This work reveals an intrinsic vulnerability in stereo cameras that stems from their pixel sampling and calibration processes, which can influence the outputs of stereo matching algorithms and proposes a novel strategy that leverages similarity scores to dynamically detect and suppress the depth discrepancies.
Abstract
Stereo cameras are integrated into autonomous systems such as self-driving cars, drones, and robots to offer precise depth estimation in a cost-effective manner compared to LiDAR technology. In this work, we reveal an intrinsic vulnerability in stereo cameras that stems from their pixel sampling and calibration processes, which can influence the outputs of stereo matching algorithms. Attackers can achieve fine-grained control over the estimated depth of real obstacles using simple repeating patterns, without relying on sophisticated adversarial machine learning techniques. Furthermore, deep learning-based depth estimation models exhibit a similar vulnerability. We evaluate the impact of this attack on two widely used stereo matching algorithms (BM and SGBM), three deep learning models (PSMNet, MoCha-Stereo, and UniMatch), a stereo-LiDAR fusion model (SGM-DDC), and two popular commercial stereo cameras, the ZED2 and Intel RealSense D435. For example, in the ZED2 camera, an attacker can displace obstacles up to 20~meters farther or 12~meters closer. In our real-world evaluation in a driving setting, a brief 0.5~second attack can trigger emergency braking in a popular autonomous driving framework. We further demonstrate the feasibility at driving speeds up to 40~km/h using CARLA. Finally, we confirm the ineffectiveness of state-of-the-art defenses, and we propose a novel strategy that leverages similarity scores to dynamically detect and suppress the depth discrepancies. Our work highlights vulnerabilities hidden in stereo matching and deep learning depth estimation models, addressing critical limitations in autonomous system deployments.
It is concluded that adversarial training is beneficial if and only if the reconstruction loss is not too constrained, and non-adversarial training outperforms (or is on par with) any method trained with a GAN when a constrained reconstruction loss is used in combination with batch normalisation.
R. Groenendijk, Sezer Karaoglu, Theo Gevers et al.· 0 citations
Point cloud–based robot policy learning has emerged as a powerful approach for robotic manipulation by enabling policies to directly exploit 3D geometric structure. In such pipelines, depth image acquisition plays a critical role in point cloud construction. However, raw depth from depth cameras is often noisy, sensiti...
Yi-Fei Ren, Pietro Vitiello, Edward Johns· IEEE Robotics and Automation...· 0 citations
Visible-light target detectors based on deep neural networks (DNNs) have been widely deployed in UAVs surveillance and low-altitude security control, posing challenges to UAVs operations. This paper employs a sample-adversarial attack method in UAVs models to address robustness issues against attacks from multiple view...
Qi-Zhan Chen, Hao-Li Xu, Qian Cheng et al.· Global Intelligent Industry...· 0 citations
This work introduces Misanthrope, a novel privacy-preserving keypoint detector trained through self-distillation to avoid detecting keypoints on people, thus mitigating inversion attacks at the source rather than through post-hoc obfuscation.
F. Vultaggio, Predrag Djindjic, Markus Gerke et al.· 0 citations
It is concluded that future industrial deployment on edge-computing platforms will rely on a synergy between lightweight network architectures and multi-sensor fusion and self-supervised frameworks.
Adversarial Calibration Attack (ACA), the first physical attack against camera-LiDAR online calibration, is presented and demonstrated that online calibration is a practical and safety-critical attack surface for AVs.
Liang-Kai Liu, Qingzhao Zhang, Kang G. Shin· 0 citations
We use cookies to run the site and, with your consent, for analytics and to show ads.
See our Cookie Policy.