IP Library › Granted Patent US 12,403,936
Granted Patent B2
US 12,403,936 · App. 18/043,449 · Granted Sep 2, 2025

Method for controlling a driver assistance system during operation of a vehicle

Inventors: Nikhil Kapoor (Wolfsburg, DE); Jan David Schneider (Wolfsburg, DE); Serin Varghese (Braunschweig, DE)
Assignee: VOLKSWAGEN AKTIENGESELLSCHAFT
B60W60/0015B60W50/0098B60W50/14B60W60/0053G06F18/2131G06F21/56B60W2420/403B60W2420/408G06N3/08
View Patent ↗
Loading inventors, assignments & file history…
Monitor This Case
Get email alerts when status or documents change.
Order Certified Copies
Most orders are placed with the USPTO same day — all within 24 business hours.
Order via The Patent Place →
Pre-filled with this patent's details
Quick Facts
Patent No.
US 12,403,936
App. No.
18/043,449
Granted
Sep 2, 2025
Kind
B2
Abstract

The disclosure relates to a method for controlling a driver assistance system during operation of a, especially partially automated, fully automated or autonomous, vehicle, wherein the driver assistance system comprises: a, for example at least one, sensor for observing an environment of the vehicle and an electronic control unit using a, especially at least one, neural network for analyzing sensor data of the sensor and providing perception tasks based on the analyzed sensor data, the method comprising: providing a data set of the sensor data by the sensor) in a spatial domain; transforming the data set of the sensor data by the electronic control unit using frequency analysis into a frequency spectrum in a frequency domain; and analyzing the frequency spectrum of the data set in order to detect an adversarially attacked data set, for example before analyzing the sensor data for providing perception tasks.

Claims (69)

1. A method for controlling a driver assistance system during operation of a vehicle, wherein the driver assistance system comprises at least one sensor for observing an environment of the vehicle and an electronic control unit using a neural network for analyzing sensor data of the at least one sensor and providing perception tasks for the vehicle based on the analyzed sensor data, wherein the sensor data comprises one or more of optical, acoustical, and electromagnetic data, the method comprising:

providing a data set of the sensor data by the at least one sensor in a spatial domain;

transforming the data set of the sensor data by the electronic control unit using frequency analysis into a frequency spectrum in a frequency domain; and

analyzing the frequency spectrum of the data set in order to detect an adversarially attacked data set; wherein

wherein in response to an adversarially attacked data set being detected from analyzing the frequency spectrum, at least the following is conducted: selectively activating a security mechanism against an adversarial attack;

wherein the security mechanism comprises one or more of:

activating a pre-processing technique to remove adversarial attack from the data set;

using a denoising filter for cleaning the adversarially attacked data set;

using a hardened neural network for analyzing the adversarially attacked data set;

using multiple other neural networks with different architectures in an ensemble and performing a consolidation of their output for analyzing the adversarially attacked data set;

applying rule-based technique for analyzing the adversarially attacked data set, especially using external, human-readable devices; and

requesting a user of the vehicle for analyzing the adversarially attacked data set; and

wherein the neural network or a special detecting neural network used for detecting the adversarially attacked data set are trained in the frequency domain on frequency spectrums of clean data sets and on frequency spectrums of prepared adversarially attacked data sets in order to learn differences between the frequency spectrums of the clean data sets and the frequency spectrums of the adversarially attacked data sets in the frequency domain.

2. The method of claim 1 , wherein providing the data set of the sensor data by the sensor in the spatial domain, transforming the data set of the sensor data by the electronic control unit using frequency analysis into the frequency spectrum in the frequency domain, and analyzing the frequency spectrum of the data set in order to detect the adversarially attacked data set are executed before analyzing the sensor data for providing perception tasks for the vehicle.

3. The method of claim 1 , wherein the sensor data comprise camera, lidar, and/or radar data.

4. The method of claim 1 , wherein the frequency analysis is provided by one or more of a discrete Fourier transformation (DFT), a discrete cosine transformation, and Wavelet transformation.

5. The method of claim 1 , wherein for detecting the adversarially attacked data set, the neural network is used, which is also used for analyzing the sensor data of the sensor and for providing perception tasks for the vehicle.

6. The method of claim 1 , wherein for detecting the adversarially attacked data set, a denoising filter is used for denoising the frequency spectrum of the data set in the frequency domain; wherein the denoising filter is built in the frequency domain using frequency spectrums of clean data sets and noise spectrums of prepared adversarially attacked data sets.

7. The method of claim 1 , wherein for detecting the adversarially attacked data set, the frequency spectrum of the data set are compared with a denoised frequency spectrum; wherein a threshold is applied by comparing the frequency spectrum of the data set with the denoised frequency spectrum; wherein the attacked data sets will be detected in response to a difference between the frequency spectrum of the data set and the denoised frequency spectrum is greater than the applied threshold.

8. The method of claim 1 , wherein when an adversarially attacked data set is detected, at least the following conducted: initiating an emergency maneuver.

9. The method of claim 8 , wherein the emergency maneuver comprises one or more of: reducing vehicle speed, initiating an emergency stop, providing an alarm inside and/or outside of the vehicle, activating a manual driving mode, and deactivate the driver assistance system.

10. An electronic control unit, comprising:

a memory, in which a program code is stored; and

a processor, wherein when executing the program code by the processor, the processor is configured to at least:

provide a data set of sensor data in a spatial domain, wherein the sensor data comprises one or more of optical, acoustical, and electromagnetic data;

transform the data set of the sensor data using frequency analysis into a frequency spectrum in a frequency domain; and

analyze the frequency spectrum of the data set in order to detect an adversarially attacked data set; wherein

wherein in response to an adversarially attacked data set being detected from analyzing the frequency spectrum, at least the following is conducted: selectively activating a security mechanism against an adversarial attack;

wherein the security mechanism comprises one or more of:

activating a pre-processing technique to remove adversarial attack from the data set;

using a denoising filter for cleaning the adversarially attacked data set;

using a hardened neural network for analyzing the adversarially attacked data set;

using multiple other neural networks with different architectures in an ensemble and performing a consolidation of their output for analyzing the adversarially attacked data set;

applying rule-based technique for analyzing the adversarially attacked data set, especially using external, human-readable devices; and

requesting a user of the vehicle for analyzing the adversarially attacked data set; and

wherein the neural network and/or a special detecting neural network used for detecting the adversarially attacked data set are trained in the frequency domain on frequency spectrums of clean data sets and on frequency spectrums of prepared adversarially attacked data sets in order to learn differences between the frequency spectrums of the clean data sets and the frequency spectrums of the adversarially attacked data sets in the frequency domain.

11. A vehicle comprising an electronic control unit, the electronic control unit comprising:

a memory, in which a program code is stored; and

a processor, wherein when executing the program code by the processor, the processor is configured to at least:

provide a data set of sensor data in a spatial domain, wherein the sensor data comprises one or more of optical, acoustical, and electromagnetic data;

transform the data set of the sensor data using frequency analysis into a frequency spectrum in a frequency domain; and

analyze the frequency spectrum of the data set in order to detect an adversarially attacked data set; wherein

wherein in response to an adversarially attacked data set being detected from analyzing the frequency spectrum, at least the following is conducted: selectively activating a security mechanism against an adversarial attack;

wherein the security mechanism comprises one or more of:

activating a pre-processing technique to remove adversarial attack from the data set;

using a denoising filter for cleaning the adversarially attacked data set;

using a hardened neural network for analyzing the adversarially attacked data set;

using multiple other neural networks with different architectures in an ensemble and performing a consolidation of their output for analyzing the adversarially attacked data set;

applying rule-based technique for analyzing the adversarially attacked data set, especially using external, human-readable devices; and

requesting a user of the vehicle for analyzing the adversarially attacked data set; and

wherein the neural network or a special detecting neural network used for detecting the adversarially attacked data set are trained in the frequency domain on frequency spectrums of clean data sets and on frequency spectrums of prepared adversarially attacked data sets in order to learn differences between the frequency spectrums of the clean data sets and the frequency spectrums of the adversarially attacked data sets in the frequency domain.

12. A non-transitory storage medium comprising instructions for a processor, which instructions, when executed by the processor, cause the processor to:

provide a data set of the sensor data by the sensor in a spatial domain, wherein the sensor data comprises one or more of optical, acoustical, and electromagnetic data;

transform the data set of the sensor data by the electronic control unit using frequency analysis into a frequency spectrum in a frequency domain; and

analyze the frequency spectrum of the data set in order to detect an adversarially attacked data set; wherein

wherein in response to an adversarially attacked data set being detected from analyzing the frequency spectrum, at least the following is conducted: selectively activating a security mechanism against an adversarial attack;

wherein the security mechanism comprises one or more of:

activating a pre-processing technique to remove adversarial attack from the data set;

using a denoising filter for cleaning the adversarially attacked data set;

using a hardened neural network for analyzing the adversarially attacked data set;

using multiple other neural networks with different architectures in an ensemble and performing a consolidation of their output for analyzing the adversarially attacked data set;

applying rule-based technique for analyzing the adversarially attacked data set, especially using external, human-readable devices; and

requesting a user of the vehicle for analyzing the adversarially attacked data set; and

wherein the neural network or a special detecting neural network used for detecting the adversarially attacked data set are trained in the frequency domain on frequency spectrums of clean data sets and on frequency spectrums of prepared adversarially attacked data sets in order to learn differences between the frequency spectrums of the clean data sets and the frequency spectrums of the adversarially attacked data sets in the frequency domain.

13. The method of claim 1 , wherein providing the data set of the sensor data by the sensor in the spatial domain, transforming the data set of the sensor data by the electronic control unit using frequency analysis into the frequency spectrum in the frequency domain, and analyzing the frequency spectrum of the data set in order to detect the adversarially attacked data set are executed periodically.

14. The method of claim 1 , wherein providing the data set of the sensor data by the sensor in the spatial domain, transforming the data set of the sensor data by the electronic control unit using frequency analysis into the frequency spectrum in the frequency domain, and analyzing the frequency spectrum of the data set in order to detect the adversarially attacked data set are executed for each data set of the sensor data during operation of the vehicle.

15. The method of claim 1 , wherein the data set is provided as a picture of the environment of the vehicle.

16. The method of claim 1 , wherein the electronic control unit uses a deep neural network as the neural network for analyzing the sensor data of the sensor and for providing perception tasks for the vehicle based on the analyzed sensor data.

17. The method of claim 1 , wherein for detecting the adversarially attacked data set, a special detecting neural network is used.

Assignments (1)
ASSIGNMENT OF ASSIGNOR'S INTEREST Recorded Jul 11, 2023
From: KAPOOR, NIKHIL; SCHNEIDER, JAN DAVID; VARGHESE, SERIN
To: VOLKSWAGEN AKTIENGESELLSCHAFT
Reel/Frame 064217/0604 →
Priority Claims (1)
DE 10 2020 211 097.2 · Sep 2, 2020 · national
Continuity (1)
Related Publication 20230331254A1 · Oct 19, 2023
References Cited (25)
US 10726134B2 · Wang et al. · 2020 [cited by applicant]
US 11106893B1 · Zhu · 2021 [cited by examiner]
US 20190187718A1 · Zou · 2019 [cited by examiner]
US 20210026958A1 · Filipek · 2021 [cited by examiner]
US 20210064980A1 · Heinrich · 2021 [cited by examiner]
US 20210156960A1 · Popov · 2021 [cited by examiner]
US 20220126863A1 · Moustafa · 2022 [cited by examiner]
US 20220157165A1 · Dantrey · 2022 [cited by examiner]
US 20220301282A1 · Witt · 2022 [cited by examiner]
US 20230213610A1 · Eberspach · 2023 [cited by examiner]
WO 2022048812A1 · 2022 [cited by applicant]
“Zifan Wang”, “Yilin Yang”, “Ankit Shrivastava”, “Varun Rawal,”, “Zihan Ding”, “Towards Frequency-Based Explanation for Robust CNN” “May 6, 2020” pp. 1-7 (Year: 2020). [cited by examiner]
“Fei Guo”, “Zichang Wang”, “Suguo Du”, “Huaxin Li”, “Haojin Zhu”, “Detecting Vehicle Anomaly in the Edge via Sensor Consistency and Frequency Characteristic” vol. 68, No. 6, 5618-5628 (Year: 2019). [cited by examiner]
“Zifan Wang”, “Yilin Yasng”, “Ankit Srivastava”, “Varun Rawal”, “Zihao Ding”. “Towards Frequency-Based Explanation for Robust CNN” (Year: 2020). [cited by examiner]
Smith, S.W. et al., “Chapter 17: Custom Filters,” The Scientist and Engineer's Guide to Digital Signal Processing, URL: http://www.dspguide.com/CH17.PDF, 14 pages, 1997. [cited by applicant]
Reschka, Andreas et al., “A Surveillance and Safety System based on Performance Criteria and Functional Degradation for an Autonomous Vehicle,” International IEEE Conference on Intelligent Transportation Systems, pp. 23… [cited by applicant]
Meng, Dongyu et al., “MagNet: a Two-Pronged Defense against Adversarial Examples,” arXiv:1705.09064v2, CCS '17, 13 pages, Oct. 30, 2017. [cited by applicant]
Xu, Weilan et al., “Feature Squeezing: Detecting Adversarial Examples in Deep Neural Networks,” Network and Distributed Systems Security Symposium (NDSS), arXiv:1704.01155v2, 15 pages, Dec. 5, 2017. [cited by applicant]
Fujiyoshi, Hirnobu et al., “Deep Learning-Based Image Recognition of Autonomous Driving,” IATSS Research 43, pp. 244-252, Dec. 6, 2019. [cited by applicant]
Vacanti, Giovanni et al., “Adversarial Detection and Correction by Matching Prediction Distributions,” arXiv:2002.09364v1, 13 pages, Feb. 21, 2020. [cited by applicant]
Frank, Joel et al., “Leveraging Frequency Analysis for Deep Fake Image Recognition,” arXiv:200308685v, International Conference on Machine Learning, PMLR, URL: https://arxiv.org/pdf/2003.08685v1.pdf, pp. 3247-3258, Mar.… [cited by applicant]
Wang, Zifan et al., “Towards Frequency-Based Explanation for Robust CNN,” arXiv:2005.03141v1, 7 pages, May 6, 2020. [cited by applicant]
Wintel, Florian et al., “Selected Topics in Deep Learning #1: Adversarial Attacks—Tutorial: Adversarial Examples Against Image Recognition,” Institute for Applied AI, URL: https://ai.hdm-stuttgart.de/news/2020/selected-… [cited by applicant]
German Office Action, Application No. 102020211097.2, 7 pages, Jul. 15, 2021. [cited by applicant]
International Search Report and Written Opinion, Application No. PCT/EP2021/068721, 14 pages, Oct. 22, 2021. [cited by applicant]