Seeing is Not Believing: Adversarial Natural Object Optimization for Hard-Label 3D Scene Attacks
Daizong Liu, Wei Hu
Abstract
Deep learning models for 3D data have shown to be vulnerable to adversarial attacks, which have received increasing attention in various safety-critical applications such as autonomous driving and robotic navigation. Existing 3D attackers mainly put effort into attacking the simple 3D classification model by perturbing point cloud objects in the white/black-box setting. However, real-world 3D applications focus on tackling more complicated scene-based data while sharing no information about the model parameters and logits with users. Therefore, directly applying previous naive 3D attack methods to these applications does not work. To this end, this paper attempts to address the challenging hard-label 3D scene attack with access only to the input/output of the 3D models. To make the attack effective and stealthy, we propose to generate universal adversarial objects, which will mislead scene-aware 3D models to predict attacker-chosen labels whenever these objects are placed on any scene input. Specifically, we inject an imperceptible object trigger with further perturbations into all scenes and learn to mislead their reasoning by only querying the 3D model. We start by initializing the trigger pattern with a realistic object and searching for an appropriate location to place it naturally in the scene data. Then, we design a novel weighted gradient estimation strategy to perturb the object trigger with additive slight noise to make them adversarial in an iterative optimization procedure. Extensive experiments demonstrate that our attack can achieve superior performance on seven 3D models and three scene-based datasets, with satisfactory adversarial imperceptibility and strong resistance to defense methods.
Ask about this paper
Your agent reads all of it.
Lune indexed this paper to the last equation, along with the top-tier papers that cite it. Ask a question and the answer quotes them.
Your agent calls
Luneget_paper_fulltext
Free to start. No credit card required.
Terminal
Install the CLIlune papers fulltext 7320943a-39d2-4038-8f0a-54a394efa93fCited by top-tier papers7
- Fit the Distribution: Cross-Image/Prompt Adversarial Attacks on Multimodal Large Language ModelsHai Yan, Haijian Ma, Xiaowen Cai, Daizong Liu et al.NeurIPS 2025 · 21 citations
- Towards Building Model/Prompt-Transferable Attackers against Large Vision-Language ModelsXiaowen Cai, Daizong Liu, Xiaoye Qu, Xiang Fang et al.NeurIPS 2025 · 8 citations
- LLM-Assisted Entropy-Based Adaptive Distillation for Unsupervised Fine-Grained Visual Representation LearningJianfeng Dong, Danfeng Luo, Daizong Liu, Jie Sun et al.ICCV 2025 · 1 citation
- Fast3D: Accelerating 3D Multi-modal Large Language Models for Efficient 3D Scene UnderstandingWencan Huang, Daizong Liu, Wei HuACM MM 2025 · 1 citation
- Learning from Few Samples: A Novel Approach for High-Quality Malcode GenerationHaijian Ma, Daizong Liu, Xiaowen Cai, Pan Zhou et al.EMNLP 2025
Builds on46
- Deep Hough Voting for 3D Object Detection in Point CloudsCharles R. Qi, Or Litany, Kaiming He, Leonidas J. GuibasICCV 2019 · 1,467 citations
- Revisiting Point Cloud Classification: A New Benchmark Dataset and Classification Model on Real-World DataMikaela Angelina Uy, Quang-Hieu Pham, Binh-Son Hua, Duc Thanh Nguyen et al.ICCV 2019 · 1,003 citations
- HopSkipJumpAttack: A Query-Efficient Decision-Based AttackJianbo Chen, Michael I. Jordan, Martin J. WainwrightS&P 2020 · 797 citations
- Group-Free 3D Object Detection via TransformersZe Liu, Zheng Zhang, Yue Cao, Han Hu et al.ICCV 2021 · 368 citations
- SoftGroup for 3D Instance Segmentation on Point CloudsThang Vu, Kookhoi Kim, Tung Minh Luu, Thanh Xuan Nguyen et al.CVPR 2022 · 251 citations
Related papers
- 3DHacker: Spectrum-based Decision Boundary Generation for Hard-label 3D Point Cloud AttackYunbo Tao, Daizong Liu, Pan Zhou, Yulai Xie et al.ICCV 2023 · 29 citations
- Physically Realizable Adversarial Examples for LiDAR Object DetectionJames Tu, Mengye Ren, Sivabalan Manivasagam, Ming Liang et al.CVPR 2020
- 3D-Adv: Black-Box Adversarial Attacks against Deep Learning Models through 3D SensorsKaichen Yang, Xuan-Yi Lin, Yixin Sun, Tsung-Yi Ho et al.DAC 2021 · 3 citations
- Minimal Adversarial Examples for Deep Learning on 3D Point CloudsJaeyeon Kim, Binh-Son Hua, Duc Thanh Nguyen, Sai-Kit YeungICCV 2021 · 73 citations
- PointBA: Towards Backdoor Attacks in 3D Point CloudXinke Li, Zhirui Chen, Yue Zhao, Zekun Tong et al.ICCV 2021 · 62 citations
