Shape Prior Guided Attack: Sparser Perturbations on 3D Point Clouds
Zhenbo Shi, Zhi Chen, Zhenbo Xu, Wei Yang, Zhidong Yu, Liusheng Huang
Abstract
Deep neural networks are extremely vulnerable to malicious input data. As 3D data is increasingly used in vision tasks such as robots, autonomous driving and drones, the internal robustness of the classification models for 3D point cloud has received widespread attention. In this paper, we propose a novel method named SPGA (Shape Prior Guided Attack) to generate adversarial point cloud examples. We use shape prior information to make perturbations sparser and thus achieve imperceptible attacks. In particular, we propose a Spatially Logical Block (SLB) to apply adversarial points through sliding in the oriented bounding box. Moreover, we design an algorithm called FOFA for this type of task, which further refines the adversarial attack in the process of breaking down complicated problems into sub-problems. Compared with the methods of global perturbation, our attack method consumes significantly fewer computations, making it more efficient. Most importantly of all, SPGA can generate examples with a higher attack success rate (even in a defensive situation), less perturbation budget and stronger transferability.
Ask about this paper
Your agent reads all of it.
Lune indexed this paper to the last equation, along with the top-tier papers that cite it. Ask a question and the answer quotes them.
Your agent calls
Luneget_paper_fulltext
Free to start. No credit card required.
Terminal
Install the CLIlune papers fulltext 28dde13d-20a5-430b-990a-7d803b942e36Cited by top-tier papers9
- 3DHacker: Spectrum-based Decision Boundary Generation for Hard-label 3D Point Cloud AttackYunbo Tao, Daizong Liu, Pan Zhou, Yulai Xie et al.ICCV 2023 · 29 citations
- PointCA: Evaluating the Robustness of 3D Point Cloud Completion Models against Adversarial ExamplesShengshan Hu, Junwei Zhang, Wei Liu, Junhui Hou et al.AAAI 2023 · 14 citations
- Ada3Diff: Defending against 3D Adversarial Point Clouds via Adaptive DiffusionKui Zhang, Hang Zhou, Jie Zhang, Qidong Huang et al.ACM MM 2023 · 14 citations
- Pagoda: Privacy Protection for Volumetric Video Streaming through Poisson Diffusion ModelRui Lu, Lai Wei, Shuntao Zhu, Chuang Hu et al.ACM MM 2023 · 4 citations
- Less Is More: Sparse and Cooperative Perturbation for Point Cloud AttacksKeke Tang, Tianyu Hao, Xiaofei Wang, Weilong Peng et al.AAAI 2026
Builds on8
- Towards Evaluating the Robustness of Neural NetworksNicholas Carlini, David A. WagnerS&P 2017 · 9,786 citations
- DensePoint: Learning Densely Contextual Representation for Efficient Point Cloud ProcessingYongcheng Liu, Bin Fan, Gaofeng Meng, Jiwen Lu et al.ICCV 2019 · 295 citations
- Robust Adversarial Objects against Deep Learning ModelsTzungyu Tsai, Kaichen Yang, Tsung-Yi Ho, Yier JinAAAI 2020 · 167 citations
- Minimal Adversarial Examples for Deep Learning on 3D Point CloudsJaeyeon Kim, Binh-Son Hua, Duc Thanh Nguyen, Sai-Kit YeungICCV 2021 · 73 citations
- View-GCN: View-Based Graph Convolutional Network for 3D Shape AnalysisXin Wei, Ruixuan Yu, Jian SunCVPR 2020
Related papers
- Explicitly Perceiving and Preserving the Local Geometric Structures for 3D Point Cloud AttackDaizong Liu, Wei HuAAAI 2024 · 22 citations
- Self-Robust 3D Point Recognition via Gather-Vector GuidanceXiaoyi Dong, Dongdong Chen, Hang Zhou, Gang Hua et al.CVPR 2020
- Towards a 3D Transfer-Based Black-Box Attack via Critical Feature GuidanceShuchao Pang, Zhenghan Chen, Shen Zhang, Liming Lu et al.ICCV 2025 · 1 citation
- Frequency-Aware GAN for Imperceptible Transfer Attack on 3D Point CloudsXiaowen Cai, Yunbo Tao, Daizong Liu, Pan Zhou et al.ACM MM 2024 · 9 citations
- Seeing is Not Believing: Adversarial Natural Object Optimization for Hard-Label 3D Scene AttacksDaizong Liu, Wei HuCVPR 2025
