Researchers led by the University of Florida found the weakness in every camera-based depth system they tested, conventional or AI-based. A pattern projected onto a vehicle produced an error large enough to trigger a response such as braking.

Stereo cameras calculate distance by matching the same point in two slightly different views. Repeated stripes or squares can fool that matching process. Pixel sampling and calibration errors compound the ambiguity, according to the team's paper, so the system can assign a wrong distance to an object.

The tests covered two conventional depth algorithms, three AI models and a model combining stereo vision with LiDAR. Two commercial camera systems, ZED2 and Intel RealSense D435, also showed the error.

In a controlled outdoor test, the team projected a checkerboard-like image onto a van's rear beside the path of a car moving at about 15 km/h. Cameras on the car recorded the van at a false distance that placed it in the car's path. By varying the pattern, the researchers could make objects appear nearer or farther away.

The team assessed whether Autoware, an open-source autonomous-driving framework, detected the false readings as obstacles. The authors say persistent errors could provoke an automatic response such as emergency braking. Tests at higher speeds, up to 40 km/h, used a driving simulator.

Sara Rampazzi, the UF assistant professor who led the work, warned that repeated patterns can also occur naturally, making this a safety concern even without an attacker. Unexpected braking could put following traffic at risk. Drones and ground robots that rely on stereo depth sensing could face similar problems.

The team developed a correction that detects a repeating region and matches it as a whole, reducing the chance of choosing the wrong stripe or square. On 200 stereo image pairs recorded outdoors, it reduced depth errors to less than half a meter in 96.5% of cases.

An adaptation for one AI model, PSMNet, also suppressed the errors in tests on 200 image pairs from KITTI, a driving dataset, with patterns added. The reported defense evaluations used image pairs.

The paper was posted on September 14 and is due to be presented in November at ACM CCS, a cybersecurity research conference.