arXiv:2512.24111cs.CVcs.RO2025-12被引 1

用扩散模型生成逼真对抗物体,攻击单目深度估计。

Guided Diffusion-based Generation of Adversarial Objects for Real-World Monocular Depth Estimation Attacks

  • 基于扩散模型生成与场景一致的对抗物体。
  • 生成物体可引发显著深度误差,提升攻击效果。
  • 无需训练,适合真实驾驶环境评估安全风险。

单目深度估计(MDE)是自动驾驶系统的核心感知模块,但极易受到对抗攻击。深度估计错误会传递至下游决策环节,影响整体交通安全。现有物理攻击主要依赖纹理贴图,存在放置限制且真实性不足,难以在复杂驾驶环境中生效。为此,本文提出一种无需训练的生成式对抗攻击框架,通过扩散模型的条件生成过程,生成自然、场景一致的对抗物体。该框架包含显著区域选择模块,用于识别对MDE影响最大的区域,并引入雅可比向量积引导机制,将对抗梯度导向预训练扩散模型支持的更新方向。该方法可生成物理上可实现的对抗物体,显著引发深度估计偏差。大量数字与物理实验表明,本方法在攻击效果、隐蔽性和物理可部署性方面均显著优于现有方法,对自动驾驶安全性评估具有重要实践意义。

原文摘要 · Abstract (English)

Monocular Depth Estimation (MDE) serves as a core perception module in autonomous driving systems, but it remains highly susceptible to adversarial attacks. Errors in depth estimation may propagate through downstream decision making and influence overall traffic safety. Existing physical attacks primarily rely on texture-based patches, which impose strict placement constraints and exhibit limited realism, thereby reducing their effectiveness in complex driving environments. To overcome these limitations, this work introduces a training-free generative adversarial attack framework that generates naturalistic, scene-consistent adversarial objects via a diffusion-based conditional generation process. The framework incorporates a Salient Region Selection module that identifies regions most influential to MDE and a Jacobian Vector Product Guidance mechanism that steers adversarial gradients toward update directions supported by the pre-trained diffusion model. This formulation enables the generation of physically plausible adversarial objects capable of inducing substantial adversarial depth shifts. Extensive digital and physical experiments demonstrate that our method significantly outperforms existing attacks in effectiveness, stealthiness, and physical deployability, underscoring its strong practical implications for autonomous driving safety assessment.

对抗攻击深度估计扩散模型自动驾驶

Thank you to arXiv for use of its open access interoperability. PaperDance 不是 arXiv 官方产品;中文卡片由大模型生成,请以原文为准。