{"slug": "investigating-adversarial-robustness-of-heterogeneous-cooperative-perception", "title": "Investigating Adversarial Robustness of Heterogeneous Cooperative Perception", "summary": "A new arXiv paper (2609.17856v1) reports that heterogeneity in cooperative perception does not defend connected vehicles against adversarial feature attacks, as previously hypothesized. The authors introduce HetPoison, a learned generator that crafts a removal perturbation in a single label-free forward pass and transfers across major heterogeneous designs without access to the victim's detector, matching or exceeding optimizer-based attacks. They also propose HetShield, a lightweight trust layer validating spatiotemporal consistency across features, which recovers 83–95% of the accuracy degraded by attacks and outperforms prior art.", "body_md": "arXiv:2609.17856v1 Announce Type: new \nAbstract: Heterogeneous cooperative perception (CP) enables connected vehicles with diverse sensor setups to share spatial awareness via compact feature maps, where receivers reconcile these maps using learned translation modules for fusion and inference. Prior attacks against CP in a homogeneous setting reveal that the data exchange introduces a critical attack surface: a single malicious agent can transmit crafted features that erase real objects from a neighbor's fused scene. Yet, it is widely hypothesized that heterogeneity naturally defends against these attacks, as the attacker lacks knowledge of the victim's detector and the translation module scrambles adversarial gradients. We demonstrate that this protection is largely an illusion. Using a matched-objective harness to standardize the perturbation budget, objective, and forward path, we show that properly tuned iterative attacks close or reverse the apparent robustness gap. However, these optimization-based attacks require ground-truth labels and iterative backpropagation, meaning they do not represent a practical field threat running in real-time. To bridge this gap, we introduce HetPoison, a learned generator that crafts a removal perturbation in a single, label-free forward pass. HetPoison transfers across major heterogeneous designs without requiring access to the victim's detector, matching or exceeding the effectiveness of expensive optimizer-based attacks. Since heterogeneity itself is not a defense, we propose HetShield, a lightweight trust layer that validates the spatiotemporal consistency across features, recovering 83--95% of the accuracy degraded by attacks, outperforming prior art.", "url": "https://wpnews.pro/news/investigating-adversarial-robustness-of-heterogeneous-cooperative-perception", "canonical_source": "https://arxiv.org/abs/2609.17856", "published_at": "2026-09-17 04:00:00+00:00", "updated_at": "2026-09-17 04:26:49.055912+00:00", "lang": "en", "topics": ["autonomous-vehicles", "ai-safety", "machine-learning", "computer-vision", "ai-research"], "entities": ["arXiv", "HetPoison", "HetShield"], "alternates": {"html": "https://wpnews.pro/news/investigating-adversarial-robustness-of-heterogeneous-cooperative-perception", "markdown": "https://wpnews.pro/news/investigating-adversarial-robustness-of-heterogeneous-cooperative-perception.md", "text": "https://wpnews.pro/news/investigating-adversarial-robustness-of-heterogeneous-cooperative-perception.txt", "jsonld": "https://wpnews.pro/news/investigating-adversarial-robustness-of-heterogeneous-cooperative-perception.jsonld"}}