Skip to main content
QUICK REVIEW

[论文解读] DoubleStar: Long-Range Attack Towards Depth Estimation based Obstacle Avoidance in Autonomous Systems

Ce Zhou, Qiben Yan|arXiv (Cornell University)|Oct 7, 2021
Adversarial Robustness in Machine Learning参考文献 29被引用 8
一句话总结

DoubleStar 是一种新型的长距离光学攻击,通过从两个互补光源投射光线,操纵基于立体视觉的深度估计,从而在自主系统中制造虚假障碍物感知。该攻击可实现对无人机的连续、远距离控制——夜间可造成高达15米的虚假深度,白天可达8米,通过利用立体匹配错误和镜头眩光效应,绕过传感器融合机制,引发无人机产生意外飞行行为,如突然停止或漂移。

ABSTRACT

Depth estimation-based obstacle avoidance has been widely adopted by autonomous systems (drones and vehicles) for safety purpose. It normally relies on a stereo camera to automatically detect obstacles and make flying/driving decisions, e.g., stopping several meters ahead of the obstacle in the path or moving away from the detected obstacle. In this paper, we explore new security risks associated with the stereo vision-based depth estimation algorithms used for obstacle avoidance. By exploiting the weaknesses of the stereo matching in depth estimation algorithms and the lens flare effect in optical imaging, we propose DoubleStar, a long-range attack that injects fake obstacle depth by projecting pure light from two complementary light sources. DoubleStar includes two distinctive attack formats: beams attack and orbs attack, which leverage projected light beams and lens flare orbs respectively to cause false depth perception. We successfully attack two commercial stereo cameras designed for autonomous systems (ZED and Intel RealSense). The visualization of fake depth perceived by the stereo cameras illustrates the false stereo matching induced by DoubleStar. We further use Ardupilot to simulate the attack and demonstrate its impact on drones. To validate the attack on real systems, we perform a real-world attack towards a commercial drone equipped with state-of-the-art obstacle avoidance algorithms. Our attack can continuously bring a flying drone to a sudden stop or drift it away across a long distance under various lighting conditions, even bypassing sensor fusion mechanisms. Specifically, our experimental results show that DoubleStar creates fake depth up to 15 meters in distance at night and up to 8 meters during the daytime. To mitigate this newly discovered threat, we provide discussions on potential countermeasures to defend against DoubleStar.

研究动机与目标

  • 揭示立体摄像头深度估计在自主系统中此前未被探索的安全漏洞。
  • 开发一种无需物理访问或传感器欺骗即可实现的长距离、持续性攻击,以操纵深度感知。
  • 展示通过投射光线对商用无人机实施光学攻击,诱导虚假障碍物检测的可行性。
  • 评估传感器融合机制在真实无人机系统遭受此类攻击时的鲁棒性。
  • 提出并分析针对此类新型3D对抗攻击的潜在防御措施。

提出的方法

  • DoubleStar 使用两个互补的光源,投射光束或镜头眩光光斑,诱导深度估计算法中发生虚假的立体匹配。
  • 光束攻击通过向一个相机视图注入强光,制造出模拟近距离障碍物的视差。
  • 光斑攻击则利用光源引起的镜头眩光效应,生成人工眩光,使其在立体匹配中表现为深度点。
  • 该攻击利用镜头眩光和光饱和等光学特性,制造持久且视觉上逼真的虚假障碍物。
  • 在商用立体摄像头(ZED、Intel RealSense)和DJI无人机上开展了真实世界实验,以验证攻击的有效性。
  • 通过Ardupilot仿真,展示了不同攻击模式对无人机飞行行为的影响。

实验结果

研究问题

  • RQ1光学投射能否在立体视觉系统中制造持久、远距离的虚假深度感知?
  • RQ2镜头眩光和立体匹配漏洞如何实现距离达15米的人工障碍物生成?
  • RQ3DoubleStar在多大程度上能够绕过现代自主无人机中的传感器融合机制?
  • RQ4现有防御措施(如偏振膜和遮光罩)对这类攻击的局限性是什么?
  • RQ5该攻击是否能在不同光照条件和飞行模式下持续进行?

主要发现

  • DoubleStar 仅通过投射光线,成功在夜间制造出高达15米、白天高达8米的虚假深度感知。
  • 该攻击使一架真实DJI无人机在7米距离处突然停止或偏离飞行路径。
  • 该攻击在多种光照条件下均有效,并可绕过RealSense摄像头的传感器融合机制。
  • 现有防御措施如薄膜偏振片和遮光罩对注入的眩光和镜头眩光光斑完全无效。
  • 该攻击利用立体匹配缺陷和光学效应,而非依赖传统对抗性扰动,因此难以通过标准2D对抗防御方法进行防御。
  • Ardupilot仿真结果证实,该攻击可引发不安全的飞行决策,包括突然停止和横向漂移,影响多种飞行模式。

更好的研究,从现在开始

从阅读论文到最终审阅,大幅缩短您的研究时间。

无需绑定信用卡

本解读由 AI 生成,并经人工编辑审核。