cd /news/autonomous-vehicles/investigating-adversarial-robustness… · home topics autonomous-vehicles article
[ARTICLE · art-132240] src=arxiv.org ↗ pub= topic=autonomous-vehicles verified=true sentiment=· neutral

Investigating Adversarial Robustness of Heterogeneous Cooperative Perception

A new arXiv paper (2609.17856v1) reports that heterogeneity in cooperative perception does not defend connected vehicles against adversarial feature attacks, as previously hypothesized. The authors introduce HetPoison, a learned generator that crafts a removal perturbation in a single label-free forward pass and transfers across major heterogeneous designs without access to the victim's detector, matching or exceeding optimizer-based attacks. They also propose HetShield, a lightweight trust layer validating spatiotemporal consistency across features, which recovers 83–95% of the accuracy degraded by attacks and outperforms prior art.

by read1 min views2 publishedSep 17, 2026

arXiv:2609.17856v1 Announce Type: new Abstract: Heterogeneous cooperative perception (CP) enables connected vehicles with diverse sensor setups to share spatial awareness via compact feature maps, where receivers reconcile these maps using learned translation modules for fusion and inference. Prior attacks against CP in a homogeneous setting reveal that the data exchange introduces a critical attack surface: a single malicious agent can transmit crafted features that erase real objects from a neighbor's fused scene. Yet, it is widely hypothesized that heterogeneity naturally defends against these attacks, as the attacker lacks knowledge of the victim's detector and the translation module scrambles adversarial gradients. We demonstrate that this protection is largely an illusion. Using a matched-objective harness to standardize the perturbation budget, objective, and forward path, we show that properly tuned iterative attacks close or reverse the apparent robustness gap. However, these optimization-based attacks require ground-truth labels and iterative backpropagation, meaning they do not represent a practical field threat running in real-time. To bridge this gap, we introduce HetPoison, a learned generator that crafts a removal perturbation in a single, label-free forward pass. HetPoison transfers across major heterogeneous designs without requiring access to the victim's detector, matching or exceeding the effectiveness of expensive optimizer-based attacks. Since heterogeneity itself is not a defense, we propose HetShield, a lightweight trust layer that validates the spatiotemporal consistency across features, recovering 83--95% of the accuracy degraded by attacks, outperforming prior art.

── more in #autonomous-vehicles 4 stories · sorted by recency
── more on @arxiv 3 stories trending now
sponsored brought to you by zahid.host 4,200+ EU-deployed projects
reading about agents? ship yours in a single git push.

Run your AI side-project on zahid.host

EU-based hosting, git-push deploys, automatic HTTPS, no cold starts. Free tier with a custom domain — perfect for shipping the agent you just read about.

$git push zahid main
Live at https://your-agent.zahid.host
Get free account → Pricing
from €0/mo · no card required
LIVE [news/investigating-advers…] indexed:0 read:1min 2026-09-17 ·