Self-supervised Adversarial Training of Monocular Depth Estimation against Physical-World Attacks

Fuente: arXiv
Gespeichert in:
Bibliographische Detailangaben
Hauptverfasser: Cheng, Zhiyuan, Han, Cheng, Liang, James, Wang, Qifan, Zhang, Xiangyu, Liu, Dongfang
Format: Preprint
Veröffentlicht: 2024
Schlagworte:
Online-Zugang:
Tags: Tag hinzufügen
Keine Tags, Fügen Sie den ersten Tag hinzu!
_version_ 1866911925795815424
author Cheng, Zhiyuan
Han, Cheng
Liang, James
Wang, Qifan
Zhang, Xiangyu
Liu, Dongfang
author_facet Cheng, Zhiyuan
Han, Cheng
Liang, James
Wang, Qifan
Zhang, Xiangyu
Liu, Dongfang
contents Monocular Depth Estimation (MDE) plays a vital role in applications such as autonomous driving. However, various attacks target MDE models, with physical attacks posing significant threats to system security. Traditional adversarial training methods, which require ground-truth labels, are not directly applicable to MDE models that lack ground-truth depth. Some self-supervised model hardening techniques (e.g., contrastive learning) overlook the domain knowledge of MDE, resulting in suboptimal performance. In this work, we introduce a novel self-supervised adversarial training approach for MDE models, leveraging view synthesis without the need for ground-truth depth. We enhance adversarial robustness against real-world attacks by incorporating L_0-norm-bounded perturbation during training. We evaluate our method against supervised learning-based and contrastive learning-based approaches specifically designed for MDE. Our experiments with two representative MDE networks demonstrate improved robustness against various adversarial attacks, with minimal impact on benign performance.
format Preprint
id arxiv_https___arxiv_org_abs_2406_05857
institution arXiv
publishDate 2024
record_format arxiv
spellingShingle Self-supervised Adversarial Training of Monocular Depth Estimation against Physical-World Attacks
Cheng, Zhiyuan
Han, Cheng
Liang, James
Wang, Qifan
Zhang, Xiangyu
Liu, Dongfang
Computer Vision and Pattern Recognition
Monocular Depth Estimation (MDE) plays a vital role in applications such as autonomous driving. However, various attacks target MDE models, with physical attacks posing significant threats to system security. Traditional adversarial training methods, which require ground-truth labels, are not directly applicable to MDE models that lack ground-truth depth. Some self-supervised model hardening techniques (e.g., contrastive learning) overlook the domain knowledge of MDE, resulting in suboptimal performance. In this work, we introduce a novel self-supervised adversarial training approach for MDE models, leveraging view synthesis without the need for ground-truth depth. We enhance adversarial robustness against real-world attacks by incorporating L_0-norm-bounded perturbation during training. We evaluate our method against supervised learning-based and contrastive learning-based approaches specifically designed for MDE. Our experiments with two representative MDE networks demonstrate improved robustness against various adversarial attacks, with minimal impact on benign performance.
title Self-supervised Adversarial Training of Monocular Depth Estimation against Physical-World Attacks
topic Computer Vision and Pattern Recognition
url https://arxiv.org/abs/2406.05857