Curvature-Invariant Adversarial Attacks for 3D Point Clouds
Jianping Zhang, Wenwei Gu, Yizhan Huang, Zhihan Jiang, Weibin Wu, Michael R. Lyu
Abstract
Imperceptibility is one of the crucial requirements for adversarial examples. Previous adversarial attacks on 3D point cloud recognition suffer from noticeable outliers, resulting in low imperceptibility. We think that the drawbacks can be alleviated via taking the local curvature of the point cloud into consideration. Existing approaches introduce the local geometry distance into the attack objective function. However, their definition of the local geometry distance neglects different perceptibility of distortions along different directions. In this paper, we aim to enhance the imperceptibility of adversarial attacks on 3D point cloud recognition by better preserving the local curvature of the original 3D point clouds. To this end, we propose the Curvature-Invariant Method (CIM), which directly regularizes the back-propagated gradient during the generation of adversarial point clouds based on two assumptions. Specifically, we first decompose the back-propagated gradients into the tangent plane and the normal direction. Then we directly reduce the gradient along the large curvature direction on the tangent plane and only keep the gradient along the negative normal direction. Comprehensive experimental comparisons confirm the superiority of our approach. Notably, our strategy can achieve 7.2% and 14.5% improvements in Hausdorff distance and Gaussian curvature measurements of the imperceptibility.
Ask about this paper
Your agent reads all of it.
Lune indexed this paper to the last equation, along with the top-tier papers that cite it. Ask a question and the answer quotes them.
Your agent calls
Luneget_paper_fulltext
Free to start. No credit card required.
Terminal
Install the CLIlune papers fulltext 0aab6849-80c6-45ef-90a0-e3efff3bc06bCited by top-tier papers2
- CASL: Curvature-Augmented Self-supervised Learning for 3D Anomaly DetectionYaohua Zha, Xue Yuerong, Chunlin Fan, Yuansong Wang et al.AAAI 2026 · 2 citations
- Good Can Sometimes be Bad: A Unified Attack against 3D Point Cloud Classifier by a Flexible Isotropic ResamplingLinkun Fan, Jiahao Zhang, Juntao Zhang, Lei Zhang et al.CVPR 2026
Builds on15
- Towards Evaluating the Robustness of Neural NetworksNicholas Carlini, David A. WagnerS&P 2017 · 9,786 citations
- PointCloud Saliency MapsTianhang Zheng, Changyou Chen, Junsong Yuan, Bo Li et al.ICCV 2019 · 265 citations
- DUP-Net: Denoiser and Upsampler Network for 3D Adversarial Point Clouds DefenseHang Zhou, Kejiang Chen, Weiming Zhang, Han Fang et al.ICCV 2019 · 206 citations
- Improving Adversarial Transferability via Neuron Attribution-based AttacksJianping Zhang, Weibin Wu, Jen-tse Huang, Yizhan Huang et al.CVPR 2022 · 140 citations
- Shape-invariant 3D Adversarial Point CloudsQidong Huang, Xiaoyi Dong, Dongdong Chen, Hang Zhou et al.CVPR 2022 · 88 citations
Related papers
- Manifold Constraints for Imperceptible Adversarial Attacks on Point CloudsKeke Tang, Xu He, Weilong Peng, Jianpeng Wu et al.AAAI 2024 · 18 citations
- SymAttack: Symmetry-aware Imperceptible Adversarial Attacks on 3D Point CloudsKeke Tang, Zhensu Wang, Weilong Peng, Lujie Huang et al.ACM MM 2024 · 10 citations
- Isometric 3D Adversarial Examples in the Physical WorldYibo Miao, Yinpeng Dong, Jun Zhu, Xiao-Shan GaoNeurIPS 2022 · 45 citations
- Imperceptible 3D Point Cloud Attacks on Lattice-based Barycentric CoordinatesKeke Tang, Ziyong Du, Weilong Peng, Xiaofei Wang et al.AAAI 2025 · 9 citations
- PointCA: Evaluating the Robustness of 3D Point Cloud Completion Models against Adversarial ExamplesShengshan Hu, Junwei Zhang, Wei Liu, Junhui Hou et al.AAAI 2023 · 14 citations
