用3D纹理欺骗自动驾驶立体测距,让真实物体消失
Cheating Stereo Matching in Full-scale: Physical Adversarial Attack against Binocular Depth Estimation in Autonomous Driving
- 用全局伪装纹理的3D物理攻击,适配双目视角差异
- 攻击使立体匹配模型误判深度,错误率超90%
- 适合研究自动驾驶安全与对抗样本防御者
尽管深度神经网络在自动驾驶感知中已被证实易受对抗样本攻击,但现有攻击多依赖2D贴图,且主要针对单目感知。立体视觉中的双目深度估计对物理对抗样本(PAEs)的脆弱性尚未充分探索。为此,本文提出首个面向自动驾驶场景的纹理增强型物理对抗攻击方法。该方法采用3D PAE配合全局伪装纹理,而非局部2D贴图,确保在双目相机不同视角下兼具视觉一致性和攻击有效性。为应对双目相机的视差效应,我们设计了一种新的3D立体匹配渲染模块,使对抗样本能精确对齐真实世界位置与朝向。此外,提出一种新型融合攻击策略,通过细粒度优化实现目标与环境的无缝融合,显著提升隐蔽性与破坏力。大量实验表明,所生成的PAEs可成功诱导立体匹配模型输出错误深度信息。
原文摘要 · Abstract (English)
Though deep neural models adopted to realize the perception of autonomous driving have proven vulnerable to adversarial examples, known attacks often leverage 2D patches and target mostly monocular perception. Therefore, the effectiveness of Physical Adversarial Examples (PAEs) on stereo-based binocular depth estimation remains largely unexplored. To this end, we propose the first texture-enabled physical adversarial attack against stereo matching models in the context of autonomous driving. Our method employs a 3D PAE with global camouflage texture rather than a local 2D patch-based one, ensuring both visual consistency and attack effectiveness across different viewpoints of stereo cameras. To cope with the disparity effect of these cameras, we also propose a new 3D stereo matching rendering module that allows the PAE to be aligned with real-world positions and headings in binocular vision. We further propose a novel merging attack that seamlessly blends the target into the environment through fine-grained PAE optimization. It has significantly enhanced stealth and lethality upon existing hiding attacks that fail to get seamlessly merged into the background. Extensive evaluations show that our PAEs can successfully fool the stereo models into producing erroneous depth information.
Thank you to arXiv for use of its open access interoperability. PaperDance 不是 arXiv 官方产品;中文卡片由大模型生成,请以原文为准。