arXivDaily arXiv每日学术速递 周一至周五更新
arXiv周末暂无论文更新,休息一下吧,周末愉快~~
arXiv 2609.16336cs.CR

深度错觉:揭示深度估计中隐藏的立体视觉漏洞

Illusion of Depth: Revealing Hidden Stereo Vision Vulnerabilities in Depth Estimation

Sri Hrushikesh Varma Bhupathiraju, Tetsu Ishizue, Nicholas U. Costagliola, Ozora Sako, Kentaro Yoshioka, Takeshi Sugawara, Sara Rampazzi

首次发表
浏览论文内容

中文总结 AI 辅助

本研究揭示立体相机深度估计的固有漏洞,攻击者可用简单重复图案精细操控障碍物深度,影响多种算法和商用相机,并提出了基于相似度分数的动态检测防御策略。

中文摘要 AI 辅助

立体相机被集成到自动驾驶汽车、无人机和机器人等自主系统中,以比LiDAR技术更具成本效益的方式提供精确的深度估计。在这项工作中,我们揭示了立体相机中一个固有的漏洞,该漏洞源于其像素采样和标定过程,这些过程可能影响立体匹配算法的输出。攻击者可以使用简单的重复图案,在不依赖复杂的对抗性机器学习技术的情况下,实现对真实障碍物估计深度的精细控制。此外,基于深度学习的深度估计模型也表现出类似的漏洞。我们评估了这种攻击对两种广泛使用的立体匹配算法(BM和SGBM)、三种深度学习模型(PSMNet、MoCha-Stereo和UniMatch)、一种立体-LiDAR融合模型(SGM-DDC)以及两种流行的商用立体相机ZED2和Intel RealSense D435的影响。例如,在ZED2相机中,攻击者可以将障碍物位移至20米更远或12米更近。在我们真实世界的驾驶场景评估中,一次短暂的0.5秒攻击即可触发流行自动驾驶框架中的紧急制动。我们进一步使用CARLA证明了在高达40公里/小时的驾驶速度下的可行性。最后,我们确认了最先进防御措施的有效性不足,并提出了一种利用相似度分数动态检测和抑制深度差异的新策略。我们的工作突出了立体匹配和深度学习深度估计模型中隐藏的漏洞,解决了自主系统部署中的关键局限性。

英文摘要

Stereo cameras are integrated into autonomous systems such as self-driving cars, drones, and robots to offer precise depth estimation in a cost-effective manner compared to LiDAR technology. In this work, we reveal an intrinsic vulnerability in stereo cameras that stems from their pixel sampling and calibration processes, which can influence the outputs of stereo matching algorithms. Attackers can achieve fine-grained control over the estimated depth of real obstacles using simple repeating patterns, without relying on sophisticated adversarial machine learning techniques. Furthermore, deep learning-based depth estimation models exhibit a similar vulnerability. We evaluate the impact of this attack on two widely used stereo matching algorithms (BM and SGBM), three deep learning models (PSMNet, MoCha-Stereo, and UniMatch), a stereo-LiDAR fusion model (SGM-DDC), and two popular commercial stereo cameras, the ZED2 and Intel RealSense D435. For example, in the ZED2 camera, an attacker can displace obstacles up to 20~meters farther or 12~meters closer. In our real-world evaluation in a driving setting, a brief 0.5~second attack can trigger emergency braking in a popular autonomous driving framework. We further demonstrate the feasibility at driving speeds up to 40~km/h using CARLA. Finally, we confirm the ineffectiveness of state-of-the-art defenses, and we propose a novel strategy that leverages similarity scores to dynamically detect and suppress the depth discrepancies. Our work highlights vulnerabilities hidden in stereo matching and deep learning depth estimation models, addressing critical limitations in autonomous system deployments.

发表机构

  • University of Florida(佛罗里达大学)
  • The University of Electro-Communications(电波通信大学)
  • Keio University(庆应义塾大学)

机构由 AI 辅助整理,请以论文原文为准。

补充信息

↑