TY - JOUR
T1 - Physical Adversarial Attack on Monocular Depth Estimation via Shape-Varying Patches
AU - Zhao, Chenxing
AU - Li, Yang
AU - Wu, Shihao
AU - Tan, Wenyi
AU - Zhou, Shuangju
AU - Pan, Quan
N1 - Publisher Copyright:
© 2001-2012 IEEE.
PY - 2024
Y1 - 2024
N2 - Adversarial attacks against monocular depth estimation (MDE) systems, which serve as critical visual sensors in autonomous driving and various safety-critical applications, pose significant challenges. These depth cameras provide essential distance information, enabling accurate perception and decision-making. Existing patch-based adversarial attacks for MDE are confined to the vicinity of the patch, limiting their impact on the entire target. To address this limitation, we propose a physics-based adversarial attack on MDE using a framework called an attack with shape-varying patches (ASP). This framework optimizes the content, shape, and position of patches to maximize its disruptive effectiveness on the sensor's output. We introduce various mask shapes, including quadrilateral, rectangular, and circular masks, to enhance the flexibility and efficiency of the attack. In addition, we propose a new loss function to extend the influence of patches beyond the overlapping regions. Experimental results demonstrate that our attack method generates an average depth error of 18 m on the target car with a patch area of 1/9, impacting over 98% of the target area. This work underscores the vulnerability of visual sensors, such as depth cameras, to adversarial attacks and highlights the imperative for enhanced security measures in sensor technology to ensure reliable and safe operation.
AB - Adversarial attacks against monocular depth estimation (MDE) systems, which serve as critical visual sensors in autonomous driving and various safety-critical applications, pose significant challenges. These depth cameras provide essential distance information, enabling accurate perception and decision-making. Existing patch-based adversarial attacks for MDE are confined to the vicinity of the patch, limiting their impact on the entire target. To address this limitation, we propose a physics-based adversarial attack on MDE using a framework called an attack with shape-varying patches (ASP). This framework optimizes the content, shape, and position of patches to maximize its disruptive effectiveness on the sensor's output. We introduce various mask shapes, including quadrilateral, rectangular, and circular masks, to enhance the flexibility and efficiency of the attack. In addition, we propose a new loss function to extend the influence of patches beyond the overlapping regions. Experimental results demonstrate that our attack method generates an average depth error of 18 m on the target car with a patch area of 1/9, impacting over 98% of the target area. This work underscores the vulnerability of visual sensors, such as depth cameras, to adversarial attacks and highlights the imperative for enhanced security measures in sensor technology to ensure reliable and safe operation.
KW - Adversarial patch
KW - depth sensor robustness
KW - monocular depth estimation (MDE)
KW - sensor adversarial attack
KW - sensor data security
KW - visual sensors
UR - http://www.scopus.com/inward/record.url?scp=85207156480&partnerID=8YFLogxK
U2 - 10.1109/JSEN.2024.3472032
DO - 10.1109/JSEN.2024.3472032
M3 - 文章
AN - SCOPUS:85207156480
SN - 1530-437X
VL - 24
SP - 38440
EP - 38452
JO - IEEE Sensors Journal
JF - IEEE Sensors Journal
IS - 22
ER -