TY - GEN
T1 - Asymmetry Vulnerability and Physical Attacks on Online Map Construction for Autonomous Driving
AU - Lou, Yang
AU - Hu, Haibo
AU - Song, Qun
AU - Xu, Qian
AU - Zhu, Yi
AU - Tan, Rui
AU - Lee, Wei-Bin
AU - Wang, Jianping
PY - 2025
Y1 - 2025
N2 - High-definition (HD) maps provide precise environmental information essential for prediction and planning in autonomous driving (AD) systems. Due to the high cost of labeling and maintenance, recent research has turned to online HD map construction using onboard sensor data, offering wider coverage and more timely updates for autonomous vehicles (AVs). However, the robustness of online map construction under adversarial conditions remains underexplored. In this paper, we present a systematic vulnerability analysis of online map construction models, which reveals that these models exhibit an inherent bias toward predicting symmetric road structures. In asymmetric scenes like forks or merges, this bias often causes the model to mistakenly predict a straight boundary that mirrors the opposite side. We demonstrate that this vulnerability persists in the real-world and can be reliably triggered by obstruction or targeted interference. Leveraging this vulnerability, we propose a novel two-stage attack framework capable of manipulating online constructed maps. First, our method identifies vulnerable asymmetric scenes along the victim AV's potential route. Then, we optimize the location and pattern of camera-blinding attacks and adversarial patch attacks. Evaluations on a public AD dataset demonstrate that our attacks can degrade mapping accuracy by up to 9.9% in average precision, render up to 44% of targeted routes unreachable, and increase unsafe planned trajectory rates-colliding with real-world road boundaries-by up to 27%. These attacks are also validated on a real-world testbed vehicle. We further analyze root causes of the symmetry bias, attributing them to training data imbalance, model architecture, and map element representation. Based on these findings, we propose asymmetric data fine-tuning as a targeted defense, which significantly improves model robustness. To the best of our knowledge, this study presents the first vulnerability assessment of online map construction models and introduces the first digital and physical attack against them. © 2025 Copyright held by the owner/author(s).
AB - High-definition (HD) maps provide precise environmental information essential for prediction and planning in autonomous driving (AD) systems. Due to the high cost of labeling and maintenance, recent research has turned to online HD map construction using onboard sensor data, offering wider coverage and more timely updates for autonomous vehicles (AVs). However, the robustness of online map construction under adversarial conditions remains underexplored. In this paper, we present a systematic vulnerability analysis of online map construction models, which reveals that these models exhibit an inherent bias toward predicting symmetric road structures. In asymmetric scenes like forks or merges, this bias often causes the model to mistakenly predict a straight boundary that mirrors the opposite side. We demonstrate that this vulnerability persists in the real-world and can be reliably triggered by obstruction or targeted interference. Leveraging this vulnerability, we propose a novel two-stage attack framework capable of manipulating online constructed maps. First, our method identifies vulnerable asymmetric scenes along the victim AV's potential route. Then, we optimize the location and pattern of camera-blinding attacks and adversarial patch attacks. Evaluations on a public AD dataset demonstrate that our attacks can degrade mapping accuracy by up to 9.9% in average precision, render up to 44% of targeted routes unreachable, and increase unsafe planned trajectory rates-colliding with real-world road boundaries-by up to 27%. These attacks are also validated on a real-world testbed vehicle. We further analyze root causes of the symmetry bias, attributing them to training data imbalance, model architecture, and map element representation. Based on these findings, we propose asymmetric data fine-tuning as a targeted defense, which significantly improves model robustness. To the best of our knowledge, this study presents the first vulnerability assessment of online map construction models and introduces the first digital and physical attack against them. © 2025 Copyright held by the owner/author(s).
KW - Autonomous driving
KW - online map construction
KW - physical attack
UR - https://www.scopus.com/pages/publications/105023889421
UR - https://www.scopus.com/record/pubmetrics.uri?eid=2-s2.0-105023889421&origin=recordpage
U2 - 10.1145/3719027.3765092
DO - 10.1145/3719027.3765092
M3 - RGC 32 - Refereed conference paper (with host publication)
SN - 979-8-4007-1525-9
T3 - CCS - Proceedings of the ACM SIGSAC Conference on Computer and Communications Security
SP - 3251
EP - 3265
BT - CCS '25
PB - Association for Computing Machinery
T2 - 32nd ACM SIGSAC Conference on Computer and Communications Security (CCS 2025)
Y2 - 13 October 2025 through 17 October 2025
ER -