Adversarial Patches in 3D: A Stealth Threat to Monocular Depth Estimation
-
Abstract
Monocular depth estimation (MDE) based on deep learning plays a critical role in applications such as autonomous driving, where robustness and reliability are essential to ensure safety. In this study, we explore the vulnerability of MDE models to visible patch-based adversarial attacks. To enhance the imperceptibility of these patches, we integrate them directly into 3D scenes and propose an end-to-end, optimization-based attack framework that generates visually subtle and vigorous adversarial examples without requiring any post-processing. Specifically, we employ gradient descent to identify vulnerable yet inconspicuous locations for patch application, while leveraging 3D geometry information to seamlessly blend patches with benign images. This approach creates natural and inconspicuous adversarial examples showing little attack intent. Our attack achieves state-of-the-art effectiveness, reducing the victim model′s performance by 29.8% and 25.1% on indoor and outdoor benchmarks, respectively. Furthermore, we extend our evaluation to other victim MDE models and autonomous driving tasks. Our adversarial examples are also effective in misleading these various models, demonstrating their strong transferability crossing models and tasks.
Full Text Translation (powered by iFLYTEK)
-
-