Stereoscopic Universal Perturbations across Different Architectures and Datasets
Zachary Berger, Parth Agrawal, Tian Yu Liu, Stefano Soatto, Alex Wong
Abstract
We study the effect of adversarial perturbations of images on deep stereo matching networks for the disparity estimation task. We present a method to craft a single set of perturbations that, when added to any stereo image pair in a dataset, can fool a stereo network to significantly alter the perceived scene geometry. Our perturbation images are “universal” in that they not only corrupt estimates of the network on the dataset they are optimized for, but also generalize to different architectures trained on different datasets. We evaluate our approach on multiple benchmark datasets where our perturbations can increase the D1-error (akin to fooling rate) of state-of-the-art stereo networks from 1% to as much as 87%. We investigate the effect of perturbations on the estimated scene geometry and identify object classes that are most vulnerable. Our analysis on the activations of registered points between left and right images led us to find architectural components that can increase robustness against adversaries. By simply designing networks with such components, one can reduce the effect of adversaries by up to 60.5%, which rivals the robustness of networks finetuned with costly adversarial data augmentation. Our design principle also improves their robustness against common image corruptions by an average of 70%.
Ask about this paper
Your agent reads all of it.
Lune indexed this paper to the last equation, along with the top-tier papers that cite it. Ask a question and the answer quotes them.
Your agent calls
Luneget_paper_fulltext
Free to start. No credit card required.
Terminal
Install the CLIlune papers fulltext 3fee8e52-c2e6-4d85-9640-ce9e84c051b0Cited by top-tier papers9
- Enhancing Generalization of Universal Adversarial Perturbation through Gradient AggregationXuannan Liu, Yaoyao Zhong, Yuhang Zhang, Lixiong Qin et al.ICCV 2023 · 42 citations
- Friendly Noise against Adversarial Noise: A Powerful Defense against Data Poisoning AttackTian Yu Liu, Yu Yang, Baharan MirzasoleimanNeurIPS 2022 · 39 citations
- Distracting Downpour: Adversarial Weather Attacks for Motion EstimationJenny Schmalfuss, Lukas Mehl, Andrés BruhnICCV 2023 · 23 citations
- RobustSpring: Benchmarking Robustness to Image Corruptions for Optical Flow, Scene Flow and StereoVictor Oei, Jenny Schmalfuss, Lukas Mehl, Madlen Bartsch et al.ICLR 2026 · 9 citations
- Extending Foundational Monocular Depth Estimators to Fisheye Cameras with Calibration TokensSuchisrit Gangopadhyay, Jung Hee Kim, Xien Chen, Patrick Rim et al.ICCV 2025 · 2 citations
Builds on13
- How Do Neural Networks See Depth in Single Images?Tom van Dijk, Guido de CroonICCV 2019 · 210 citations
- Universal Adversarial TrainingAli Shafahi, Mahyar Najibi, Zheng Xu, John P. Dickerson et al.AAAI 2020 · 210 citations
- Mixup Inference: Better Exploiting Mixup to Defend Adversarial AttacksTianyu Pang, Kun Xu, Jun ZhuICLR 2020 · 114 citations
- Enhancing Adversarial Defense by k-Winners-Take-AllChang Xiao, Peilin Zhong, Changxi ZhengICLR 2020 · 114 citations
- Attacking Optical FlowAnurag Ranjan, Joel Janai, Andreas Geiger, Michael J. BlackICCV 2019 · 93 citations
Related papers
- Stereopagnosia: Fooling Stereo Networks with Adversarial PerturbationsAlex Wong, Mukund Mundhra, Stefano SoattoAAAI 2021 · 33 citations
- Targeted Adversarial Perturbations for Monocular Depth PredictionAlex Wong, Safa Cicek, Stefano SoattoNeurIPS 2020 · 61 citations
- Revisiting Non-Parametric Matching Cost Volumes for Robust and Generalizable Stereo MatchingKelvin Cheng, Tianfu Wu, Christopher G. HealeyNeurIPS 2022 · 5 citations
- DepthVanish: Optimizing Adversarial Interval Structures for Stereo-Depth-Invisible PatchesYun Xing, Yue Cao, Nhat Chung, Jie M. Zhang et al.NeurIPS 2025
- Defending Against Universal Perturbations With Shared Adversarial TrainingChaithanya Kumar Mummadi, Thomas Brox, Jan Hendrik MetzenICCV 2019 · 61 citations
