Skip to content
Preprint

Illusion of Depth: Revealing Hidden Stereo Vision Vulnerabilities in Depth Estimation

Sep 2026 · 0 citations · 64 references
Computer Science

TL;DR

This work reveals an intrinsic vulnerability in stereo cameras that stems from their pixel sampling and calibration processes, which can influence the outputs of stereo matching algorithms and proposes a novel strategy that leverages similarity scores to dynamically detect and suppress the depth discrepancies.

Abstract

Stereo cameras are integrated into autonomous systems such as self-driving cars, drones, and robots to offer precise depth estimation in a cost-effective manner compared to LiDAR technology. In this work, we reveal an intrinsic vulnerability in stereo cameras that stems from their pixel sampling and calibration processes, which can influence the outputs of stereo matching algorithms. Attackers can achieve fine-grained control over the estimated depth of real obstacles using simple repeating patterns, without relying on sophisticated adversarial machine learning techniques. Furthermore, deep learning-based depth estimation models exhibit a similar vulnerability. We evaluate the impact of this attack on two widely used stereo matching algorithms (BM and SGBM), three deep learning models (PSMNet, MoCha-Stereo, and UniMatch), a stereo-LiDAR fusion model (SGM-DDC), and two popular commercial stereo cameras, the ZED2 and Intel RealSense D435. For example, in the ZED2 camera, an attacker can displace obstacles up to 20~meters farther or 12~meters closer. In our real-world evaluation in a driving setting, a brief 0.5~second attack can trigger emergency braking in a popular autonomous driving framework. We further demonstrate the feasibility at driving speeds up to 40~km/h using CARLA. Finally, we confirm the ineffectiveness of state-of-the-art defenses, and we propose a novel strategy that leverages similarity scores to dynamically detect and suppress the depth discrepancies. Our work highlights vulnerabilities hidden in stereo matching and deep learning depth estimation models, addressing critical limitations in autonomous system deployments.

View source

Similar papers

Computer Vision and Image Understanding

It is concluded that adversarial training is beneficial if and only if the reconstruction loss is not too constrained, and non-adversarial training outperforms (or is on par with) any method trained with a GAN when a constrained reconstruction loss is used in combination with batch normalisation.

R. Groenendijk, Sezer Karaoglu, Theo Gevers et al. · 0 citations
Nov 2026

Depth Camera or RGB-to-Depth? A Study of RGB-to-Depth Estimation for Robot Policy Learning

Point cloud–based robot policy learning has emerged as a powerful approach for robotic manipulation by enabling policies to directly exploit 3D geometric structure. In such pipelines, depth image acquisition plays a critical role in point cloud construction. However, raw depth from depth cameras is often noisy, sensiti...

Yi-Fei Ren, Pietro Vitiello, Edward Johns · 0 citations
Conference Sep 2026

Generation of optical intelligent deception samples for UAVs

Visible-light target detectors based on deep neural networks (DNNs) have been widely deployed in UAVs surveillance and low-altitude security control, posing challenges to UAVs operations. This paper employs a sample-adversarial attack method in UAVs models to address robustness issues against attacks from multiple view...

Qi-Zhan Chen, Hao-Li Xu, Qian Cheng et al. · 0 citations
#edge computing Preprint Aug 2026

Misanthrope: A Privacy-Preserving Keypoint Detector

This work introduces Misanthrope, a novel privacy-preserving keypoint detector trained through self-distillation to avoid detecting keypoints on people, thus mitigating inversion attacks at the source rather than through post-hoc obfuscation.

F. Vultaggio, Predrag Djindjic, Markus Gerke et al. · 0 citations
Conference Aug 2026

Monocular distance estimation: from geometric foundations and deep learning innovations to industrial deployment challenges

It is concluded that future industrial deployment on edge-computing platforms will rely on a synergy between lightweight network architectures and multi-sensor fusion and self-supervised frameworks.

Zi-Kang Fan, Zi-Hao Xiang, Jiang-Sheng Liu · 0 citations
#machine learning Preprint Aug 2026

Adversarial Calibration Attack on Autonomous Vehicles

Adversarial Calibration Attack (ACA), the first physical attack against camera-LiDAR online calibration, is presented and demonstrated that online calibration is a practical and safety-critical attack surface for AVs.

Liang-Kai Liu, Qingzhao Zhang, Kang G. Shin · 0 citations

We use cookies to run the site and, with your consent, for analytics and to show ads. See our Cookie Policy.