Self-supervised Adversarial Training of Monocular Depth Estimation against Physical-World Attacks
Fuente:
arXiv
Gespeichert in:
| Hauptverfasser: | , , , , , |
|---|---|
| Format: | Preprint |
| Veröffentlicht: |
2024
|
| Schlagworte: | |
| Online-Zugang: | |
| Tags: |
Tag hinzufügen
Keine Tags, Fügen Sie den ersten Tag hinzu!
|
| _version_ | 1866911925795815424 |
|---|---|
| author | Cheng, Zhiyuan Han, Cheng Liang, James Wang, Qifan Zhang, Xiangyu Liu, Dongfang |
| author_facet | Cheng, Zhiyuan Han, Cheng Liang, James Wang, Qifan Zhang, Xiangyu Liu, Dongfang |
| contents | Monocular Depth Estimation (MDE) plays a vital role in applications such as autonomous driving. However, various attacks target MDE models, with physical attacks posing significant threats to system security. Traditional adversarial training methods, which require ground-truth labels, are not directly applicable to MDE models that lack ground-truth depth. Some self-supervised model hardening techniques (e.g., contrastive learning) overlook the domain knowledge of MDE, resulting in suboptimal performance. In this work, we introduce a novel self-supervised adversarial training approach for MDE models, leveraging view synthesis without the need for ground-truth depth. We enhance adversarial robustness against real-world attacks by incorporating L_0-norm-bounded perturbation during training. We evaluate our method against supervised learning-based and contrastive learning-based approaches specifically designed for MDE. Our experiments with two representative MDE networks demonstrate improved robustness against various adversarial attacks, with minimal impact on benign performance. |
| format | Preprint |
| id |
arxiv_https___arxiv_org_abs_2406_05857 |
| institution | arXiv |
| publishDate | 2024 |
| record_format | arxiv |
| spellingShingle | Self-supervised Adversarial Training of Monocular Depth Estimation against Physical-World Attacks Cheng, Zhiyuan Han, Cheng Liang, James Wang, Qifan Zhang, Xiangyu Liu, Dongfang Computer Vision and Pattern Recognition Monocular Depth Estimation (MDE) plays a vital role in applications such as autonomous driving. However, various attacks target MDE models, with physical attacks posing significant threats to system security. Traditional adversarial training methods, which require ground-truth labels, are not directly applicable to MDE models that lack ground-truth depth. Some self-supervised model hardening techniques (e.g., contrastive learning) overlook the domain knowledge of MDE, resulting in suboptimal performance. In this work, we introduce a novel self-supervised adversarial training approach for MDE models, leveraging view synthesis without the need for ground-truth depth. We enhance adversarial robustness against real-world attacks by incorporating L_0-norm-bounded perturbation during training. We evaluate our method against supervised learning-based and contrastive learning-based approaches specifically designed for MDE. Our experiments with two representative MDE networks demonstrate improved robustness against various adversarial attacks, with minimal impact on benign performance. |
| title | Self-supervised Adversarial Training of Monocular Depth Estimation against Physical-World Attacks |
| topic | Computer Vision and Pattern Recognition |
| url | https://arxiv.org/abs/2406.05857 |