镜头划痕在特定光照下会引发深度误判,成像系统易受隐蔽物理攻击。
Scratched Lenses, Shifted Depth: Passive Camera-Side Optical Attacks

- 用光学建模方法,将划痕视为受场景触发的固定干扰通道。
- 真实与数字实验中,单目深度估计误差最高达32%。
- 适合关注物理安全、硬件鲁棒性的视觉系统研究者阅读。
视觉系统面临的物理对抗攻击通常通过场景操控(如对抗贴纸或投影)实现,攻击者控制相机所见内容。基于贴纸或附加光学器件的摄像头侧攻击则被视为设计图案引发的图像空间扰动,忽略了物理缺陷与场景光照、光学特性之间的交互。本文揭示一种威胁:被动式镜头侧损伤,具有持久性但仅在特定视觉条件下触发,产生影响几何推断的光学伪影。我们提出SLASH(Scratch-induced Lens Adversarial Streak Hijacking),即由摄像头镜头或保护罩上的微小划痕引起的物理攻击。划痕在强光源和镜面反射作用下生成结构化条纹伪影,扭曲深度线索。由于扰动固定于光路但依赖场景触发,具备持续性与选择性。我们从光学空间建模攻击,将划痕模式视为触发条件相关的光学信道,并优化单一配置以适应多样观测条件。在单目深度估计与单目3D目标检测任务中评估了SLASH在数字与真实世界的表现。在固定划痕约束下,单目深度估计的方向性深度偏差最高达32%相对误差,且对单目3D目标检测有稳定影响。物理实验验证其可迁移至真实摄像头记录,导致深度偏移超过模型自然预测基线。这些发现揭示了良性外观硬件缺陷作为潜在、场景触发的对抗机制的存在,挑战了物理鲁棒性的假设,推动安全视觉系统的防御研究。
原文摘要 · Abstract (English)
Physical adversarial attacks on vision systems are typically studied through scene manipulation, such as adversarial patches or projections, where the adversary controls what the camera observes. Camera-side attacks using stickers or auxiliary optics have also been explored, but they treat attacks as image-space perturbations from designed patterns. This misses how physical imperfections interact with scene-dependent lighting and optics. We identify a threat: passive lens-side damage that is persistent yet trigger-conditioned, producing optical artifacts that bias geometric inference under particular visual conditions. We instantiate this threat through Scratch-induced Lens Adversarial Streak Hijacking SLASH, a physical-world attack caused by small scratches on a camera lens or protective cover. Scratches interact with bright light sources and specular reflections to create structured streak artifacts that distort depth cues. Since the perturbation is fixed in the optical path but triggered by the scene, it is both persistent and selective. We formulate the attack in optical space, model the scratch pattern as a trigger-conditioned optical channel, and optimize one fixed configuration across diverse viewing conditions. We evaluate SLASH on monocular depth estimation and monocular 3D object detection in digital and real-world settings. Under the fixed-scratch constraint, directional depth shifts reach up to 32% relative error for monocular depth estimation, with consistent effects on monocular 3D object detection. Physical experiments confirm transfer to real camera recordings, inducing depth shifts above the model's natural prediction baseline. These findings reveal an attack surface where benign-looking hardware imperfections act as latent, scene-triggered adversarial mechanisms, challenging assumptions about physical robustness and motivating defenses for secure vision systems.
Thank you to arXiv for use of its open access interoperability. PaperDance 不是 arXiv 官方产品;中文卡片由大模型生成,请以原文为准。