GLST: Defending Confidence-Driven V2X Collaborative Perception Against Stealthy Multi-Attacker Feature Injection

📅 2026-07-25
📈 Citations: 0
Influential: 0
📄 PDF
🤖 AI Summary
This work addresses a critical vulnerability in existing V2X cooperative perception systems, whose trust mechanisms rely solely on single-source consistency signals and thus fail under coordinated attacks that fabricate spurious consensus—particularly in high-confidence regions or areas where the ego vehicle exhibits perceptual uncertainty. To mitigate this, the paper proposes GLST, a lightweight, multi-level trust framework that is the first to expose this vulnerability and counter it through tripartite consistency evaluation: global feature consistency, multi-scale local residual consistency, and structural alignment with the ego vehicle’s semantic topology. These complementary trust signals guide weighted feature fusion to suppress malicious inputs. Experiments demonstrate that GLST achieves an AP@0.3 of 0.69 on OPV2V under a four-attacker Pretend Benign scenario, substantially outperforming current defenses, while also exhibiting strong robustness against gradient-based attacks such as PGD.
📝 Abstract
Collaborative perception (CP) improves autonomous-driving perception by enabling connected vehicles to exchange intermediate features via V2X. Confidence-driven sparse communication reduces bandwidth by transmitting only perception-critical spatial regions, but creates a security risk: once a collaborator is compromised, malicious features in high-confidence or ego-uncertain regions may be preferentially selected and amplified during fusion. Using Where2comm as a representative framework, we show that the proposed Pretend Benign attack exploits its spatial-confidence mechanism by injecting stealthy perturbations into uncertain yet perception-critical regions, substantially degrading 3D object detection while preserving benign-like feature characteristics. Beyond this attack-framework pair, we identify a broader weakness of existing trust-based defenses: their reliance primarily on a single consistency signal leaves them vulnerable when multiple attackers form a pseudo-consensus that biases trust estimation. We therefore propose Global-Local Structural Trust (GLST), a lightweight defense that assesses collaborator reliability through three complementary perspectives: global feature consistency, multi-scale local residual consistency, and structural consistency with ego-side semantic topology. The resulting trust scores guide feature fusion to suppress unreliable collaborators. Experiments on OPV2V show that GLST achieves competitive performance against single-attacker Pretend Benign attacks and substantially stronger robustness in multi-attacker settings. Under a four-attacker Pretend Benign attack, GLST maintains 0.69 AP@0.3, whereas existing single-signal defenses degrade severely. GLST also remains effective against gradient-based attacks such as PGD, indicating that multi-level trust modeling is essential for securing confidence-driven CP.
Problem

Research questions and friction points this paper is trying to address.

V2X collaborative perception
feature injection attack
multi-attacker
trust-based defense
confidence-driven communication
Innovation

Methods, ideas, or system contributions that make the work stand out.

collaborative perception
trust modeling
multi-attacker defense
feature injection attack
V2X security
🔎 Similar Papers
No similar papers found.