Slow Drift Temporal Poisoning attacks and vision language model guided defense for BEV perception in autonomous vehicles

World-model BEV perception maintains a persistent temporal latent memory that can be gradually corrupted by perturbations too small to trigger existing per-frame anomaly checks. We formalize this as Slow-Drift Temporal Poisoning (SDTP): frame-wise perturbations bounded by a small digital L∞ budget (ε ≤ 2/255) - a standard proxy for low perturbation magnitude, not a validated measure of human-perceptual imperceptibility or physical-world realizability, jointly optimized across a temporal window via a Backward Temporal Gradient procedure, that reach an 84.3% Temporal Drift Success Rate by frame 32 on BEVFormer-T while evading temporal-consistency defenses calibrated on single-step thresholds. We propose SemantiGuard, a cross-modal defense that cross-checks BEV detections against a frozen vision-language model’s scene description and triggers latent-memory rollback on divergence, reducing the Temporal Drift Success Rate (TDSR) from 91.2% to 13.8% under the primary evaluation configuration (SDTP-L: ε = 4/255, T = 32, BEVFormer-T, Table 6), with a lower 11.2% TDSR observed under the smaller SDTP-M ablation configuration (ε = 2/255, T = 16, Table 7). We also introduce TemporalAdvBEV, a benchmark extending RoboBEV with multi-frame adversarial configurations and drift-specific metrics. These results indicate that temporal memory is an attack surface that BEV security evaluation has not yet accounted for, and that cross-modal semantic verification is a promising, if not yet field-validated, direction for defending it. The paper also introduces TemporalAdvBEV, a benchmark extending RoboBEV with multi-frame adversarial configurations and drift-specific metrics, designed to support evaluation on both nuScenes and Waymo Open, with nuScenes results reported in this manuscript.

Authors

Institutions

Publication Details

Journal
Discover Vehicles
Published
2026-09-21
DOI
https://doi.org/10.1007/s44465-026-00048-7
Primary Topic
Adversarial Robustness in Machine Learning
Type
article
Field-Weighted Citation Impact
0.00
Controls
|||
ALL TIME
JAN
FEB
MAR
APR
MAY
JUN
JUL
AUG
SEP
article

Slow Drift Temporal Poisoning attacks and vision language model guided defense for BEV perception in autonomous vehicles

Sudhakar Hallur, Srikar Geethaprabhu Beechu, Hari Krishna Kattoju, G. Baskaran et al.
Discover Vehicles
Adversarial Robustness in Machine Learning
article

Slow Drift Temporal Poisoning attacks and vision language model guided defense for BEV perception in autonomous vehicles

Sudhakar Hallur, Srikar Geethaprabhu Beechu, Hari Krishna Kattoju, G. Baskaran, B. V. Gajendra
article en

Abstract

World-model BEV perception maintains a persistent temporal latent memory that can be gradually corrupted by perturbations too small to trigger existing per-frame anomaly checks. We formalize this as Slow-Drift Temporal Poisoning (SDTP): frame-wise perturbations bounded by a small digital L∞ budget (ε ≤ 2/255) - a standard proxy for low perturbation magnitude, not a validated measure of human-perceptual imperceptibility or physical-world realizability, jointly optimized across a temporal window via a Backward Temporal Gradient procedure, that reach an 84.3% Temporal Drift Success Rate by frame 32 on BEVFormer-T while evading temporal-consistency defenses calibrated on single-step thresholds. We propose SemantiGuard, a cross-modal defense that cross-checks BEV detections against a frozen vision-language model’s scene description and triggers latent-memory rollback on divergence, reducing the Temporal Drift Success Rate (TDSR) from 91.2% to 13.8% under the primary evaluation configuration (SDTP-L: ε = 4/255, T = 32, BEVFormer-T, Table 6), with a lower 11.2% TDSR observed under the smaller SDTP-M ablation configuration (ε = 2/255, T = 16, Table 7). We also introduce TemporalAdvBEV, a benchmark extending RoboBEV with multi-frame adversarial configurations and drift-specific metrics. These results indicate that temporal memory is an attack surface that BEV security evaluation has not yet accounted for, and that cross-modal semantic verification is a promising, if not yet field-validated, direction for defending it. The paper also introduces TemporalAdvBEV, a benchmark extending RoboBEV with multi-frame adversarial configurations and drift-specific metrics, designed to support evaluation on both nuScenes and Waymo Open, with nuScenes results reported in this manuscript.

Discover VehiclesVol. 2(1)
Jain University (IN), KLE Academy of Higher Education and Research (IN), Institute of Wood Science and Technology (IN), KLS Gogte Institute of Technology, East West Institute of Technology (IN), GITAM University (IN), SASTRA University (IN)
Openalex Percentile: Top 8%
Adversarial Robustness in Machine Learning
AI Navigator

Ask Laika to Summarize, Analyze, and Connect papers live on the map.

Summarize Papers & Methodologies

Extract key findings, datasets, and comparative methods across publications.

Benchmark Rankings & Visual Analytics

Rank top research institutions, authors, funders, topics, and journals by Field-Weighted Citation Impact (FWCI) and paper volume with instant charts.

Connect Distant Disciplines

Bridge topological clusters on the map to find hidden collaborative intersections.