DoubleStar: Long-Range Attack Towards Depth Estimation based Obstacle Avoidance in Autonomous Systems
Ce Zhou, Qiben Yan, Yan Shi, Lichao Sun
摘要
Depth estimation-based obstacle avoidance has been widely adopted by autonomous systems (drones and vehicles) for safety purpose. It normally relies on a stereo camera to automatically detect obstacles and make flying/driving decisions, e.g., stopping several meters ahead of the obstacle in the path or moving away from the detected obstacle. In this paper, we explore new security risks associated with the stereo vision-based depth estimation algorithms used for obstacle avoidance. By exploiting the weaknesses of the stereo matching in depth estimation algorithms and the lens flare effect in optical imaging, we propose DoubleStar, a long-range attack that injects fake obstacle depth by projecting pure light from two complementary light sources. DoubleStar includes two distinctive attack formats: beams attack and orbs attack, which leverage projected light beams and lens flare orbs respectively to cause false depth perception. We successfully attack two commercial stereo cameras designed for autonomous systems (ZED and Intel RealSense). The visualization of fake depth perceived by the stereo cameras illustrates the false stereo matching induced by DoubleStar. We further use Ardupilot to simulate the attack and demonstrate its impact on drones. To validate the attack on real systems, we perform a real-world attack towards a commercial drone equipped with state-of-the-art obstacle avoidance algorithms. Our attack can continuously bring a flying drone to a sudden stop or drift it away across a long distance under various lighting conditions, even bypassing sensor fusion mechanisms. Specifically, our experimental results show that DoubleStar creates fake depth up to 15 meters in distance at night and up to 8 meters during the daytime. To mitigate this newly discovered threat, we provide discussions on potential countermeasures to defend against DoubleStar.
问问这篇 Paper
智能体会读完全文。
Lune 把这篇 Paper 索引到了每一个公式,引用它的顶会 Paper 也一样。你提问,回答直接引用原文。
引用它的顶会 Paper9
- Physical Backdoor: Towards Temperature-Based Backdoor Attacks in the Physical WorldWen Yin, Jian Lou, Pan Zhou, Yulai Xie 等CVPR 2024 · 被引用 9 次
- pi-Jack: Physical-World Adversarial Attack on Monocular Depth Estimation with Perspective HijackingTianyue Zheng, Jingzhi Hu, Rui Tan, Yinqian Zhang 等USENIX Security 2024 · 被引用 8 次
- FlyTrap: Physical Distance-Pulling Attack Towards Camera-based Autonomous Target Tracking SystemsShaoyuan Xie, Mohamad Habib Fakih, Junchi Lu, Fayzah Alshammari 等NDSS 2026 · 被引用 5 次
- PhyScout: Detecting Sensor Spoofing Attacks via Spatio-temporal ConsistencyYuan Xu, Gelei Deng, Xingshuo Han, Guanlin Li 等CCS 2024 · 被引用 2 次
- The Heat is On: Understanding and Mitigating Vulnerabilities of Thermal Image Perception in Autonomous SystemsSri Hrushikesh Varma Bhupathiraju, Shaoyuan Xie, Michael Clifford, Qi Alfred Chen 等NDSS 2026 · 被引用 1 次
它引用的顶会 Paper10
- Distillation as a Defense to Adversarial Perturbations Against Deep Neural NetworksNicolas Papernot, Patrick D. McDaniel, Xi Wu, Somesh Jha 等S&P 2016 · 被引用 3,275 次
- Certified Robustness to Adversarial Examples with Differential PrivacyMathias Lécuyer, Vaggelis Atlidakis, Roxana Geambasu, Daniel Hsu 等S&P 2019 · 被引用 1,022 次
- Adversarial Sensor Attack on LiDAR-based Perception in Autonomous DrivingYulong Cao, Chaowei Xiao, Benjamin Cyr, Yimeng Zhou 等CCS 2019 · 被引用 626 次
- Dirty Road Can Attack: Security of Deep Learning based Automated Lane Centering under Physical-World AttackTakami Sato, Junjie Shen, Ningfei Wang, Yunhan Jia 等USENIX Security 2021 · 被引用 152 次
- Defending Against Physically Realizable Attacks on Image ClassificationTong Wu, Liang Tong, Yevgeniy VorobeychikICLR 2020 · 被引用 143 次
相关 Paper
- DepthVanish: Optimizing Adversarial Interval Structures for Stereo-Depth-Invisible PatchesYun Xing, Yue Cao, Nhat Chung, Jie M. Zhang 等NeurIPS 2025
- Invisible for both Camera and LiDAR: Security of Multi-Sensor Fusion based Perception in Autonomous Driving Under Physical-World AttacksYulong Cao, Ningfei Wang, Chaowei Xiao, Dawei Yang 等S&P 2021 · 被引用 309 次
- Cheating Stereo Matching in Full-Scale: Physical Adversarial Attack Against Binocular Depth Estimation in Autonomous DrivingKangqiao Zhao, Shuo Huai, Xurui Song, Jun LuoAAAI 2026
- Can We Use Arbitrary Objects to Attack LiDAR Perception in Autonomous Driving?Yi Zhu, Chenglin Miao, Tianhang Zheng, Foad Hajiaghajani 等CCS 2021 · 被引用 65 次
- Investigating Physical Latency Attacks Against Camera-Based PerceptionRaymond Muller, Ruoyu Song, Chenyi Wang, Yuxia Zhan 等S&P 2025
