Pixel-Optimization-Free Patch Attack on Stereo Depth Estimation

Fuente: arXiv
Saved in:
Bibliographic Details
Main Authors: Liu, Hangcheng, Kuang, Xu, Han, Xingshuo, Wu, Xingwan, Ou, Haoran, Guo, Shangwei, Huang, Xingyi, Xiang, Tao, Zhang, Tianwei
Format: Preprint
Published: 2025
Subjects:
Online Access:
Tags: Add Tag
No Tags, Be the first to tag this record!
_version_ 1866918131089276928
author Liu, Hangcheng
Kuang, Xu
Han, Xingshuo
Wu, Xingwan
Ou, Haoran
Guo, Shangwei
Huang, Xingyi
Xiang, Tao
Zhang, Tianwei
author_facet Liu, Hangcheng
Kuang, Xu
Han, Xingshuo
Wu, Xingwan
Ou, Haoran
Guo, Shangwei
Huang, Xingyi
Xiang, Tao
Zhang, Tianwei
contents Stereo Depth Estimation (SDE) is essential for scene perception in vision-based systems such as autonomous driving. Prior work shows SDE is vulnerable to pixel-optimization attacks, but these methods are limited to digital, static, and view-specific settings, making them impractical. This raises a central question: how to design deployable, adaptive, and transferable attacks under realistic constraints? We present two contributions to answer it. First, we build a unified framework that extends pixel-optimization attacks to four stereo-matching stages: feature extraction, cost-volume construction, cost aggregation, and disparity regression. Through systematic evaluation across nine SDE models with realistic constraints like photometric consistency, we show existing attacks suffer from poor transferability. Second, we propose PatchHunter, the first pixel-optimization-free attack. PatchHunter casts patch generation as a search in a structured space of visual patterns that disrupt core SDE assumptions, and uses a reinforcement learning policy to discover effective and transferable patterns efficiently. We evaluate PatchHunter on three levels: autonomous driving dataset, high-fidelity simulator, and real-world deployment. On KITTI, PatchHunter outperforms pixel-level attacks in both effectiveness and black-box transferability. Tests in CARLA and on vehicles with industrial-grade stereo cameras confirm robustness to physical variations. Even under challenging conditions such as low lighting, PatchHunter achieves a D1-all error above 0.4, while pixel-level attacks remain near 0.
format Preprint
id arxiv_https___arxiv_org_abs_2506_17632
institution arXiv
publishDate 2025
record_format arxiv
spellingShingle Pixel-Optimization-Free Patch Attack on Stereo Depth Estimation
Liu, Hangcheng
Kuang, Xu
Han, Xingshuo
Wu, Xingwan
Ou, Haoran
Guo, Shangwei
Huang, Xingyi
Xiang, Tao
Zhang, Tianwei
Computer Vision and Pattern Recognition
Stereo Depth Estimation (SDE) is essential for scene perception in vision-based systems such as autonomous driving. Prior work shows SDE is vulnerable to pixel-optimization attacks, but these methods are limited to digital, static, and view-specific settings, making them impractical. This raises a central question: how to design deployable, adaptive, and transferable attacks under realistic constraints? We present two contributions to answer it. First, we build a unified framework that extends pixel-optimization attacks to four stereo-matching stages: feature extraction, cost-volume construction, cost aggregation, and disparity regression. Through systematic evaluation across nine SDE models with realistic constraints like photometric consistency, we show existing attacks suffer from poor transferability. Second, we propose PatchHunter, the first pixel-optimization-free attack. PatchHunter casts patch generation as a search in a structured space of visual patterns that disrupt core SDE assumptions, and uses a reinforcement learning policy to discover effective and transferable patterns efficiently. We evaluate PatchHunter on three levels: autonomous driving dataset, high-fidelity simulator, and real-world deployment. On KITTI, PatchHunter outperforms pixel-level attacks in both effectiveness and black-box transferability. Tests in CARLA and on vehicles with industrial-grade stereo cameras confirm robustness to physical variations. Even under challenging conditions such as low lighting, PatchHunter achieves a D1-all error above 0.4, while pixel-level attacks remain near 0.
title Pixel-Optimization-Free Patch Attack on Stereo Depth Estimation
topic Computer Vision and Pattern Recognition
url https://arxiv.org/abs/2506.17632