Physical Adversarial Attack on Monocular Depth Estimation via Shape-Varying Patches

Chenxing Zhao, Yang Li, Shihao Wu, Wenyi Tan, Shuangju Zhou, Quan Pan

科研成果: 期刊稿件文章同行评审

1 引用 (Scopus)

摘要

Adversarial attacks against monocular depth estimation (MDE) systems, which serve as critical visual sensors in autonomous driving and various safety-critical applications, pose significant challenges. These depth cameras provide essential distance information, enabling accurate perception and decision-making. Existing patch-based adversarial attacks for MDE are confined to the vicinity of the patch, limiting their impact on the entire target. To address this limitation, we propose a physics-based adversarial attack on MDE using a framework called an attack with shape-varying patches (ASP). This framework optimizes the content, shape, and position of patches to maximize its disruptive effectiveness on the sensor's output. We introduce various mask shapes, including quadrilateral, rectangular, and circular masks, to enhance the flexibility and efficiency of the attack. In addition, we propose a new loss function to extend the influence of patches beyond the overlapping regions. Experimental results demonstrate that our attack method generates an average depth error of 18 m on the target car with a patch area of 1/9, impacting over 98% of the target area. This work underscores the vulnerability of visual sensors, such as depth cameras, to adversarial attacks and highlights the imperative for enhanced security measures in sensor technology to ensure reliable and safe operation.

源语言英语
页(从-至)38440-38452
页数13
期刊IEEE Sensors Journal
24
22
DOI
出版状态已出版 - 2024

指纹

探究 'Physical Adversarial Attack on Monocular Depth Estimation via Shape-Varying Patches' 的科研主题。它们共同构成独一无二的指纹。

引用此