; how does that compare to what we usually see in these types of attacks?
Nadia: Table one compares this new attack, Pose Perturb, against other existing methods, and it shows that Pose Perturb achieves intermediate results in both stealthiness and effectiveness compared to other research shown.
Elias: It seems like they are trying to balance the communication cost of the attack with its ability to achieve a realistic scenario computation that actually leads to an unsafe driving outcome.
Priya: I'm interested in what this means for measurement researchers: if a defense can successfully isolate and detect an anomaly within a specific object's feature region, how reliable are those localized distance metrics they use for detection?
Nadia: The paper claims that this localized approach achieves an eighty percent detection rate on small pose perturbations, which is significantly higher than the eleven percent rate reported for existing methods.
Elias: That jump in detection efficacy really highlights the value of focusing the defense effort where it matters most, away from broad feature map comparisons.
Priya: So, to summarize what we've heard about "From Stealthy Data Fabrication to Unsafe Driving: Realistic Scenario Attacks on Collaborative Perception," they found a way to create subtle pose perturbations that accumulate over time in the perception stack to cause unsafe driving actions, and they proposed PoseGuard as a localized defense that detects these issues with an eighty percent success rate.
Nadia: That's the gist of it; it moves the security evaluation from easily constructed scenarios to something much more realistic where small errors have safety consequences.
Elias: And from a cryptographic viewpoint, I see the implication here is that if the underlying data fabrication relies on specific feature manipulations, we need to understand exactly which parameters in their model allow those manipulations to bypass detection and how we can mathematically verify those constraints.
Priya: It really shows that for collaborative perception systems, the focus needs to shift from just preventing outright spoofing to rigorously monitoring the accumulation of tiny inconsistencies across different sensing modalities.
Nadia: And that leads us nicely into what they suggest as improvements, which are essentially refining PoseGuard by making it more robust against these specific types of fabrication attacks.
Elias: They suggest replacing global feature-map distance metrics with localized feature-crop comparisons within detected object bounding boxes to prevent the signal dilution we talked about earlier.
Title and authors: Priya: That makes sense; focusing the comparison only on what's happening inside the target object's area should help filter out noise from benign neighboring objects.
Nadia: They also recommend integrating a predictive safety filter that prioritizes anomaly detection for objects whose predicted trajectories intersect with the ego vehicle's planned path within a defined safety threshold.
Elias: That integration of prediction and detection seems like a necessary step to move beyond just finding errors to actively stopping the unsafe driving behavior before it happens.
Priya: And finally, they propose deploying a Fused-vs-Ego Disagreement Filter that only triggers high-intensity scrutiny when collaborative detections deviate from the ego vehicle’s own sensor data.
Nadia: That final step really solidifies the defense by ensuring we only spend computational power on discrepancies that are actually relevant to the immediate safety of the vehicle.
Elias: It seems like a very practical set of enhancements aimed at building a system that can handle these realistic, temporal accumulation attacks in a more resilient way.
Priya: It’s encouraging to see how they are moving toward localized detection methods rather than relying on broad global analysis for security checks in this domain.
Nadia: So, to wrap up our discussion on "From Stealthy Data Fabrication to Unsafe Driving: Realistic Scenario Attacks on Collaborative Perception," we've seen how PosePert creates subtle, accumulating errors that lead to unsafe driving actions.
Elias: And the authors provide a solid framework with PoseGuard, focusing on localized anomaly detection and safety-critical object prioritization as a way to counter this.
Priya: I think the real implication here for the broader field is that we need to start thinking about these perception systems not just as data processing pipelines, but as active agents that must be continuously monitored for emergent behaviors arising from small errors.
Nadia: Exactly; it forces a shift in how we test and validate these systems, moving beyond simple attack detection to testing the system's resilience against temporal propagation of error.
Elias: It's important to remember that this research focuses on the mechanics of the attack and defense but doesn't necessarily provide a complete cryptographic proof for breaking the underlying perception model itself.
Priya: That’s fair; the paper is more about system-level security implications than proving mathematical hardness, which is an important distinction for our measurement focus.
Nadia: Well, we've covered the attack mechanism, the proposed defense improvements, and why this work matters for real-world safety in CAVs with "From Stealthy Data Fabrication to Unsafe Driving: Realistic Scenario Attacks on Collaborative Perception." We’re going to take a quick break and then move on to another interesting piece of research.
Elias: Indeed, it's been a deep dive into the mechanics of how these small errors can become big problems for autonomous systems.
Priya: I look forward to hearing what the next paper brings to the table, especially concerning privacy implications in this context.
The paper's summary: Nadia: So, we've just heard that this paper introduces an attack called PosePert that subtly messes with object locations in shared perception to cause unsafe driving decisions over time, and now we need to talk about what it actually means for our world.
Elias: Exactly, Nadia; the core idea is that these small, targeted changes in perceived vehicle positions can cascade through the system until the autonomy stack makes a dangerous move. This isn't just a theoretical glitch; it’s about creating real-world consequences from seemingly insignificant data noise.
Priya: From my research background, what I find most compelling is how they move away from those easy-to-spot, manually created scenarios and focus on the temporal accumulation of these small errors in a dynamic setting. This suggests that defenses built only around single frames or global checks simply won't catch this type of stealthy manipulation.
Nadia: Right, Priya; the authors are showing how to craft these perturbations so they stay under detection thresholds while still achieving a safety-critical outcome, which is the key difficulty they're addressing. They make it hard to detect because the shifts are small and localized, like staying below a half-meter change.
Elias: And from my perspective as a cryptographer, I’m thinking about how this works; the attack uses two distinct stages—a physics-informed initialization followed by a lightweight neural network correction—which means we need to understand precisely which components of the perception pipeline are most vulnerable to these kinds of localized feature manipulations.
Priya: That points toward a big privacy implication, Nadia; if we can't trust that the perception system is reporting an accurate reality because it’s been subtly manipulated, it impacts everything from safety assurance to how other systems share data in collaborative environments. It makes the integrity of shared sensory input a much bigger concern.
Nadia: It really does; and this work highlights a massive gap in existing security evaluations, proving that we need to move testing into more realistic simulations where errors are allowed to propagate temporally rather than just being static anomalies. The authors' proposed PoseGuard defense seems like a direct response to that by focusing detection on safety-critical regions.
Elias: That’s where the technical challenge lies; implementing localized anomaly detection within those object bounding boxes requires very precise feature comparison metrics, and we have to make sure the defense itself isn't fooled by its own local feature maps.
Priya: And what I want to emphasize is that this pushes us toward a new way of auditing these AI systems, moving beyond just checking for catastrophic failures to actively monitoring the accumulation of minor inconsistencies across different sensors. It’s about building resilience against emergent behavior from small data inaccuracies.
Nadia: Exactly; it shifts the focus from simply stopping obvious spoofing attacks to rigorously testing how a system handles subtle, realistic data fabrication designed specifically to induce unsafe driving actions.
Elias: So, we’re looking at a complex interplay between sophisticated AI manipulation and the need for localized, context-aware defense mechanisms that can handle temporal errors. The next step is figuring out the mathematical bounds on how much perturbation an attacker can introduce before PoseGuard's detection thresholds are inevitably crossed.
The paper's improvements: Tom: So, we've heard about how the PoseGuard defense tries to stop these attacks by focusing on localized object regions, and now we need to discuss what improvements they suggest for making that defense even stronger.
Nadia: The authors propose several enhancements, starting with replacing those broad global feature-map distances with localized comparisons right within the target object's bounding box to prevent that signal dilution we talked about earlier. That seems like a direct fix for the detection sensitivity issue we identified.
Elias: I agree; that move toward localized L1 or L2 distances is smart because it means the defense isn't just looking at everything in the scene, which is computationally expensive, but it also keeps the detection highly specific to where an actual anomaly could be hiding.
Priya: And they also suggest integrating a predictive safety filter that prioritizes anomaly detection for objects whose predicted trajectories intersect with the ego vehicle's planned path within a defined safety threshold. That links the perception error directly to an immediate, real-world risk.
Nadia: That is a crucial addition because it moves the defense from passive detection to active risk management; it stops the system from wasting resources on minor, non-threatening shifts and focuses only on things that could actually cause unnecessary braking or evasive actions.
Elias: From a cryptographic standpoint, prioritizing based on predicted collision paths introduces a layer of dynamic weighting into the defense mechanism, which means we need to verify the assumptions underpinning those trajectory predictors to make sure they aren't also being manipulated by an attacker.
Priya: It really shows how this research is moving toward making these security mechanisms more practical for real-time applications, focusing computational power only where the potential impact on safety is highest, rather than running exhaustive global scans.
Nadia: And finally, they recommend deploying a Fused-vs-Ego Disagreement Filter that triggers intense scrutiny specifically when collaborative detections deviate from the ego vehicle’s own sensor data. That’s a fantastic way to validate the entire perception pipeline against reality by comparing it directly to what the ego car sees.
Elias: That disagreement filter is interesting because it acts as a final sanity check, verifying if the AI's collaborative output aligns with physical reality observed by another reliable source, which helps narrow down whether an error is a genuine fabrication or just a sensor glitch.
Priya: It’s encouraging to see this progression toward defenses that are not only sensitive to small perturbations but also contextually aware of safety risks and cross-validated against ego vehicle data. This makes the whole system feel much more trustworthy for shared perception tasks.
Conclusion: Tom: So, we’ve covered how the PoseGuard defense tries to stop these attacks by focusing on localized object regions, and now we need to discuss what improvements they suggest for making that defense even stronger before we wrap up this segment.
Nadia: The authors propose several enhancements, starting with replacing those broad global feature-map distances with localized comparisons right within the target object's bounding box to prevent that signal dilution we talked about earlier. That seems like a direct fix for the detection sensitivity issue we identified.
Elias: I agree; that move toward localized L1 or L2 distances is smart because it means the defense isn't just looking at everything in the scene, which is computationally expensive, but it also keeps the detection highly specific to where an actual anomaly could be hiding.
Priya: And they also suggest integrating a predictive safety filter that prioritizes anomaly detection for objects whose predicted trajectories intersect with the ego vehicle's planned path within a defined safety threshold. That links the perception error directly to an immediate, real-world risk.
Nadia: That is a crucial addition because it moves the defense from passive detection to active risk management; it stops the system from wasting resources on minor, non-threatening shifts and focuses only on things that could actually cause unnecessary braking or evasive actions.
Elias: From a cryptographic standpoint, prioritizing based on predicted collision paths introduces a layer of dynamic weighting into the defense mechanism, which means we need to verify the assumptions underpinning those trajectory predictors to make sure they aren't also being manipulated by an attacker.
Priya: It really shows how this research is moving toward making these security mechanisms more practical for real-time applications, focusing computational power only where the potential impact on safety is highest, rather than running exhaustive global scans.
Nadia: And finally, they recommend deploying a Fused-vs-Ego Disagreement Filter that triggers intense scrutiny specifically when collaborative detections deviate from the ego vehicle’s own sensor data. That’s a fantastic way to validate the entire perception pipeline against reality by comparing it directly to what the ego car sees.
Elias: That disagreement filter is interesting because it acts as a final sanity check, verifying if the AI's collaborative output aligns with physical reality observed by another reliable source, which helps narrow down whether an error is a genuine fabrication or just a sensor glitch.
Priya: It’s encouraging to see this progression toward defenses that are not only sensitive to small perturbations but also contextually aware of safety risks and cross-validated against ego vehicle data. This makes the whole system feel much more trustworthy for shared perception tasks.
Nadia: So, to summarize our discussion on "From Stealthy Data Fabrication to Unsafe Driving: Realistic Scenario Attacks on Collaborative Perception," we’ve seen how PosePert creates subtle, accumulating errors that lead to unsafe driving actions, and the authors provide a solid framework with PoseGuard focusing on localized detection and safety prioritization.
Elias: Indeed; it’s a very robust approach that addresses the temporal nature of these attacks by creating layered defenses tailored to where the risk actually lies in the system.
Priya: I think this work really demonstrates that for collaborative perception systems, we need to start thinking about them not just as data processing pipelines, but as active agents that must be continuously monitored for emergent behaviors arising from small errors.
Nadia: That’s right; it forces a shift in how we test and validate these systems, moving beyond simple attack detection to testing the system's resilience against temporal propagation of error.
Elias: It's important to remember that this research focuses on the mechanics of the attack and defense but doesn't necessarily provide a complete cryptographic proof for breaking the underlying perception model itself.
Priya: That’s fair; the paper is more about system-level security implications than proving mathematical hardness, which is an important distinction for our measurement focus.
Nadia: Well, we’ve covered the attack mechanism, the proposed defense improvements, and why this work matters for real-world safety in CAVs with "From Stealthy Data Fabrication to Unsafe Driving: Realistic Scenario Attacks on Collaborative Perception." We’re going to take a quick break and then move on to another interesting piece of research.
Elias: Indeed, it's been a deep dive into the mechanics of how these small errors can become big problems for autonomous systems.
Priya: I look forward to hearing what the next paper brings to the table, especially concerning privacy implications in this context.
Qingzhao Zhang, Runting Zhang, Z. Morley Mao
The University of Arizona · University of Michigan · University of Michigan
cs.CR
Submitted: 2026-05-02
Updated: 2026-09-11
License: http://creativecommons.org/licenses/by/4.0/
Importance score: 71/100
The gist: This paper investigates security vulnerabilities in collaborative perception for connected and autonomous vehicles (CAVs), where vehicles share sensory data to improve perception but create an
Key concepts
- PosePert
- This is a stealthy attack that manipulates object poses within shared perception results. It uses a two-stage process: scaled multi-view ray casting for initialization and a lightweight neural network called PertNet to predict feature corrections based on local context, keeping perturbations below detection thresholds while causing unsafe driving.
- PoseGuard
- This is the proposed mitigation strategy that focuses on object-level defense rather than global feature-level checks. It detects anomalies by identifying objects whose predicted trajectories threaten the ego vehicle's path, comparing fused detections with ego vehicle data, and performing localized anomaly detection on feature regions.
- Temporal Accumulation Attacks
- This refers to attacks where small pose errors are introduced frame by frame. The paper shows that these small per-frame shifts can gradually shift a nearby vehicle toward the ego lane until the trajectory predictor makes an incorrect decision, which is more realistic than static scenario testing.
- Localized Anomaly Detection
- This defense approach focuses on detecting issues within specific object bounding boxes rather than scanning the entire scene for global inconsistencies. It uses localized feature-crop comparisons to filter out noise from benign neighboring objects and achieve a high detection rate.
Terminology
Summary
This paper investigates security vulnerabilities in collaborative perception for connected and autonomous vehicles (CAVs), where vehicles share sensory data to improve perception but create an attack surface for data fabrication attacks.
The authors address a critical research gap: existing attacks are often detectable or evaluated in manually constructed scenarios,
failing to account for how small, subtle perturbations can propagate through downstream modules like tracking and trajectory prediction to induce safety-critical outcomes in dynamic environments.
The PosePert attack mechanism
The proposed attack, PosePert, focuses on object pose perturbation,
which involves subtly perturbing the perceived location of an existing vehicle
to evade detection. Unlike prior spoofing or removal attacks, PosePert achieves precise control through a two-stage process:
-
Scaled multi-view ray casting
produces aphysics-informed initialization
by synthesizing fake point clouds from virtual viewpoints to anchor the geometry of the target pose. -
A
lightweight neural network
(PertNet) predictsper-voxel feature corrections conditioned on local context,
enabling real-time control without iterative optimization.
To ensure the shifted signal dominates fusion, the attacker uses a scaling factor (β) to amplify features, as unscaled features are often outvoted
by benign vehicles during fusion. This prevents the perturbation from being absorbed by batch normalization layers while avoiding values that would push features outside the training distribution and cause distorted bounding boxes.
Scenario-aware orchestration
To induce unsafe driving behaviors, the authors develop a scenario-aware attack framework
that operates under an observe–predict–plan–execute paradigm.
This framework moves beyond single-frame manipulation to model how errors accumulate over time through a temporal amplification mechanism.
The attacker continuously updates its belief of the scene and optimizes perturbations over a temporal horizon to satisfy three specific properties:
** Effectiveness
: Ensuring the victim's trajectory predictor forecasts a lane intrusion, triggering unnecessary braking or evasive actions.
**
** Stealthiness
: Keeping per-frame locational perturbations within a strict bound (e.g., 0.5 m) to remain below detection thresholds.
**
** Realizability
: Ensuring target positions lie within the attacker's feature map coverage. **
The PoseGuard mitigation strategy
To counter these threats, the paper proposes PoseGuard, an object-level defense
that addresses the limitations of existing global feature-level or bounding box-level methods. While traditional defenses often miss small, localized changes,
PoseGuard focuses on detecting anomalies in localized, safety-critical regions.
The detection pipeline follows three stages:
-
Safety-critical object identification
: Identifying objects whose predicted trajectories threaten the ego vehicle's path. -
Fused-vs-ego disagreement filter
: Comparing fused detections with the ego vehicle's own sensor data to find inconsistencies. -
Object-level anomaly detection
: Performinglocalized anomaly detection on their feature regions
by computing pairwise L1 distances within the specific bounding box area of the target object.
This localized approach significantly improves sensitivity, achieving an 80% detection rate on small pose perturbations compared to only 11% for existing methods.
Improvements for AI systems
To improve the security and reliability of collaborative perception systems in Connected and Autonomous Vehicles (CAVs), I recommend implementing the following technical improvements derived from the paper's findings:
-
Implement a Multi-Stage, Object-Centric Anomaly Detection Pipeline (PoseGuard).
-
Replace global feature-map distance metrics (e.g., Global L1/L2) with localized feature-crop comparisons within detected object bounding boxes to prevent
signal dilution.
-
Integrate a predictive safety filter that prioritizes anomaly detection for
safety-critical
objects—specifically those whose predicted trajectories intersect with the ego vehicle's planned path within a defined safety threshold. -
Deploy a Fused-vs-Ego Disagreement Filter to trigger high-intensity scrutiny only when collaborative detections deviate from the ego vehicle’s local sensor observations.
The improved AI system will be able to:
-
Detect
stealthy
pose perturbations (e.g., <0.5m shifts in position or orientation) that are designed to bypass existing occupancy-based and global feature-based defenses. -
Prevent the propagation of minor perception errors through the autonomy stack, ensuring that small spatial inaccuracies do not escalate into incorrect trajectory predictions or unsafe driving decisions (such as unnecessary emergency braking).
-
Maintain real-time operational efficiency by focusing heavy computational resources on high-risk, safety-critical regions rather than performing exhaustive global scene analysis.
-
Identify and mitigate sophisticated
physics-informed
data fabrication attacks that utilize ray-casting to create highly realistic but spatially deceptive feature maps.
Abstract
Collaborative perception allows connected and autonomous vehicles (CAVs) to improve perception by sharing sensory data, but it also introduces security risks from manipulated inputs. Prior work shows that attackers can spoof or remove objects by fabricating shared data, yet the practicality of such attacks in real-world driving remains unclear. Existing attacks are often detectable or evaluated in manually constructed scenarios, leaving open whether they can induce safety-critical outcomes in dynamic environments. To bridge this gap, we present a stealthy, scenario-realistic data fabrication attack that induces unsafe driving behaviors through end-to-end system effects. Instead of creating large, easily detectable anomalies, our attack subtly manipulates the poses of existing objects in shared perception results, keeping perturbations below detection thresholds. These small errors are then propagated through downstream modules, including object tracking and trajectory prediction, leading to significant deviations in predicted behaviors and ultimately unsafe driving decisions. We further design an online, scenario-aware attack framework that adapts to dynamic traffic conditions and optimizes attack strategies at runtime. Experiments on OPV2V and V2X-Real demonstrate that the attack achieves over 90% success in inducing detection errors and triggers safety-critical behaviors, such as unnecessary hard braking, in up to 50% of scenarios, while largely evading state-of-the-art defenses. We also propose a mitigation that focuses on detecting anomalies in localized, safety-critical regions, achieving an 80% detection rate on the small pose perturbation compared to 11% for the best existing methods.
Sources
- A Cooperative Perception Environment for Traffic Operations and Control
- CP-Guard+: A New Paradigm for Malicious Agent Detection and Defense in Collaborative Perception
- GRIP++: Enhanced Graph-based Interaction-aware Trajectory Prediction for Autonomous Driving
- ControlLoc: Physical-World Hijacking Attack on Visual Perception in Autonomous Driving
- AutoCast: Scalable Infrastructure-less Cooperative Perception for Distributed Collaborative Driving
- A Cooperative Perception System Robust to Localization Errors
- AB3DMOT: A Baseline for 3D Multi-Object Tracking and New Evaluation Metrics
- CoBEVT: Cooperative Bird's Eye View Semantic Segmentation with Sparse Transformers
- Open3D: A Modern Library for 3D Data Processing
Related papers
- SoK: AI-Augmented Binary Reversing
- Relaxed Sender Anonymity for CBDC Interbank Settlement: A Zero-Knowledge Approach on Permissioned EVM
- Calibration-Family Overfit: Why Trusted Sabotage Monitors Don't Transfer Across Lineages
- Efficient Fuzzy PSI under One-Sided Assumptions
- Sealing the Audit-Runtime Gap for LLM Skills
- Token Composition: A Graph Based on EVM Logs