Stereoscopic Universal Perturbations across Different Architectures and Datasets
Zachary Berger, Parth Agrawal, Tian Yu Liu, Stefano Soatto, Alex Wong
摘要
We study the effect of adversarial perturbations of images on deep stereo matching networks for the disparity estimation task. We present a method to craft a single set of perturbations that, when added to any stereo image pair in a dataset, can fool a stereo network to significantly alter the perceived scene geometry. Our perturbation images are “universal” in that they not only corrupt estimates of the network on the dataset they are optimized for, but also generalize to different architectures trained on different datasets. We evaluate our approach on multiple benchmark datasets where our perturbations can increase the D1-error (akin to fooling rate) of state-of-the-art stereo networks from 1% to as much as 87%. We investigate the effect of perturbations on the estimated scene geometry and identify object classes that are most vulnerable. Our analysis on the activations of registered points between left and right images led us to find architectural components that can increase robustness against adversaries. By simply designing networks with such components, one can reduce the effect of adversaries by up to 60.5%, which rivals the robustness of networks finetuned with costly adversarial data augmentation. Our design principle also improves their robustness against common image corruptions by an average of 70%.
问问这篇 Paper
智能体会读完全文。
Lune 把这篇 Paper 索引到了每一个公式,引用它的顶会 Paper 也一样。你提问,回答直接引用原文。
引用它的顶会 Paper9
- Enhancing Generalization of Universal Adversarial Perturbation through Gradient AggregationXuannan Liu, Yaoyao Zhong, Yuhang Zhang, Lixiong Qin 等ICCV 2023 · 被引用 42 次
- Friendly Noise against Adversarial Noise: A Powerful Defense against Data Poisoning AttackTian Yu Liu, Yu Yang, Baharan MirzasoleimanNeurIPS 2022 · 被引用 39 次
- Distracting Downpour: Adversarial Weather Attacks for Motion EstimationJenny Schmalfuss, Lukas Mehl, Andrés BruhnICCV 2023 · 被引用 23 次
- RobustSpring: Benchmarking Robustness to Image Corruptions for Optical Flow, Scene Flow and StereoVictor Oei, Jenny Schmalfuss, Lukas Mehl, Madlen Bartsch 等ICLR 2026 · 被引用 9 次
- Extending Foundational Monocular Depth Estimators to Fisheye Cameras with Calibration TokensSuchisrit Gangopadhyay, Jung Hee Kim, Xien Chen, Patrick Rim 等ICCV 2025 · 被引用 2 次
它引用的顶会 Paper13
- How Do Neural Networks See Depth in Single Images?Tom van Dijk, Guido de CroonICCV 2019 · 被引用 210 次
- Universal Adversarial TrainingAli Shafahi, Mahyar Najibi, Zheng Xu, John P. Dickerson 等AAAI 2020 · 被引用 210 次
- Mixup Inference: Better Exploiting Mixup to Defend Adversarial AttacksTianyu Pang, Kun Xu, Jun ZhuICLR 2020 · 被引用 114 次
- Enhancing Adversarial Defense by k-Winners-Take-AllChang Xiao, Peilin Zhong, Changxi ZhengICLR 2020 · 被引用 114 次
- Attacking Optical FlowAnurag Ranjan, Joel Janai, Andreas Geiger, Michael J. BlackICCV 2019 · 被引用 93 次
相关 Paper
- Stereopagnosia: Fooling Stereo Networks with Adversarial PerturbationsAlex Wong, Mukund Mundhra, Stefano SoattoAAAI 2021 · 被引用 33 次
- Targeted Adversarial Perturbations for Monocular Depth PredictionAlex Wong, Safa Cicek, Stefano SoattoNeurIPS 2020 · 被引用 61 次
- Revisiting Non-Parametric Matching Cost Volumes for Robust and Generalizable Stereo MatchingKelvin Cheng, Tianfu Wu, Christopher G. HealeyNeurIPS 2022 · 被引用 5 次
- DepthVanish: Optimizing Adversarial Interval Structures for Stereo-Depth-Invisible PatchesYun Xing, Yue Cao, Nhat Chung, Jie M. Zhang 等NeurIPS 2025
- Defending Against Universal Perturbations With Shared Adversarial TrainingChaithanya Kumar Mummadi, Thomas Brox, Jan Hendrik MetzenICCV 2019 · 被引用 61 次
