Physical Attack on Monocular Depth Estimation with Optimal Adversarial Patches

被引:48
|
作者
Cheng, Zhiyuan [1 ]
Liang, James [2 ]
Choi, Hongjun [1 ]
Tao, Guanhong [1 ]
Cao, Zhiwen [1 ]
Liu, Dongfang [2 ]
Zhang, Xiangyu [1 ]
机构
[1] Purdue Univ, W Lafayette, IN 47907 USA
[2] Rochester Inst Technol, Rochester, NY 14623 USA
来源
关键词
Physical adversarial attack; Monocular depth estimation; Autonomous driving;
D O I
10.1007/978-3-031-19839-7_30
中图分类号
TP18 [人工智能理论];
学科分类号
081104 ; 0812 ; 0835 ; 1405 ;
摘要
Deep learning has substantially boosted the performance of Monocular Depth Estimation (MDE), a critical component in fully vision-based autonomous driving (AD) systems (e.g., Tesla and Toyota). In this work, we develop an attack against learning-based MDE. In particular, we use an optimization-based method to systematically generate stealthy physical-object-oriented adversarial patches to attack depth estimation. We balance the stealth and effectiveness of our attack with object-oriented adversarial design, sensitive region localization, and natural style camouflage. Using real-world driving scenarios, we evaluate our attack on concurrent MDE models and a representative downstream task for AD (i.e., 3D object detection). Experimental results show that our method can generate stealthy, effective, and robust adversarial patches for different target objects and models and achieves more than 6m mean depth estimation error and 93% attack success rate (ASR) in object detection with a patch of 1/9 of the vehicle's rear area. Field tests on three different driving routes with a real vehicle indicate that we cause over 6m mean depth estimation error and reduce the object detection rate from 90.70% to 5.16% in continuous video frames.
引用
收藏
页码:514 / 532
页数:19
相关论文
共 50 条
  • [1] Physical Adversarial Attack on Monocular Depth Estimation via Shape-Varying Patches
    Zhao, Chenxing
    Li, Yang
    Wu, Shihao
    Tan, Wenyi
    Zhou, Shuangju
    Pan, Quan
    IEEE SENSORS JOURNAL, 2024, 24 (22) : 38440 - 38452
  • [2] Projection-Based Physical Adversarial Attack for Monocular Depth Estimation
    Daimo, Renya
    Ono, Satoshi
    IEICE TRANSACTIONS ON INFORMATION AND SYSTEMS, 2023, E106D (01) : 31 - 35
  • [3] SAAM: Stealthy Adversarial Attack on Monocular Depth Estimation
    Guesmi, Amira
    Hanif, Muhammad Abdullah
    Ouni, Bassem
    Shafique, Muhammad
    IEEE ACCESS, 2024, 12 : 13571 - 13585
  • [4] On the benefit of adversarial training for monocular depth estimation
    Groenendijk, Rick
    Karaoglu, Sezer
    Gevers, Theo
    Mensink, Thomas
    COMPUTER VISION AND IMAGE UNDERSTANDING, 2020, 190
  • [5] Learning Regularizer for Monocular Depth Estimation with Adversarial Guidance
    Shen, Guibao
    Zhang, Yingkui
    Li, Jialu
    Wei, Mingqiang
    Wang, Qiong
    Chen, Guangyong
    Heng, Pheng-Ann
    PROCEEDINGS OF THE 29TH ACM INTERNATIONAL CONFERENCE ON MULTIMEDIA, MM 2021, 2021, : 5222 - 5230
  • [6] Structured Adversarial Training for Unsupervised Monocular Depth Estimation
    Mehta, Ishit
    Sakurikar, Parikshit
    Narayanan, P. J.
    2018 INTERNATIONAL CONFERENCE ON 3D VISION (3DV), 2018, : 314 - 323
  • [7] Semi-Supervised Adversarial Monocular Depth Estimation
    Ji, Rongrong
    Li, Ke
    Wang, Yan
    Sun, Xiaoshuai
    Guo, Feng
    Guo, Xiaowei
    Wu, Yongjian
    Huang, Feiyue
    Luo, Jiebo
    IEEE TRANSACTIONS ON PATTERN ANALYSIS AND MACHINE INTELLIGENCE, 2020, 42 (10) : 2410 - 2422
  • [8] Adversarial Patch Attacks on Monocular Depth Estimation Networks
    Yamanaka, Koichiro
    Matsumoto, Ryutaroh
    Takahashi, Keita
    Fujii, Toshiaki
    IEEE ACCESS, 2020, 8 : 179094 - 179104
  • [9] Self-Supervised Adversarial Training of Monocular Depth Estimation Against Physical-World Attacks
    Cheng, Zhiyuan
    Han, Cheng
    Liang, James
    Wang, Qifan
    Zhang, Xiangyu
    Liu, Dongfang
    IEEE TRANSACTIONS ON PATTERN ANALYSIS AND MACHINE INTELLIGENCE, 2024, 46 (12) : 9084 - 9101
  • [10] Adv-Depth: Self-Supervised Monocular Depth Estimation With an Adversarial Loss
    Li, Kunhong
    Fu, Zhiheng
    Wang, Hanyun
    Chen, Zonghao
    Guo, Yulan
    IEEE SIGNAL PROCESSING LETTERS, 2021, 28 : 638 - 642