Temporal Logic-Based Multi-Vehicle Backdoor Attacks against Offline RL Agents in End-to-end Autonomous Driving

Fuente: arXiv
Saved in:
Bibliographic Details
Main Authors: Chen, Xuan, Feng, Shiwei, Xiong, Zikang, An, Shengwei, Mao, Yunshu, Yan, Lu, Tao, Guanhong, Guo, Wenbo, Zhang, Xiangyu
Format: Preprint
Published: 2025
Subjects:
Online Access:
Tags: Add Tag
No Tags, Be the first to tag this record!
_version_ 1866915548138307584
author Chen, Xuan
Feng, Shiwei
Xiong, Zikang
An, Shengwei
Mao, Yunshu
Yan, Lu
Tao, Guanhong
Guo, Wenbo
Zhang, Xiangyu
author_facet Chen, Xuan
Feng, Shiwei
Xiong, Zikang
An, Shengwei
Mao, Yunshu
Yan, Lu
Tao, Guanhong
Guo, Wenbo
Zhang, Xiangyu
contents Assessing the safety of autonomous driving (AD) systems against security threats, particularly backdoor attacks, is a stepping stone for real-world deployment. However, existing works mainly focus on pixel-level triggers that are impractical to deploy in the real world. We address this gap by introducing a novel backdoor attack against the end-to-end AD systems that leverage one or more other vehicles' trajectories as triggers. To generate precise trigger trajectories, we first use temporal logic (TL) specifications to define the behaviors of attacker vehicles. Configurable behavior models are then used to generate these trajectories, which are quantitatively evaluated and iteratively refined based on the TL specifications. We further develop a negative training strategy by incorporating patch trajectories that are similar to triggers but are designated not to activate the backdoor. It enhances the stealthiness of the attack and refines the system's responses to trigger scenarios. Through extensive experiments on 5 offline reinforcement learning (RL) driving agents with 6 trigger patterns and target action combinations, we demonstrate the flexibility and effectiveness of our proposed attack, showing the under-exploration of existing end-to-end AD systems' vulnerabilities to such trajectory-based backdoor attacks.
format Preprint
id arxiv_https___arxiv_org_abs_2509_16950
institution arXiv
publishDate 2025
record_format arxiv
spellingShingle Temporal Logic-Based Multi-Vehicle Backdoor Attacks against Offline RL Agents in End-to-end Autonomous Driving
Chen, Xuan
Feng, Shiwei
Xiong, Zikang
An, Shengwei
Mao, Yunshu
Yan, Lu
Tao, Guanhong
Guo, Wenbo
Zhang, Xiangyu
Cryptography and Security
Assessing the safety of autonomous driving (AD) systems against security threats, particularly backdoor attacks, is a stepping stone for real-world deployment. However, existing works mainly focus on pixel-level triggers that are impractical to deploy in the real world. We address this gap by introducing a novel backdoor attack against the end-to-end AD systems that leverage one or more other vehicles' trajectories as triggers. To generate precise trigger trajectories, we first use temporal logic (TL) specifications to define the behaviors of attacker vehicles. Configurable behavior models are then used to generate these trajectories, which are quantitatively evaluated and iteratively refined based on the TL specifications. We further develop a negative training strategy by incorporating patch trajectories that are similar to triggers but are designated not to activate the backdoor. It enhances the stealthiness of the attack and refines the system's responses to trigger scenarios. Through extensive experiments on 5 offline reinforcement learning (RL) driving agents with 6 trigger patterns and target action combinations, we demonstrate the flexibility and effectiveness of our proposed attack, showing the under-exploration of existing end-to-end AD systems' vulnerabilities to such trajectory-based backdoor attacks.
title Temporal Logic-Based Multi-Vehicle Backdoor Attacks against Offline RL Agents in End-to-end Autonomous Driving
topic Cryptography and Security
url https://arxiv.org/abs/2509.16950