CamouPurifier: Zero-shot and Camouflage-Agnostic Defense Against Adversarial Camouflage Attacks on Monocular Depth Estimation
Abstract
Adversarial camouflage attacks pose a significant threat to monocular depth estimation (MDE) systems in autonomous driving due to their physical realizability and robustness across diverse viewpoints. Existing adversarial defenses primarily focus on imperceptible perturbations or localized adversarial patches, rendering them ineffective against full-surface adversarial camouflage textures and potentially introducing additional geometric distortions. To address these limitations, we propose CamouPurifier, a zero-shot and camouflage-agnostic adversarial purification framework that incorporates adversarial camouflage localization and texture reconstruction. Specifically, we first employ a low-confidence-threshold detector to identify candidate vehicles and then integrate semantic-aware localization (SAL) with multi-domain texture anomaly localization (MTAL) to generate precise adversarial camouflage masks. Subsequently, we remove the localized adversarial patterns and reconstruct the missing vehicle textures using a geometry-guided diffusion model conditioned on vehicle edge information. To integrate the reconstructed textures into the original image, we further apply boundary-aware blending to maintain visual consistency with the surrounding scene. Comprehensive experiments demonstrate that CamouPurifier reduces the vehicle-region depth discrepancy by 84.5% compared with the undefended setting and by 51.2% compared with the strongest baseline. Its fidelity-oriented configuration further reduces global and background discrepancies by 53.7% and 41.2%, respectively.
est. 32% chance this paper gets accepted at ICLR 2027.
What do you think this paper will get?
All positions stay anonymous.