Zonotope-Based Active Exposure of Stealthy Deception Attacks in Sensor-Fusion Systems
arXiv:2609.02587
2026
Dynamics
1 ideas extracted · analyzed Sep 3, 2026
What the math gives to ML
The paper provides a constructive active-exposure mechanism: represent bounded-noise state/output predictions and attack hypotheses as zonotopes, then optimize bounded control-channel perturbations so the admissible and attack output sets become separated. Its transferable asset is not merely interval uncertainty, but a receding-horizon controller that actively creates a measurable detection margin against multiple simultaneous sensor compromises. For neural sensor-fusion systems, the same mechanism can inject small probing perturbations into inputs or intermediate modalities and use Jacobian-based zonotopes to select perturbations that maximally separate trusted and corrupted-feature predictions. The key falsifiable signature is a sharp transition from overlapping sets to a positive separation margin as exposure budget increases.
Ideas from this paper
✗ Mechanism failed
2026
Add a bounded probing perturbation to the inputs or intermediate outputs of a neural sensor-fusion model, and choose the perturbation by maximizing separation between the predicted trusted-output set and output sets induced by candidate sensor attacks. Bounded feature and measurement uncertainty are propagated through local neural Jacobians as zonotopes, giving a conservative, geometry-based exposure objective rather than relying on random noise. Training can use the resulting margin as a…
Useful7/10
Difficulty6/10
Novelty7/10