arXiv:2409.17376cs.CRcs.CV2024-09被引 3

用物理镜片干扰自动驾驶单目测距,让系统误判距离。

Optical Lens Attack on Deep Learning Based Monocular Depth Estimation

  • 通过在车摄像头加装凹凸镜片,制造虚假深度感知。
  • 实测显示攻击可使主流单目测距模型误差超30%。
  • 揭示自动驾驶视觉系统的物理安全漏洞,适合安全研究者关注。

单目深度估计(MDE)在基于视觉的自动驾驶(AD)系统中起关键作用,它利用单个摄像头图像判断物体深度,支持刹车、变道等决策。本文研究了自动驾驶系统中基于单目视觉的深度估计算法所面临的安全风险。通过利用MDE的漏洞及光学透镜原理,我们提出LensAttack——一种物理攻击方法,即在自动驾驶车辆摄像头前放置特定光学镜片,以操纵系统对物体距离的感知。LensAttack包含两种攻击形式:凹透镜攻击和凸透镜攻击,分别使用不同类型的镜片诱导错误的深度感知。我们首先构建了攻击的数学模型,整合多种攻击参数;随后进行仿真,并在真实驾驶场景中评估其性能,验证其对当前主流MDE模型的影响。结果表明,LensAttack显著降低了深度估计的准确性。

原文摘要 · Abstract (English)

Monocular Depth Estimation (MDE) plays a crucial role in vision-based Autonomous Driving (AD) systems. It utilizes a single-camera image to determine the depth of objects, facilitating driving decisions such as braking a few meters in front of a detected obstacle or changing lanes to avoid collision. In this paper, we investigate the security risks associated with monocular vision-based depth estimation algorithms utilized by AD systems. By exploiting the vulnerabilities of MDE and the principles of optical lenses, we introduce LensAttack, a physical attack that involves strategically placing optical lenses on the camera of an autonomous vehicle to manipulate the perceived object depths. LensAttack encompasses two attack formats: concave lens attack and convex lens attack, each utilizing different optical lenses to induce false depth perception. We begin by constructing a mathematical model of our attack, incorporating various attack parameters. Subsequently, we simulate the attack and evaluate its real-world performance in driving scenarios to demonstrate its effect on state-of-the-art MDE models. The results highlight the significant impact of LensAttack on the accuracy of depth estimation in AD systems.

自动驾驶物理攻击深度估计

Thank you to arXiv for use of its open access interoperability. PaperDance 不是 arXiv 官方产品;中文卡片由大模型生成,请以原文为准。