@article{Bai2025, 
author = {Xuesong Bai and Peng Dong and Jinlei Wang and Yuanhao Huang and Haiyang Yu and Yilong Ren},
title = {AdvGLOW: Covert adversarial attacks against autonomous driving perception},
year = {2025},
journal = {Journal of Intelligent and Connected Vehicles},
volume = {8},
number = {4},
pages = {9210067},
keywords = {autonomous driving, perception test, adversarial attack, flow-based generation},
url = {https://www.sciopen.com/article/10.26599/JICV.2025.9210067},
doi = {10.26599/JICV.2025.9210067},
abstract = {Autonomous driving technology is becoming increasingly popular, transforming transportation systems worldwide. However, its perception modules are highly vulnerable to adversarial attacks, which exploit weaknesses in deep neural networks, leading to potential safety risks and compromised decision-making in autonomous systems. In this study, we propose AdvGLOW, a novel adversarial attack model tailored for covert attacks on autonomous driving perception modules in traffic scenarios. Leveraging an information exchange network within a flow-based model, AdvGLOW introduces reversible data transformations to achieve high attack success with minimal perturbation visibility. By optimizing a combined global-local loss, our model preserves structural details while embedding adversarial features, resulting in robust yet visually imperceptible adversarial samples. We conduct extensive experiments on traffic-related datasets, demonstrating that the generated adversarial samples are challenging for both humans and algorithms to detect. Additionally, this method exhibits strong attack robustness and transferability.}
}