{"id":"https://openalex.org/W4416514072","doi":"https://doi.org/10.1109/isncc66965.2025.11250426","title":"Multi-Scenario Simulation of Machine Learning Based Vision Attacks in CARLA","display_name":"Multi-Scenario Simulation of Machine Learning Based Vision Attacks in CARLA","publication_year":2025,"publication_date":"2025-10-27","ids":{"openalex":"https://openalex.org/W4416514072","doi":"https://doi.org/10.1109/isncc66965.2025.11250426"},"language":"en","primary_location":{"id":"doi:10.1109/isncc66965.2025.11250426","is_oa":false,"landing_page_url":"https://doi.org/10.1109/isncc66965.2025.11250426","pdf_url":null,"source":null,"license":null,"license_id":null,"version":"publishedVersion","is_accepted":true,"is_published":true,"raw_source_name":"2025 International Symposium on Networks, Computers and Communications (ISNCC)","raw_type":"proceedings-article"},"type":"article","indexed_in":["crossref"],"open_access":{"is_oa":true,"oa_status":"green","oa_url":"https://research-information.bris.ac.uk/files/473549598/ISNCC_4_.pdf","any_repository_has_fulltext":true},"authorships":[{"author_position":"first","author":{"id":null,"display_name":"Lanai Huang","orcid":null},"institutions":[{"id":"https://openalex.org/I183067930","display_name":"Shanghai Jiao Tong University","ror":"https://ror.org/0220qvk04","country_code":"CN","type":"education","lineage":["https://openalex.org/I183067930"]}],"countries":["CN"],"is_corresponding":true,"raw_author_name":"Lanai Huang","raw_affiliation_strings":["Shanghai Jiao Tong University,Shanghai,China"],"raw_orcid":null,"affiliations":[{"raw_affiliation_string":"Shanghai Jiao Tong University,Shanghai,China","institution_ids":["https://openalex.org/I183067930"]}]},{"author_position":"middle","author":{"id":"https://openalex.org/A5111221393","display_name":"Winston Ellis","orcid":null},"institutions":[{"id":"https://openalex.org/I36234482","display_name":"University of Bristol","ror":"https://ror.org/0524sp257","country_code":"GB","type":"education","lineage":["https://openalex.org/I36234482"]}],"countries":["GB"],"is_corresponding":false,"raw_author_name":"Winston Ellis","raw_affiliation_strings":["University of Bristol,Bristol,UK"],"raw_orcid":null,"affiliations":[{"raw_affiliation_string":"University of Bristol,Bristol,UK","institution_ids":["https://openalex.org/I36234482"]}]},{"author_position":"last","author":{"id":"https://openalex.org/A5044341219","display_name":"Sana Belguith","orcid":"https://orcid.org/0000-0003-0069-8552"},"institutions":[{"id":"https://openalex.org/I36234482","display_name":"University of Bristol","ror":"https://ror.org/0524sp257","country_code":"GB","type":"education","lineage":["https://openalex.org/I36234482"]}],"countries":["GB"],"is_corresponding":false,"raw_author_name":"Sana Belguith","raw_affiliation_strings":["University of Bristol,Bristol,UK"],"raw_orcid":null,"affiliations":[{"raw_affiliation_string":"University of Bristol,Bristol,UK","institution_ids":["https://openalex.org/I36234482"]}]}],"institutions":[],"countries_distinct_count":2,"institutions_distinct_count":3,"corresponding_author_ids":[],"corresponding_institution_ids":["https://openalex.org/I183067930"],"apc_list":null,"apc_paid":null,"fwci":0.0,"has_fulltext":true,"cited_by_count":0,"citation_normalized_percentile":{"value":0.18315124,"is_in_top_1_percent":false,"is_in_top_10_percent":false},"cited_by_percentile_year":null,"biblio":{"volume":null,"issue":null,"first_page":"1","last_page":"8"},"is_retracted":false,"is_paratext":false,"is_xpac":false,"primary_topic":{"id":"https://openalex.org/T11689","display_name":"Adversarial Robustness in Machine Learning","score":0.9878000020980835,"subfield":{"id":"https://openalex.org/subfields/1702","display_name":"Artificial Intelligence"},"field":{"id":"https://openalex.org/fields/17","display_name":"Computer Science"},"domain":{"id":"https://openalex.org/domains/3","display_name":"Physical Sciences"}},"topics":[{"id":"https://openalex.org/T11689","display_name":"Adversarial Robustness in Machine Learning","score":0.9878000020980835,"subfield":{"id":"https://openalex.org/subfields/1702","display_name":"Artificial Intelligence"},"field":{"id":"https://openalex.org/fields/17","display_name":"Computer Science"},"domain":{"id":"https://openalex.org/domains/3","display_name":"Physical Sciences"}},{"id":"https://openalex.org/T11099","display_name":"Autonomous Vehicle Technology and Safety","score":0.004800000227987766,"subfield":{"id":"https://openalex.org/subfields/2203","display_name":"Automotive Engineering"},"field":{"id":"https://openalex.org/fields/22","display_name":"Engineering"},"domain":{"id":"https://openalex.org/domains/3","display_name":"Physical Sciences"}},{"id":"https://openalex.org/T10036","display_name":"Advanced Neural Network Applications","score":0.001500000013038516,"subfield":{"id":"https://openalex.org/subfields/1707","display_name":"Computer Vision and Pattern Recognition"},"field":{"id":"https://openalex.org/fields/17","display_name":"Computer Science"},"domain":{"id":"https://openalex.org/domains/3","display_name":"Physical Sciences"}}],"keywords":[{"id":"https://openalex.org/keywords/adversarial-system","display_name":"Adversarial system","score":0.7483999729156494},{"id":"https://openalex.org/keywords/perception","display_name":"Perception","score":0.4977000057697296},{"id":"https://openalex.org/keywords/speedup","display_name":"Speedup","score":0.47620001435279846},{"id":"https://openalex.org/keywords/latency","display_name":"Latency (audio)","score":0.4675999879837036},{"id":"https://openalex.org/keywords/deep-learning","display_name":"Deep learning","score":0.45320001244544983},{"id":"https://openalex.org/keywords/collision","display_name":"Collision","score":0.4239000082015991}],"concepts":[{"id":"https://openalex.org/C41008148","wikidata":"https://www.wikidata.org/wiki/Q21198","display_name":"Computer science","level":0,"score":0.777999997138977},{"id":"https://openalex.org/C37736160","wikidata":"https://www.wikidata.org/wiki/Q1801315","display_name":"Adversarial system","level":2,"score":0.7483999729156494},{"id":"https://openalex.org/C154945302","wikidata":"https://www.wikidata.org/wiki/Q11660","display_name":"Artificial intelligence","level":1,"score":0.5968999862670898},{"id":"https://openalex.org/C26760741","wikidata":"https://www.wikidata.org/wiki/Q160402","display_name":"Perception","level":2,"score":0.4977000057697296},{"id":"https://openalex.org/C119857082","wikidata":"https://www.wikidata.org/wiki/Q2539","display_name":"Machine learning","level":1,"score":0.47760000824928284},{"id":"https://openalex.org/C68339613","wikidata":"https://www.wikidata.org/wiki/Q1549489","display_name":"Speedup","level":2,"score":0.47620001435279846},{"id":"https://openalex.org/C82876162","wikidata":"https://www.wikidata.org/wiki/Q17096504","display_name":"Latency (audio)","level":2,"score":0.4675999879837036},{"id":"https://openalex.org/C108583219","wikidata":"https://www.wikidata.org/wiki/Q197536","display_name":"Deep learning","level":2,"score":0.45320001244544983},{"id":"https://openalex.org/C121704057","wikidata":"https://www.wikidata.org/wiki/Q352070","display_name":"Collision","level":2,"score":0.4239000082015991},{"id":"https://openalex.org/C2778403875","wikidata":"https://www.wikidata.org/wiki/Q20312394","display_name":"Adversarial machine learning","level":3,"score":0.42080000042915344},{"id":"https://openalex.org/C6528762","wikidata":"https://www.wikidata.org/wiki/Q1574298","display_name":"Traffic sign recognition","level":4,"score":0.38609999418258667},{"id":"https://openalex.org/C12725497","wikidata":"https://www.wikidata.org/wiki/Q810247","display_name":"Baseline (sea)","level":2,"score":0.37560001015663147},{"id":"https://openalex.org/C26517878","wikidata":"https://www.wikidata.org/wiki/Q228039","display_name":"Key (lock)","level":2,"score":0.37310001254081726},{"id":"https://openalex.org/C38652104","wikidata":"https://www.wikidata.org/wiki/Q3510521","display_name":"Computer security","level":1,"score":0.3702000081539154},{"id":"https://openalex.org/C31972630","wikidata":"https://www.wikidata.org/wiki/Q844240","display_name":"Computer vision","level":1,"score":0.3411000072956085},{"id":"https://openalex.org/C79403827","wikidata":"https://www.wikidata.org/wiki/Q3988","display_name":"Real-time computing","level":1,"score":0.3246999979019165},{"id":"https://openalex.org/C46637626","wikidata":"https://www.wikidata.org/wiki/Q6693015","display_name":"Low latency (capital markets)","level":2,"score":0.3005000054836273},{"id":"https://openalex.org/C50644808","wikidata":"https://www.wikidata.org/wiki/Q192776","display_name":"Artificial neural network","level":2,"score":0.2623000144958496},{"id":"https://openalex.org/C107457646","wikidata":"https://www.wikidata.org/wiki/Q207434","display_name":"Human\u2013computer interaction","level":1,"score":0.2619999945163727}],"mesh":[],"locations_count":3,"locations":[{"id":"doi:10.1109/isncc66965.2025.11250426","is_oa":false,"landing_page_url":"https://doi.org/10.1109/isncc66965.2025.11250426","pdf_url":null,"source":null,"license":null,"license_id":null,"version":"publishedVersion","is_accepted":true,"is_published":true,"raw_source_name":"2025 International Symposium on Networks, Computers and Communications (ISNCC)","raw_type":"proceedings-article"},{"id":"pmh:oai:research-information.bris.ac.uk:publications/82417e97-c262-4b26-9481-531b7d6531b8","is_oa":true,"landing_page_url":"https://hdl.handle.net/1983/82417e97-c262-4b26-9481-531b7d6531b8","pdf_url":"https://research-information.bris.ac.uk/files/473549598/ISNCC_4_.pdf","source":{"id":"https://openalex.org/S7407055359","display_name":"Explore Bristol Research","issn_l":null,"issn":null,"is_oa":false,"is_in_doaj":false,"is_core":false,"host_organization":null,"host_organization_name":null,"host_organization_lineage":[],"host_organization_lineage_names":[],"type":"repository"},"license":"cc-by","license_id":"https://openalex.org/licenses/cc-by","version":"submittedVersion","is_accepted":false,"is_published":false,"raw_source_name":"Huang, L, Ellis, W & Belguith, S 2025, Multi-Scenario Simulation of Machine Learning Based Vision Attacks in CARLA. in 2025 International Symposium on Networks, Computers and Communications (ISNCC). International Symposium on Networks, Computers and Communications (ISNCC), Institute of Electrical and Electronics Engineers (IEEE), Paris, France. https://doi.org/10.1109/ISNCC66965.2025.11250426","raw_type":"contributionToPeriodical"},{"id":"pmh:oai:research-information.bris.ac.uk:openaire/82417e97-c262-4b26-9481-531b7d6531b8","is_oa":true,"landing_page_url":"https://research-information.bris.ac.uk/en/publications/82417e97-c262-4b26-9481-531b7d6531b8","pdf_url":null,"source":{"id":"https://openalex.org/S4306400895","display_name":"Bristol Research (University of Bristol)","issn_l":null,"issn":null,"is_oa":false,"is_in_doaj":false,"is_core":false,"host_organization":"https://openalex.org/I36234482","host_organization_name":"University of Bristol","host_organization_lineage":["https://openalex.org/I36234482"],"host_organization_lineage_names":[],"type":"repository"},"license":"cc-by","license_id":"https://openalex.org/licenses/cc-by","version":"submittedVersion","is_accepted":false,"is_published":false,"raw_source_name":"Huang, L, Ellis, W & Belguith, S 2025, Multi-Scenario Simulation of Machine Learning Based Vision Attacks in CARLA. in 2025 International Symposium on Networks, Computers and Communications (ISNCC). International Symposium on Networks, Computers and Communications (ISNCC), Institute of Electrical and Electronics Engineers (IEEE), Paris, France. https://doi.org/10.1109/ISNCC66965.2025.11250426","raw_type":"contributionToPeriodical"}],"best_oa_location":{"id":"pmh:oai:research-information.bris.ac.uk:publications/82417e97-c262-4b26-9481-531b7d6531b8","is_oa":true,"landing_page_url":"https://hdl.handle.net/1983/82417e97-c262-4b26-9481-531b7d6531b8","pdf_url":"https://research-information.bris.ac.uk/files/473549598/ISNCC_4_.pdf","source":{"id":"https://openalex.org/S7407055359","display_name":"Explore Bristol Research","issn_l":null,"issn":null,"is_oa":false,"is_in_doaj":false,"is_core":false,"host_organization":null,"host_organization_name":null,"host_organization_lineage":[],"host_organization_lineage_names":[],"type":"repository"},"license":"cc-by","license_id":"https://openalex.org/licenses/cc-by","version":"submittedVersion","is_accepted":false,"is_published":false,"raw_source_name":"Huang, L, Ellis, W & Belguith, S 2025, Multi-Scenario Simulation of Machine Learning Based Vision Attacks in CARLA. in 2025 International Symposium on Networks, Computers and Communications (ISNCC). International Symposium on Networks, Computers and Communications (ISNCC), Institute of Electrical and Electronics Engineers (IEEE), Paris, France. https://doi.org/10.1109/ISNCC66965.2025.11250426","raw_type":"contributionToPeriodical"},"sustainable_development_goals":[],"awards":[],"funders":[],"has_content":{"pdf":true,"grobid_xml":true},"content_urls":{"pdf":"https://content.openalex.org/works/W4416514072.pdf","grobid_xml":"https://content.openalex.org/works/W4416514072.grobid-xml"},"referenced_works_count":22,"referenced_works":["https://openalex.org/W1901616594","https://openalex.org/W2243397390","https://openalex.org/W2284188655","https://openalex.org/W2746600820","https://openalex.org/W2781800156","https://openalex.org/W2798302089","https://openalex.org/W2905423756","https://openalex.org/W2911846900","https://openalex.org/W3015176854","https://openalex.org/W3015625436","https://openalex.org/W3032244443","https://openalex.org/W3041006851","https://openalex.org/W3107235539","https://openalex.org/W3132583427","https://openalex.org/W3163293237","https://openalex.org/W3192778626","https://openalex.org/W3197944870","https://openalex.org/W3210076120","https://openalex.org/W4282936640","https://openalex.org/W4313563688","https://openalex.org/W4378647963","https://openalex.org/W4396525424"],"related_works":[],"abstract_inverted_index":{"Autonomous":[0],"Vehicles":[1],"(AVs)":[2],"rely":[3],"heavily":[4],"on":[5,31,222],"machine":[6],"learning":[7],"(ML)":[8],"algorithms":[9],"for":[10,205,231],"real-time":[11,129,163,199],"perception":[12,164],"and":[13,28,64,78,95,101,112,122,175,195,201,208,235],"decisionmaking,":[14],"making":[15],"them":[16],"vulnerable":[17],"to":[18,119,146,184],"adversarial":[19,29,57,220],"attacks.":[20],"While":[21],"prior":[22],"studies":[23],"have":[24],"explored":[25],"physical":[26],"attacks":[27,43,87,138,197,221],"manipulations":[30],"static":[32],"datasets,":[33],"there":[34],"remains":[35],"a":[36,142,159],"significant":[37],"gap":[38],"in":[39,47,109,115,198,225,238],"understanding":[40],"how":[41],"ML-based":[42],"affect":[44],"AV":[45,156,239],"performance":[46],"dynamic":[48,226],"environments.":[49],"To":[50],"address":[51],"this,":[52],"we":[53],"simulate":[54],"two":[55],"representative":[56],"attacks,":[58],"Fast":[59],"Gradient":[60],"Sign":[61],"Method":[62],"(FGSM)":[63],"Simple":[65],"Black-box":[66],"Attack":[67],"(SimBA),":[68],"within":[69,180],"the":[70,91,135,148,190,203,215],"CARLA":[71],"simulator,":[72],"targeting":[73],"camera":[74,167,223],"sensors":[75,224],"under":[76,124],"urban":[77,110],"motorway":[79,116],"driving":[80],"scenarios.":[81],"Our":[82],"experiments":[83],"demonstrate":[84],"that":[85,133],"both":[86,232],"can":[88],"significantly":[89],"increase":[90],"probability":[92],"of":[93,155,182,192,219],"collisions":[94],"reduce":[96],"time-to-collision":[97],"(TTC),":[98],"with":[99],"FGSM":[100],"SimBA":[102],"causing":[103],"over":[104,113],"$60":[105,143],"\\%$":[106],"collision":[107],"rates":[108],"settings":[111],"95%":[114],"scenarios,":[117],"compared":[118],"only":[120],"12%":[121],"3%":[123],"baseline":[125],"conditions.":[126],"Furthermore,":[127],"our":[128],"feasibility":[130],"analysis":[131],"shows":[132],"even":[134],"most":[136],"efficient":[137],"require":[139],"at":[140,172],"least":[141],"\\times$":[144],"speedup":[145],"meet":[147],"sub-":[149],"50":[150],"ms":[151],"end-to-end":[152],"latency":[153],"requirements":[154],"systems":[157],"-":[158],"threshold":[160],"dictated":[161],"by":[162],"needs,":[165],"where":[166],"frames":[168],"are":[169],"typically":[170],"processed":[171],"30-60":[173],"FPS":[174],"decisions":[176],"must":[177],"be":[178],"made":[179],"tens":[181],"milliseconds":[183],"ensure":[185],"safety.":[186],"These":[187],"findings":[188],"underscore":[189],"limitations":[191],"traditional":[193],"white-box":[194],"black-box":[196],"deployments":[200],"highlight":[202],"need":[204],"simulationaware":[206],"optimizations":[207],"hybrid":[209],"attack":[210,233],"strategies.":[211],"This":[212],"study":[213],"provides":[214],"first":[216],"comprehensive":[217],"evaluation":[218],"environments,":[227],"offering":[228],"practical":[229],"insights":[230],"refinement":[234],"defense":[236],"development":[237],"systems.":[240]},"counts_by_year":[],"updated_date":"2026-04-27T08:22:11.395708","created_date":"2025-11-23T00:00:00"}
