Physical 3D Adversarial Attacks against Monocular Depth Estimation in Autonomous Driving
Junhao Zheng, Chenhao Lin, Jiahao Sun, Zhengyu Zhao, Qian Li, Chao Shen
Abstract
Deep learning-based monocular depth estimation (MDE), extensively applied in autonomous driving, is known to be vulnerable to adversarial attacks. Previous physical attacks against MDE models rely on 2D adversarial patches, so they only affect a small, localized region in the MDE map but fail under various viewpoints. To address these limitations, we propose 3D Depth Fool (3D<sup xmlns:mml="http://www.w3.org/1998/Math/MathML" xmlns:xlink="http://www.w3.org/1999/xlink">2</sup>Fool), the first 3D texture-based adversarial attack against MDE models. 3D<sup xmlns:mml="http://www.w3.org/1998/Math/MathML" xmlns:xlink="http://www.w3.org/1999/xlink">2</sup> Fool is specifically optimized to generate 3D adversarial textures agnostic to model types of vehicles and to have improved robustness in bad weather conditions, such as rain and fog. Experimental results validate the superior performance of our 3D<sup xmlns:mml="http://www.w3.org/1998/Math/MathML" xmlns:xlink="http://www.w3.org/1999/xlink">2</sup> Fool across various scenarios, including vehicles, MDE models, weather conditions, and viewpoints. Real-world experiments with printed 3D textures on physical vehicle models further demonstrate that our 3D<sup xmlns:mml="http://www.w3.org/1998/Math/MathML" xmlns:xlink="http://www.w3.org/1999/xlink">2</sup> Fool can cause an MDE error of over 10 meters. The code is available at https://github.com/GandolfczjhI3D2Fool.
Ask about this paper
Your agent reads all of it.
Lune indexed this paper to the last equation, along with the top-tier papers that cite it. Ask a question and the answer quotes them.
Cited by top-tier papers13
- Beware of Road Markings: A New Adversarial Patch Attack to Monocular Depth EstimationHangcheng Liu, Zhenhu Wu, Hao Wang, Xingshuo Han et al.NeurIPS 2024 · 13 citations
- D3: Training-Free AI-Generated Video Detection Using Second-Order FeaturesChende Zheng, Ruiqi Suo, Chenhao Lin, Zhengyu Zhao et al.ICCV 2025 · 11 citations
- Enhancing the Adversarial Robustness via Manifold ProjectionZhiting Li, Shibai Yin, Tai-Xiang Jiang, Yexun Hu et al.AAAI 2025 · 5 citations
- Revisiting Adversarial Patch Defenses on Object Detectors: Unified Evaluation, Large-Scale Dataset, and New InsightsJunhao Zheng, Jiahao Sun, Chenhao Lin, Zhengyu Zhao et al.ICCV 2025 · 4 citations
- Thermally Activated Dual-Modal Adversarial Clothing against AI Surveillance SystemsJiahuan Long, Tingsong Jiang, Hanqing Liu, Chao Ma et al.CVPR 2026 · 3 citations
Builds on14
- Towards Evaluating the Robustness of Neural NetworksNicholas Carlini, David A. WagnerS&P 2017 · 9,786 citations
- Accessorize to a Crime: Real and Stealthy Attacks on State-of-the-Art Face RecognitionMahmood Sharif, Sruti Bhagavatula, Lujo Bauer, Michael K. ReiterCCS 2016 · 1,765 citations
- Self-Supervised Monocular Depth HintsJamie Watson, Michael Firman, Gabriel J. Brostow, Daniyar TurmukhambetovICCV 2019 · 287 citations
- On Success and Simplicity: A Second Look at Transferable Targeted AttacksZhengyu Zhao, Zhuoran Liu, Martha A. LarsonNeurIPS 2021 · 173 citations
- FCA: Learning a 3D Full-Coverage Vehicle Camouflage for Multi-View Physical Adversarial AttackDonghua Wang, Tingsong Jiang, Jialiang Sun, Weien Zhou et al.AAAI 2022 · 149 citations
Related papers
- Cheating Stereo Matching in Full-Scale: Physical Adversarial Attack Against Binocular Depth Estimation in Autonomous DrivingKangqiao Zhao, Shuo Huai, Xurui Song, Jun LuoAAAI 2026
- DepthCloak: Projecting Optical Camouflage Patches for Erroneous Monocular Depth Estimation of VehiclesHuixiang Wen, Shizong Yan, Shan Chang, Jie Xu et al.ACM MM 2024 · 2 citations
- pi-Jack: Physical-World Adversarial Attack on Monocular Depth Estimation with Perspective HijackingTianyue Zheng, Jingzhi Hu, Rui Tan, Yinqian Zhang et al.USENIX Security 2024 · 8 citations
- Adversarial Training of Self-supervised Monocular Depth Estimation against Physical-World AttacksZhiyuan Cheng, James Liang, Guanhong Tao, Dongfang Liu et al.ICLR 2023 · 6 citations
- Physically Realizable Adversarial Examples for LiDAR Object DetectionJames Tu, Mengye Ren, Sivabalan Manivasagam, Ming Liang et al.CVPR 2020
