arXiv:2512.24792cs.CVcs.LG2025-12

用物理模型优化的投影攻击,让单目深度模型误判物体消失。

Projection-based Adversarial Attack using Physics-in-the-Loop Optimization for Monocular Depth Estimation

  • 基于物理回路优化,在真实环境测试扰动效果
  • 成功生成使物体在深度图中消失的对抗样本
  • 适合研究深度估计鲁棒性与防御机制的研究者

深度神经网络(DNN)对特定输入扰动敏感,易引发误分类,这一漏洞同样威胁基于DNN的单目深度估计(MDE)模型的可靠性,因此增强鲁棒性在实际应用中至关重要。为验证MDE模型的脆弱性,本文提出一种基于投影的对抗攻击方法,将扰动光投射到目标物体上。该方法采用物理回路优化(PITL),在真实环境中评估候选解,以考虑设备特性与干扰因素,并结合分布式协方差矩阵自适应进化策略。实验表明,所提方法成功生成导致深度误估的对抗样本,致使目标场景中部分物体在深度图中消失。

原文摘要 · Abstract (English)

Deep neural networks (DNNs) remain vulnerable to adversarial attacks that cause misclassification when specific perturbations are added to input images. This vulnerability also threatens the reliability of DNN-based monocular depth estimation (MDE) models, making robustness enhancement a critical need in practical applications. To validate the vulnerability of DNN-based MDE models, this study proposes a projection-based adversarial attack method that projects perturbation light onto a target object. The proposed method employs physics-in-the-loop (PITL) optimization -- evaluating candidate solutions in actual environments to account for device specifications and disturbances -- and utilizes a distributed covariance matrix adaptation evolution strategy. Experiments confirmed that the proposed method successfully created adversarial examples that lead to depth misestimations, resulting in parts of objects disappearing from the target scene.

深度估计对抗攻击物理建模

Thank you to arXiv for use of its open access interoperability. PaperDance 不是 arXiv 官方产品;中文卡片由大模型生成,请以原文为准。