Robust Structured Declarative Classifiers for 3D Point Clouds: Defending Adversarial Attacks with Implicit Gradients
Kaidong Li, Ziming Zhang, Cuncong Zhong, Guanghui Wang
Abstract
Deep neural networks for 3D point cloud classification, such as PointNet, have been demonstrated to be vulnerable to adversarial attacks. Current adversarial defenders often learn to denoise the (attacked) point clouds by reconstruction, and then feed them to the classifiers as input. In contrast to the literature, we propose a family of robust structured declarative classifiers for point cloud classification, where the internal constrained optimization mechanism can effectively defend adversarial attacks through implicit gradients. Such classifiers can be formulated using a bilevel optimization framework. We further propose an effective and efficient instantiation of our approach, namely, Lattice Point Classifier (LPC), based on structured sparse coding in the permutohedral lattice and 2D convolutional neural networks (CNNs) that is end-to-end trainable. We demonstrate state-of-the-art robust point cloud classification performance on ModelNet40 and ScanNet under seven different attackers. For instance, we achieve 89.51% and 83.16% test accuracy on each dataset under the recent JGBA attacker that outperforms DUP-Net and IF-Defense with PointNet by ∼70%. The demo code is available at https://zhang-vislab.github.io .
Ask about this paper
Your agent reads all of it.
Lune indexed this paper to the last equation, along with the top-tier papers that cite it. Ask a question and the answer quotes them.
Your agent calls
Luneget_paper_fulltext
Free to start. No credit card required.
Terminal
Install the CLIlune papers fulltext 03cdbc94-0756-4bf5-a28b-fe266f172a7dCited by top-tier papers7
- 3DHacker: Spectrum-based Decision Boundary Generation for Hard-label 3D Point Cloud AttackYunbo Tao, Daizong Liu, Pan Zhou, Yulai Xie et al.ICCV 2023 · 29 citations
- A Critical Revisit of Adversarial Robustness in 3D Point Cloud Recognition with Diffusion-Driven PurificationJiachen Sun, Jiongxiao Wang, Weili Nie, Zhiding Yu et al.ICML 2023 · 24 citations
- Ada3Diff: Defending against 3D Adversarial Point Clouds via Adaptive DiffusionKui Zhang, Hang Zhou, Jie Zhang, Qidong Huang et al.ACM MM 2023 · 14 citations
- PointCert: Point Cloud Classification with Deterministic Certified Robustness GuaranteesJinghuai Zhang, Jinyuan Jia, Hongbin Liu, Neil Zhenqiang GongCVPR 2023
- PWAVEP: Purifying Imperceptible Adversarial Perturbations in 3D Point Clouds via Spectral Graph WaveletsHaoran Li, Renyang Liu, Hongjia Liu, Chen Wang et al.WWW 2026
Builds on18
- PointCloud Saliency MapsTianhang Zheng, Changyou Chen, Junsong Yuan, Bo Li et al.ICCV 2019 · 265 citations
- DUP-Net: Denoiser and Upsampler Network for 3D Adversarial Point Clouds DefenseHang Zhou, Kejiang Chen, Weiming Zhang, Han Fang et al.ICCV 2019 · 206 citations
- Robust Adversarial Objects against Deep Learning ModelsTzungyu Tsai, Kaichen Yang, Tsung-Yi Ho, Yier JinAAAI 2020 · 167 citations
- Learning Relationships for Multi-View 3D Object RecognitionZe Yang, Liwei WangICCV 2019 · 166 citations
- A Backdoor Attack against 3D Point Cloud ClassifiersZhen Xiang, David J. Miller, Siheng Chen, Xi Li et al.ICCV 2021 · 90 citations
Related papers
- CAP: Robust Point Cloud Classification via Semantic and Structural ModelingDaizong Ding, Erling Jiang, Yuanmin Huang, Mi Zhang et al.CVPR 2023
- CausalPC: Improving the Robustness of Point Cloud Classification by Causal Effect IdentificationYuanmin Huang, Mi Zhang, Daizong Ding, Erling Jiang et al.CVPR 2024
- Efficient Joint Gradient Based Attack Against SOR Defense for 3D Point Cloud ClassificationChengcheng Ma, Weiliang Meng, Baoyuan Wu, Shibiao Xu et al.ACM MM 2020 · 49 citations
- PointGuard: Provably Robust 3D Point Cloud ClassificationHongbin Liu, Jinyuan Jia, Neil Zhenqiang GongCVPR 2021
- LG-GAN: Label Guided Adversarial Network for Flexible Targeted Attack of Point Cloud Based Deep NetworksHang Zhou, Dongdong Chen, Jing Liao, Kejiang Chen et al.CVPR 2020
