paper-with-me

Papers

BadDepth: Backdoor Attacks Against Monocular Depth Estimation in the Physical World

2025-05-22 · Ji Guo, Long Zhou, Zhijin Wang, Jiaming He, Qiyang Song, Aiguo Chen, Wenbo Jiang

In recent years, deep learning-based Monocular Depth Estimation (MDE) models have been widely applied in fields such as autonomous driving and robotics. However, their vulnerability to backdoor attacks remains unexplored. To fill the gap in this area, we conduct a comprehensive investigation of backdoor attacks against MDE models. Typically, existing backdoor attack methods can not be applied to MDE models. This is because the label used in MDE is in the form of a depth map. To address this, we propose BadDepth, the first backdoor attack targeting MDE models. BadDepth overcomes this limitation by selectively manipulating the target object's depth using an image segmentation model and restoring the surrounding areas via depth completion, thereby generating poisoned datasets for object-level backdoor attacks. To improve robustness in physical world scenarios, we further introduce digital-to-physical augmentation to adapt to the domain gap between the physical world and the digital domain. Extensive experiments on multiple models validate the effectiveness of BadDepth in both the digital domain and the physical world, without being affected by environmental factors.

📄 PDF Abstract BibTeX arXiv:2505.16154

Code (0)

등록된 구현이 없습니다.

Tasks

Autonomous DrivingBackdoor AttackDepth CompletionDepth EstimationImage SegmentationMonocular Depth EstimationSemantic Segmentation

Similar Papers 제목 키워드 기반

BAFFLE: TOWARDS RESOLVING FEDERATED LEARNING’S DILEMMA - THWARTING BACKDOOR AND INFERENCE ATTACKS

2021-01-01 · Thien Duc Nguyen, Phillip Rieger, Hossein Yalame, Helen Möllering 외

Recently, federated learning (FL) has been subject to both security and privacy attacks posing a dilemmatic challenge on the underlying algorithmic designs: On the one hand, FL is shown to be vulnerable to backdoor attac…

Federated Learningimage-classificationImage Classification

On Certifying Robustness against Backdoor Attacks via Randomized Smoothing

2020-02-26 · Binghui Wang, Xiaoyu Cao, Jinyuan Jia, Neil Zhenqiang Gong

Backdoor attack is a severe security threat to deep neural networks (DNNs). We envision that, like adversarial examples, there will be a cat-and-mouse game for backdoor attacks, i.e., new empirical defenses are developed…

Backdoor Attack

Reliable Poisoned Sample Detection against Backdoor Attacks Enhanced by Sharpness Aware Minimization

2024-11-18 · Mingda Zhang, Mingli Zhu, Zihao Zhu, Baoyuan Wu

Backdoor attack has been considered as a serious security threat to deep neural networks (DNNs). Poisoned sample detection (PSD) that aims at filtering out poisoned samples from an untrustworthy training dataset has show…

Backdoor AttackData Poisoning

Self-supervised Adversarial Training of Monocular Depth Estimation against Physical-World Attacks

2024-06-09 · Zhiyuan Cheng, Cheng Han, James Liang, Qifan Wang 외

Monocular Depth Estimation (MDE) plays a vital role in applications such as autonomous driving. However, various attacks target MDE models, with physical attacks posing significant threats to system security. Traditional…

Adversarial RobustnessAutonomous DrivingContrastive LearningDepth Estimation+1

Adversarial Training of Self-supervised Monocular Depth Estimation against Physical-World Attacks

2023-01-31 · Zhiyuan Cheng, James Liang, Guanhong Tao, Dongfang Liu 외

Monocular Depth Estimation (MDE) is a critical component in applications such as autonomous driving. There are various attacks against MDE networks. These attacks, especially the physical ones, pose a great threat to the…

Adversarial RobustnessAutonomous DrivingContrastive LearningDepth Estimation+1