NeRFool: Uncovering the Vulnerability of Generalizable Neural Radiance Fields against Adversarial Perturbations
Yonggan Fu, Ye Yuan, Souvik Kundu, Shang Wu, Shunyao Zhang, Yingyan Celine Lin
Abstract
Generalizable Neural Radiance Fields (GNeRF) are one of the most promising real-world solutions for novel view synthesis, thanks to their cross-scene generalization capability and thus the possibility of instant rendering on new scenes. While adversarial robustness is essential for realworld applications, little study has been devoted to understanding its implication on GNeRF. We hypothesize that because GNeRF is implemented by conditioning on the source views from new scenes, which are often acquired from the Internet or third-party providers, there are potential new security concerns regarding its real-world applications. Meanwhile, existing understanding and solutions for neural networks' adversarial robustness may not be applicable to GNeRF, due to its 3D nature and uniquely diverse operations. To this end, we present NeRFool, which to the best of our knowledge is the first work that sets out to understand the adversarial robustness of GNeRF. Specifically, NeRFool unveils the vulnerability patterns and important insights regarding GNeRF's adversarial robustness. Built upon the above insights gained from NeRFool, we further develop NeRFool + , which integrates two techniques capable of effectively attacking GNeRF across a wide range of target views, and provide guidelines for defending against our proposed attacks. We believe that our NeRFool/NeRFool + lays the initial foundation for future innovations in developing robust realworld GNeRF solutions. Our codes are available at: https://github.com/GATECH-EIC/NeRFool .
Ask about this paper
Your agent reads all of it.
Lune indexed this paper to the last equation, along with the top-tier papers that cite it. Ask a question and the answer quotes them.
Your agent calls
Luneget_paper_fulltext
Free to start. No credit card required.
Terminal
Install the CLIlune papers fulltext 5f260b8a-442a-4cfa-8aa7-4b299a764a59Cited by top-tier papers6
- Geometry Cloak: Preventing TGS-based 3D Reconstruction from Copyrighted ImagesQi Song, Ziyuan Luo, Ka Chun Cheung, Simon See et al.NeurIPS 2024 · 20 citations
- StealthAttack: Robust 3D Gaussian Splatting Poisoning via Density-Guided IllusionsBo-Hsu Ke, You-Zhe Xie, Yu-Lun Liu, Wei-Chen ChiuICCV 2025 · 3 citations
- PoInit-of-View: Poisoning Initialization of Views Transfers Across Multiple 3D Reconstruction SystemsWeijie Wang, Songlong Xing, Zhengyu Zhao, Nicu Sebe et al.CVPR 2026 · 1 citation
- WhisperSplat: Lossless Steganography in 3D Gaussian SplattingNicole Meng, Ronak Sahu, Miao Yin, Faysal Hossain Shezan et al.ICML 2026
- Poison-splat: Computation Cost Attack on 3D Gaussian SplattingJiahao Lu, Yifan Zhang, Qiuhong Shen, Xinchao Wang et al.ICLR 2025
Builds on21
- Towards Evaluating the Robustness of Neural NetworksNicholas Carlini, David A. WagnerS&P 2017 · 9,786 citations
- Fast is better than free: Revisiting adversarial trainingEric Wong, Leslie Rice, J. Zico KolterICLR 2020 · 1,352 citations
- PlenOctrees for Real-time Rendering of Neural Radiance FieldsAlex Yu, Ruilong Li, Matthew Tancik, Hao Li et al.ICCV 2021 · 1,284 citations
- Overfitting in adversarially robust deep learningLeslie Rice, Eric Wong, J. Zico KolterICML 2020 · 935 citations
- FastNeRF: High-Fidelity Neural Rendering at 200FPSStephan J. Garbin, Marek Kowalski, Matthew Johnson, Jamie Shotton et al.ICCV 2021 · 778 citations
Related papers
- Advancing Adversarial Robustness in GNeRFs: The IL2-NeRF AttackNicole Meng, Caleb Manicke, Ronak Sahu, Caiwen Ding et al.CVPR 2025
- ViewFool: Evaluating the Robustness of Visual Recognition to Adversarial ViewpointsYinpeng Dong, Shouwei Ruan, Hang Su, Caixin Kang et al.NeurIPS 2022 · 72 citations
- GNeRF: GAN-based Neural Radiance Field without Posed CameraQuan Meng, Anpei Chen, Haimin Luo, Minye Wu et al.ICCV 2021 · 222 citations
- GeoNeRF: Generalizing NeRF with Geometry PriorsMohammad Mahdi Johari, Yann Lepoittevin, François FleuretCVPR 2022 · 154 citations
- Gen-NeRF: Efficient and Generalizable Neural Radiance Fields via Algorithm-Hardware Co-DesignYonggan Fu, Zhifan Ye, Jiayi Yuan, Shunyao Zhang et al.ISCA 2023 · 34 citations
