Physical Attack on Monocular Depth Estimation with Optimal Adversarial Patches

被引:48
作者
Cheng, Zhiyuan [1 ]
Liang, James [2 ]
Choi, Hongjun [1 ]
Tao, Guanhong [1 ]
Cao, Zhiwen [1 ]
Liu, Dongfang [2 ]
Zhang, Xiangyu [1 ]
机构
[1] Purdue Univ, W Lafayette, IN 47907 USA
[2] Rochester Inst Technol, Rochester, NY 14623 USA
来源
COMPUTER VISION, ECCV 2022, PT XXXVIII | 2022年 / 13698卷
关键词
Physical adversarial attack; Monocular depth estimation; Autonomous driving;
D O I
10.1007/978-3-031-19839-7_30
中图分类号
TP18 [人工智能理论];
学科分类号
081104 ; 0812 ; 0835 ; 1405 ;
摘要
Deep learning has substantially boosted the performance of Monocular Depth Estimation (MDE), a critical component in fully vision-based autonomous driving (AD) systems (e.g., Tesla and Toyota). In this work, we develop an attack against learning-based MDE. In particular, we use an optimization-based method to systematically generate stealthy physical-object-oriented adversarial patches to attack depth estimation. We balance the stealth and effectiveness of our attack with object-oriented adversarial design, sensitive region localization, and natural style camouflage. Using real-world driving scenarios, we evaluate our attack on concurrent MDE models and a representative downstream task for AD (i.e., 3D object detection). Experimental results show that our method can generate stealthy, effective, and robust adversarial patches for different target objects and models and achieves more than 6m mean depth estimation error and 93% attack success rate (ASR) in object detection with a patch of 1/9 of the vehicle's rear area. Field tests on three different driving routes with a real vehicle indicate that we cause over 6m mean depth estimation error and reduce the object detection rate from 90.70% to 5.16% in continuous video frames.
引用
收藏
页码:514 / 532
页数:19
相关论文
共 66 条
  • [1] Aich S, 2021, Arxiv, DOI arXiv:2009.00743
  • [2] [Anonymous], Vehicle Stopping Distance and Time
  • [3] [Anonymous], Tesla use per-pixel depth estimation with self-supervised learning
  • [4] [Anonymous], BREAK DISTANCE
  • [5] [Anonymous], Tesla AI Day
  • [6] Athalye A, 2018, PR MACH LEARN RES, V80
  • [7] Brown TB, 2018, Arxiv, DOI arXiv:1712.09665
  • [8] A LIMITED MEMORY ALGORITHM FOR BOUND CONSTRAINED OPTIMIZATION
    BYRD, RH
    LU, PH
    NOCEDAL, J
    ZHU, CY
    [J]. SIAM JOURNAL ON SCIENTIFIC COMPUTING, 1995, 16 (05) : 1190 - 1208
  • [9] Cao YL, 2021, P IEEE S SECUR PRIV, P176, DOI 10.1109/SP40001.2021.00076
  • [10] Adversarial Sensor Attack on LiDAR-based Perception in Autonomous Driving
    Cao, Yulong
    Xiao, Chaowei
    Cyr, Benjamin
    Zhou, Yimeng
    Park, Won
    Rampazzi, Sara
    Chen, Qi Alfred
    Fu, Kevin
    Mao, Z. Morley
    [J]. PROCEEDINGS OF THE 2019 ACM SIGSAC CONFERENCE ON COMPUTER AND COMMUNICATIONS SECURITY (CCS'19), 2019, : 2267 - 2281