Shape-invariant 3D Adversarial Point Clouds
Qidong Huang, Xiaoyi Dong, Dongdong Chen, Hang Zhou, Weiming Zhang, Nenghai Yu
Abstract
Adversary and invisibility are two fundamental but conflict characters of adversarial perturbations. Previous adversarial attacks on 3D point cloud recognition have often been criticized for their noticeable point outliers, since they just involve an “implicit constrain” like global distance loss in the time-consuming optimization to limit the generated noise. While point cloud is a highly structured data format, it is hard to constrain its perturbation with a simple loss or metric properly. In this paper, we propose a novel Point-Cloud Sensitivity Map to boost both the efficiency and imperceptibility of point perturbations. This map reveals the vulnerability of point cloud recognition models when encountering shape-invariant adversarial noises. These noises are designed along the shape surface with an “explicit constrain” instead of extra distance loss. Specifically, we first apply a reversible coordinate transformation on each point of the point cloud input, to reduce one degree of point freedom and limit its movement on the tangent plane. Then we calculate the best attacking direction with the gradients of the transformed point cloud obtained on the white-box model. Finally we assign each point with a non-negative score to construct the sensitivity map, which benefits both white-box adversarial invisibility and black-box query-efficiency extended in our work. Extensive evaluations prove that our method can achieve the superior performance on various point cloud recognition models, with its satisfying adversarial imperceptibility and strong resistance to different point cloud defense settings. Our code is available at: https://github.com/shikiw/SI-Adv.
Ask about this paper
Your agent reads all of it.
Lune indexed this paper to the last equation, along with the top-tier papers that cite it. Ask a question and the answer quotes them.
Your agent calls
Luneget_paper_fulltext
Free to start. No credit card required.
Terminal
Install the CLIlune papers fulltext 99d444e0-bc3c-41b2-8497-3775b6cddba5Cited by top-tier papers30
- 3DHacker: Spectrum-based Decision Boundary Generation for Hard-label 3D Point Cloud AttackYunbo Tao, Daizong Liu, Pan Zhou, Yulai Xie et al.ICCV 2023 · 29 citations
- Deep Manifold Attack on Point Clouds via Parameter Plane StretchingKeke Tang, Jianpeng Wu, Weilong Peng, Yawen Shi et al.AAAI 2023 · 25 citations
- Explicitly Perceiving and Preserving the Local Geometric Structures for 3D Point Cloud AttackDaizong Liu, Wei HuAAAI 2024 · 22 citations
- Hide in Thicket: Generating Imperceptible and Rational Adversarial Perturbations on 3D Point CloudsTianrui Lou, Xiaojun Jia, Jindong Gu, Li Liu et al.CVPR 2024 · 19 citations
- Manifold Constraints for Imperceptible Adversarial Attacks on Point CloudsKeke Tang, Xu He, Weilong Peng, Jianpeng Wu et al.AAAI 2024 · 18 citations
Builds on14
- Towards Evaluating the Robustness of Neural NetworksNicholas Carlini, David A. WagnerS&P 2017 · 9,786 citations
- Walk in the Cloud: Learning Curves for Point Clouds Shape AnalysisTiange Xiang, Chaoyi Zhang, Yang Song, Jianhui Yu et al.ICCV 2021 · 369 citations
- Invisible for both Camera and LiDAR: Security of Multi-Sensor Fusion based Perception in Autonomous Driving Under Physical-World AttacksYulong Cao, Ningfei Wang, Chaowei Xiao, Dawei Yang et al.S&P 2021 · 309 citations
- Revisiting Point Cloud Shape Classification with a Simple and Effective BaselineAnkit Goyal, Hei Law, Bowei Liu, Alejandro Newell et al.ICML 2021 · 297 citations
- PointCloud Saliency MapsTianhang Zheng, Changyou Chen, Junsong Yuan, Bo Li et al.ICCV 2019 · 265 citations
Related papers
- Curvature-Invariant Adversarial Attacks for 3D Point CloudsJianping Zhang, Wenwei Gu, Yizhan Huang, Zhihan Jiang et al.AAAI 2024 · 17 citations
- SymAttack: Symmetry-aware Imperceptible Adversarial Attacks on 3D Point CloudsKeke Tang, Zhensu Wang, Weilong Peng, Lujie Huang et al.ACM MM 2024 · 10 citations
- Generating Transferable 3D Adversarial Point Cloud via Random Perturbation FactorizationBangyan He, Jian Liu, Yiming Li, Siyuan Liang et al.AAAI 2023 · 53 citations
- DUP-Net: Denoiser and Upsampler Network for 3D Adversarial Point Clouds DefenseHang Zhou, Kejiang Chen, Weiming Zhang, Han Fang et al.ICCV 2019 · 206 citations
- Shape Prior Guided Attack: Sparser Perturbations on 3D Point CloudsZhenbo Shi, Zhi Chen, Zhenbo Xu, Wei Yang et al.AAAI 2022 · 25 citations
