Physical 3D Adversarial Attacks against Monocular Depth Estimation in Autonomous Driving

Fuente: arXiv
Saved in:
Bibliographic Details
Main Authors: Zheng, Junhao, Lin, Chenhao, Sun, Jiahao, Zhao, Zhengyu, Li, Qian, Shen, Chao
Format: Preprint
Published: 2024
Subjects:
Online Access:
Tags: Add Tag
No Tags, Be the first to tag this record!
_version_ 1866914730127392768
author Zheng, Junhao
Lin, Chenhao
Sun, Jiahao
Zhao, Zhengyu
Li, Qian
Shen, Chao
author_facet Zheng, Junhao
Lin, Chenhao
Sun, Jiahao
Zhao, Zhengyu
Li, Qian
Shen, Chao
contents Deep learning-based monocular depth estimation (MDE), extensively applied in autonomous driving, is known to be vulnerable to adversarial attacks. Previous physical attacks against MDE models rely on 2D adversarial patches, so they only affect a small, localized region in the MDE map but fail under various viewpoints. To address these limitations, we propose 3D Depth Fool (3D$^2$Fool), the first 3D texture-based adversarial attack against MDE models. 3D$^2$Fool is specifically optimized to generate 3D adversarial textures agnostic to model types of vehicles and to have improved robustness in bad weather conditions, such as rain and fog. Experimental results validate the superior performance of our 3D$^2$Fool across various scenarios, including vehicles, MDE models, weather conditions, and viewpoints. Real-world experiments with printed 3D textures on physical vehicle models further demonstrate that our 3D$^2$Fool can cause an MDE error of over 10 meters.
format Preprint
id arxiv_https___arxiv_org_abs_2403_17301
institution arXiv
publishDate 2024
record_format arxiv
spellingShingle Physical 3D Adversarial Attacks against Monocular Depth Estimation in Autonomous Driving
Zheng, Junhao
Lin, Chenhao
Sun, Jiahao
Zhao, Zhengyu
Li, Qian
Shen, Chao
Computer Vision and Pattern Recognition
Cryptography and Security
Deep learning-based monocular depth estimation (MDE), extensively applied in autonomous driving, is known to be vulnerable to adversarial attacks. Previous physical attacks against MDE models rely on 2D adversarial patches, so they only affect a small, localized region in the MDE map but fail under various viewpoints. To address these limitations, we propose 3D Depth Fool (3D$^2$Fool), the first 3D texture-based adversarial attack against MDE models. 3D$^2$Fool is specifically optimized to generate 3D adversarial textures agnostic to model types of vehicles and to have improved robustness in bad weather conditions, such as rain and fog. Experimental results validate the superior performance of our 3D$^2$Fool across various scenarios, including vehicles, MDE models, weather conditions, and viewpoints. Real-world experiments with printed 3D textures on physical vehicle models further demonstrate that our 3D$^2$Fool can cause an MDE error of over 10 meters.
title Physical 3D Adversarial Attacks against Monocular Depth Estimation in Autonomous Driving
topic Computer Vision and Pattern Recognition
Cryptography and Security
url https://arxiv.org/abs/2403.17301