Don't Let One Lie Survive A Hundred Truths: A Selective Bayesian Trust Estimator for Collaborative Perception

📅 2026-10-06
📈 Citations: 0
✨ Influential: 0
📄 PDF
🤖 AI Summary
This study addresses the vulnerability of cooperative perception to stealthy single-target attacks, where malicious evidence is easily diluted by benign information, and the high miss-detection and false alarm rates of existing trust mechanisms. To overcome these limitations, this work proposes SABER, a selective two-layer Bayesian trust estimator. By introducing a dual-layer architecture with a reference-weighted Beta state space, SABER employs cumulative sum testing to screen anomalous node pairs for independent evaluation, thereby effectively mitigating the dilution of attack evidence. Experimental results on the OPV2V dataset demonstrate that SABER significantly improves ROC-AUC performance, increasing the detection rate against advanced attacks by up to 96.4 percentage points. Consequently, the proposed method achieves an effective balance between precise attack detection and low false alarm rates in collaborative sensing systems.
📝 Abstract
Collaborative perception (CP) enables connected vehicles to see beyond their own sensors but makes them dependent on messages they cannot independently verify. A compromised collaborator can surgically conceal a single safety-critical object or inject a non-existing one while correctly reporting many others. Existing Bayesian trust mechanisms pool agreement across objects, which, while effective against blatant untargeted attacks, either incurs high false-positive rates (FPR), or allows unrelated correct reports to dilute persistent attack evidence for stealthy single-object attackers. To address this problem, we propose SABER, a selective two-tier Bayesian trust estimator. The first tier maintains broad agent and object trust, preserving the ability to downweight benign but low-quality contributors. Cumulative-sum screening selects agent--object pairs with persistent omissions or unsupported reports for focused Bayesian assessment. The second tier checks these pairs against other agents' evidence and maintains a separate, reference-weighted Beta state for each. The lowest pair score constrains agent trust, preventing unrelated reports from diluting a targeted attack. We establish sufficient conditions for stronger attacker-side trust reductions with bounded additional benign false alarms at fixed thresholds. Compared with state-of-the-art CP defenses, SABER improves attack detection while reducing benign FPRs. On OPV2V, SABER improves defense ROC-AUC over MATE by up to 0.427 in late fusion and 0.337 in intermediate fusion. Against advanced intermediate-fusion data fabrication attacks, it increases detection rates over ROBOSAC and LUCIA by up to 96.40 and 67.07 percentage points, respectively, while reducing FPRs.
Problem

Research questions and friction points this paper is trying to address.

collaborative perception
trust estimation
stealthy attack
Bayesian trust mechanism
false positive rate
Innovation

Methods, ideas, or system contributions that make the work stand out.

Collaborative Perception
Bayesian Trust Estimation
Selective Screening
Cumulative-Sum
Adversarial Defense
🔎 Similar Papers
Y
Yutong Liu
School of Electrical, Computing & Software Engineering, The University of Arizona, Tucson, AZ
C
Chenyi Wang
School of Electrical, Computing & Software Engineering, The University of Arizona, Tucson, AZ
M
Ming F. Li
School of Electrical, Computing & Software Engineering, The University of Arizona, Tucson, AZ
Qingzhao Zhang
Qingzhao Zhang
University of Arizona
system securitysoftware securityAI security