Physical Adversarial Attack on Monocular Depth Estimation via Shape-Varying Patches

Fuente: arXiv
Saved in:
Bibliographic Details
Main Authors: Zhao, Chenxing, Li, Yang, Wu, Shihao, Tan, Wenyi, Zhou, Shuangju, Pan, Quan
Format: Preprint
Published: 2024
Subjects:
Online Access:
Tags: Add Tag
No Tags, Be the first to tag this record!
_version_ 1866917731960356864
author Zhao, Chenxing
Li, Yang
Wu, Shihao
Tan, Wenyi
Zhou, Shuangju
Pan, Quan
author_facet Zhao, Chenxing
Li, Yang
Wu, Shihao
Tan, Wenyi
Zhou, Shuangju
Pan, Quan
contents Adversarial attacks against monocular depth estimation (MDE) systems pose significant challenges, particularly in safety-critical applications such as autonomous driving. Existing patch-based adversarial attacks for MDE are confined to the vicinity of the patch, making it difficult to affect the entire target. To address this limitation, we propose a physics-based adversarial attack on monocular depth estimation, employing a framework called Attack with Shape-Varying Patches (ASP), aiming to optimize patch content, shape, and position to maximize effectiveness. We introduce various mask shapes, including quadrilateral, rectangular, and circular masks, to enhance the flexibility and efficiency of the attack. Furthermore, we propose a new loss function to extend the influence of the patch beyond the overlapping regions. Experimental results demonstrate that our attack method generates an average depth error of 18 meters on the target car with a patch area of 1/9, affecting over 98\% of the target area.
format Preprint
id arxiv_https___arxiv_org_abs_2407_17312
institution arXiv
publishDate 2024
record_format arxiv
spellingShingle Physical Adversarial Attack on Monocular Depth Estimation via Shape-Varying Patches
Zhao, Chenxing
Li, Yang
Wu, Shihao
Tan, Wenyi
Zhou, Shuangju
Pan, Quan
Computer Vision and Pattern Recognition
Adversarial attacks against monocular depth estimation (MDE) systems pose significant challenges, particularly in safety-critical applications such as autonomous driving. Existing patch-based adversarial attacks for MDE are confined to the vicinity of the patch, making it difficult to affect the entire target. To address this limitation, we propose a physics-based adversarial attack on monocular depth estimation, employing a framework called Attack with Shape-Varying Patches (ASP), aiming to optimize patch content, shape, and position to maximize effectiveness. We introduce various mask shapes, including quadrilateral, rectangular, and circular masks, to enhance the flexibility and efficiency of the attack. Furthermore, we propose a new loss function to extend the influence of the patch beyond the overlapping regions. Experimental results demonstrate that our attack method generates an average depth error of 18 meters on the target car with a patch area of 1/9, affecting over 98\% of the target area.
title Physical Adversarial Attack on Monocular Depth Estimation via Shape-Varying Patches
topic Computer Vision and Pattern Recognition
url https://arxiv.org/abs/2407.17312