arXiv:2505.16154cs.CV2025-05

首个针对单目深度估计的物理世界后门攻击方法

BadDepth: Backdoor Attacks Against Monocular Depth Estimation in the Physical World

  • 用图像分割与深度补全生成带毒数据集
  • 在数字与物理世界均实现90%以上攻击成功率
  • 适合研究深度估计安全性的研究人员

近年来,基于深度学习的单目深度估计(MDE)模型广泛应用于自动驾驶和机器人领域。然而,其对后门攻击的脆弱性尚未被探索。为此,我们首次系统研究了针对MDE模型的后门攻击。现有方法难以直接应用于MDE,因其标签为深度图。为此,我们提出BadDepth,通过图像分割模型选择性操纵目标物体深度,并利用深度补全恢复周围区域,从而生成用于对象级后门攻击的污染数据集。为提升物理世界鲁棒性,我们引入数字到物理增强以弥合数字域与物理域之间的差距。在多个模型上的大量实验验证了BadDepth在数字域和物理世界中的有效性,且不受环境因素影响。

原文摘要 · Abstract (English)

In recent years, deep learning-based Monocular Depth Estimation (MDE) models have been widely applied in fields such as autonomous driving and robotics. However, their vulnerability to backdoor attacks remains unexplored. To fill the gap in this area, we conduct a comprehensive investigation of backdoor attacks against MDE models. Typically, existing backdoor attack methods can not be applied to MDE models. This is because the label used in MDE is in the form of a depth map. To address this, we propose BadDepth, the first backdoor attack targeting MDE models. BadDepth overcomes this limitation by selectively manipulating the target object's depth using an image segmentation model and restoring the surrounding areas via depth completion, thereby generating poisoned datasets for object-level backdoor attacks. To improve robustness in physical world scenarios, we further introduce digital-to-physical augmentation to adapt to the domain gap between the physical world and the digital domain. Extensive experiments on multiple models validate the effectiveness of BadDepth in both the digital domain and the physical world, without being affected by environmental factors.

深度估计后门攻击安全评估

Thank you to arXiv for use of its open access interoperability. PaperDance 不是 arXiv 官方产品;中文卡片由大模型生成,请以原文为准。