Frequency-Aware GAN for Imperceptible Transfer Attack on 3D Point Clouds
Xiaowen Cai, Yunbo Tao, Daizong Liu, Pan Zhou, Xiaoye Qu, Jianfeng Dong, Keke Tang, Lichao Sun
Abstract
With the development of depth sensors and 3D vision, the vulnerability of 3D point cloud models has garnered heightened concern. Almost all existing 3D attackers are deployed in the white-box setting, where they access the model details and directly optimize coordinate-wise noises to perturb 3D objects. However, realistic 3D applications would not share any model information (model parameters, gradients, etc.) with users. Although a few recent works try to explore the black-box attack, they still achieve limited attack success rates (ASR) and fail to generate high-quality adversarial samples. In this paper, we focus on designing a transfer-based black-box attack method, called Transferable Frequency-aware 3D GAN, to delve into achieving a high black-box ASR by improving the adversarial transferability while making the adversarial samples more imperceptible. Considering that the 3D imperceptibility depends on whether the shape of the object is distorted, we utilize the spectral tool with the GAN design to explicitly perceive and preserve the 3D geometric structures. Specifically, we design the Graph Fourier Transform (GFT) encoding layer in the GAN generator to extract the geometries as guidance, and develop a corresponding Inverse-GFT decoding layer to decode latent features with this guidance to reconstruct high-quality adversarial samples. To further improve the transferability, we develop a dual learning scheme of discriminator from both frequency and feature perspectives to constrain the generator via adversarial learning. Finally, imperceptible and transferable perturbations are rapidly generated by our proposed attack. Experimental results demonstrate that our attack method achieves the highest transfer ASR while exhibiting stronger imperceptibility.
Ask about this paper
Ask your agent about it.
Lune has read the top-tier papers around this one, so every answer names the papers it rests on.
Your agent calls
Lunesearch_papers
Free to start. No credit card required.
Terminal
Install the CLIlune papers get 6c199526-0024-48b5-9da7-eff5e9bf0dd6Cited by top-tier papers7
- Fit the Distribution: Cross-Image/Prompt Adversarial Attacks on Multimodal Large Language ModelsHai Yan, Haijian Ma, Xiaowen Cai, Daizong Liu et al.NeurIPS 2025 · 21 citations
- Towards Building Model/Prompt-Transferable Attackers against Large Vision-Language ModelsXiaowen Cai, Daizong Liu, Xiaoye Qu, Xiang Fang et al.NeurIPS 2025 · 8 citations
- Learning from Few Samples: A Novel Approach for High-Quality Malcode GenerationHaijian Ma, Daizong Liu, Xiaowen Cai, Pan Zhou et al.EMNLP 2025
- Seeing is Not Believing: Adversarial Natural Object Optimization for Hard-Label 3D Scene AttacksDaizong Liu, Wei HuCVPR 2025
- NoPain: No-box Point Cloud Attack via Optimal Transport Singular BoundaryZezeng Li, Xiaoyu Du, Na Lei, Liming Chen et al.CVPR 2025
Related papers
- Towards a 3D Transfer-Based Black-Box Attack via Critical Feature GuidanceShuchao Pang, Zhenghan Chen, Shen Zhang, Liming Lu et al.ICCV 2025 · 1 citation
- Generating Transferable 3D Adversarial Point Cloud via Random Perturbation FactorizationBangyan He, Jian Liu, Yiming Li, Siyuan Liang et al.AAAI 2023 · 53 citations
- 3DHacker: Spectrum-based Decision Boundary Generation for Hard-label 3D Point Cloud AttackYunbo Tao, Daizong Liu, Pan Zhou, Yulai Xie et al.ICCV 2023 · 29 citations
- On Isometry Robustness of Deep 3D Point Cloud Models Under Adversarial AttacksYue Zhao, Yuwei Wu, Caihua Chen, Andrew LimCVPR 2020
- Shape Prior Guided Attack: Sparser Perturbations on 3D Point CloudsZhenbo Shi, Zhi Chen, Zhenbo Xu, Wei Yang et al.AAAI 2022 · 25 citations
