Unless you can either produce the correct 3D surface itself or fool the sensors somehow I don’t see how the inner implementation matters.
Or do you mean attacking the inner network somehow from inside the system?
Or do you mean attacking the inner network somehow from inside the system?
You don't need to produce the correct 3d surface if the surface recogniser is neural - you just need to produce a 3d surface that's adversarial. The adversarial surface could be completely unrealistic, like these adversarial images. (Although the adversarial generator could also be trained with "realism" as a constraint.)
Are they able to detect depth independent of the surface of a presented image? That would make it harder, but the point of failure then is just figuring out a way to dynamically fool them. I wouldn't be confident saying that's impossible.