Physical 3D Adversarial Attacks against Monocular Depth Estimation in Autonomous Driving
Junhao Zheng, Chenhao Lin, Jiahao Sun, Zhengyu Zhao, Qian Li, Chao Shen
摘要
Deep learning-based monocular depth estimation (MDE), extensively applied in autonomous driving, is known to be vulnerable to adversarial attacks. Previous physical attacks against MDE models rely on 2D adversarial patches, so they only affect a small, localized region in the MDE map but fail under various viewpoints. To address these limitations, we propose 3D Depth Fool (3D<sup xmlns:mml="http://www.w3.org/1998/Math/MathML" xmlns:xlink="http://www.w3.org/1999/xlink">2</sup>Fool), the first 3D texture-based adversarial attack against MDE models. 3D<sup xmlns:mml="http://www.w3.org/1998/Math/MathML" xmlns:xlink="http://www.w3.org/1999/xlink">2</sup> Fool is specifically optimized to generate 3D adversarial textures agnostic to model types of vehicles and to have improved robustness in bad weather conditions, such as rain and fog. Experimental results validate the superior performance of our 3D<sup xmlns:mml="http://www.w3.org/1998/Math/MathML" xmlns:xlink="http://www.w3.org/1999/xlink">2</sup> Fool across various scenarios, including vehicles, MDE models, weather conditions, and viewpoints. Real-world experiments with printed 3D textures on physical vehicle models further demonstrate that our 3D<sup xmlns:mml="http://www.w3.org/1998/Math/MathML" xmlns:xlink="http://www.w3.org/1999/xlink">2</sup> Fool can cause an MDE error of over 10 meters. The code is available at https://github.com/GandolfczjhI3D2Fool.
问问这篇 Paper
智能体会读完全文。
Lune 把这篇 Paper 索引到了每一个公式,引用它的顶会 Paper 也一样。你提问,回答直接引用原文。
引用它的顶会 Paper13
- Beware of Road Markings: A New Adversarial Patch Attack to Monocular Depth EstimationHangcheng Liu, Zhenhu Wu, Hao Wang, Xingshuo Han 等NeurIPS 2024 · 被引用 13 次
- D3: Training-Free AI-Generated Video Detection Using Second-Order FeaturesChende Zheng, Ruiqi Suo, Chenhao Lin, Zhengyu Zhao 等ICCV 2025 · 被引用 11 次
- Enhancing the Adversarial Robustness via Manifold ProjectionZhiting Li, Shibai Yin, Tai-Xiang Jiang, Yexun Hu 等AAAI 2025 · 被引用 5 次
- Revisiting Adversarial Patch Defenses on Object Detectors: Unified Evaluation, Large-Scale Dataset, and New InsightsJunhao Zheng, Jiahao Sun, Chenhao Lin, Zhengyu Zhao 等ICCV 2025 · 被引用 4 次
- Thermally Activated Dual-Modal Adversarial Clothing against AI Surveillance SystemsJiahuan Long, Tingsong Jiang, Hanqing Liu, Chao Ma 等CVPR 2026 · 被引用 3 次
它引用的顶会 Paper14
- Towards Evaluating the Robustness of Neural NetworksNicholas Carlini, David A. WagnerS&P 2017 · 被引用 9,786 次
- Accessorize to a Crime: Real and Stealthy Attacks on State-of-the-Art Face RecognitionMahmood Sharif, Sruti Bhagavatula, Lujo Bauer, Michael K. ReiterCCS 2016 · 被引用 1,765 次
- Self-Supervised Monocular Depth HintsJamie Watson, Michael Firman, Gabriel J. Brostow, Daniyar TurmukhambetovICCV 2019 · 被引用 287 次
- On Success and Simplicity: A Second Look at Transferable Targeted AttacksZhengyu Zhao, Zhuoran Liu, Martha A. LarsonNeurIPS 2021 · 被引用 173 次
- FCA: Learning a 3D Full-Coverage Vehicle Camouflage for Multi-View Physical Adversarial AttackDonghua Wang, Tingsong Jiang, Jialiang Sun, Weien Zhou 等AAAI 2022 · 被引用 149 次
相关 Paper
- Cheating Stereo Matching in Full-Scale: Physical Adversarial Attack Against Binocular Depth Estimation in Autonomous DrivingKangqiao Zhao, Shuo Huai, Xurui Song, Jun LuoAAAI 2026
- DepthCloak: Projecting Optical Camouflage Patches for Erroneous Monocular Depth Estimation of VehiclesHuixiang Wen, Shizong Yan, Shan Chang, Jie Xu 等ACM MM 2024 · 被引用 2 次
- pi-Jack: Physical-World Adversarial Attack on Monocular Depth Estimation with Perspective HijackingTianyue Zheng, Jingzhi Hu, Rui Tan, Yinqian Zhang 等USENIX Security 2024 · 被引用 8 次
- Adversarial Training of Self-supervised Monocular Depth Estimation against Physical-World AttacksZhiyuan Cheng, James Liang, Guanhong Tao, Dongfang Liu 等ICLR 2023 · 被引用 6 次
- Physically Realizable Adversarial Examples for LiDAR Object DetectionJames Tu, Mengye Ren, Sivabalan Manivasagam, Ming Liang 等CVPR 2020
