Advancing Adversarial Robustness in GNeRFs: The IL2-NeRF Attack
Nicole Meng, Caleb Manicke, Ronak Sahu, Caiwen Ding, Yingjie Lao
Abstract
Generalizable Neural Radiance Fields (GNeRF) are recognized as one of the most promising techniques for novel view synthesis and 3D model generation in real-world applications. However, like other generative models in computer vision, ensuring their adversarial robustness against various threat models is essential for practical use. The pioneering work in this area, NeRFool, introduced a state-ofthe-art attack that targets GNeRFs by manipulating source views before feature extraction, successfully disrupting the color and density results of the constructed views. Building on this foundation, we propose IL2-NeRF (Iterative L 2 NeRF Attack), a novel adversarial attack method that explores a new threat model (in the L 2 domain) for attacking GNeRFs. We evaluated IL2-NeRF against two standard GNeRF models across three benchmark datasets, demonstrating similar performance compared to NeRFool, based on the same evaluation metrics proposed by NeR-Fool. Our results establish IL2-NeRF as the first adversarial method for GNeRFs under the L 2 norm. We establish a foundational L 2 threat model for future research, enabling direct performance comparisons while introducing a smoother, image-wide perturbation approach in Adversarial 3D Reconstruction.
Ask about this paper
Your agent reads all of it.
Lune indexed this paper to the last equation, along with the top-tier papers that cite it. Ask a question and the answer quotes them.
Your agent calls
Luneget_paper_fulltext
Free to start. No credit card required.
Terminal
Install the CLIlune papers fulltext c1f45197-06cf-4465-8b5f-70d218f7d6cdCited by top-tier papers1
Ask how each one uses itBuilds on9
- Reliable evaluation of adversarial robustness with an ensemble of diverse parameter-free attacksFrancesco Croce, Matthias HeinICML 2020 · 2,337 citations
- MVSNeRF: Fast Generalizable Radiance Field Reconstruction from Multi-View StereoAnpei Chen, Zexiang Xu, Fuqiang Zhao, Xiaoshuai Zhang et al.ICCV 2021 · 1,024 citations
- Neural Rays for Occlusion-aware Image-based RenderingYuan Liu, Sida Peng, Lingjie Liu, Qianqian Wang et al.CVPR 2022 · 164 citations
- CGBA: Curvature-aware Geometric Black-box AttackMd Farhamdur Reza, Ali Rahmati, Tianfu Wu, Huaiyu DaiICCV 2023 · 33 citations
- BounceAttack: A Query-Efficient Decision-based Adversarial Attack by Bouncing into the WildJie Wan, Jianhao Fu, Lijin Wang, Ziqi YangS&P 2024 · 13 citations
Related papers
- NeRFool: Uncovering the Vulnerability of Generalizable Neural Radiance Fields against Adversarial PerturbationsYonggan Fu, Ye Yuan, Souvik Kundu, Shang Wu et al.ICML 2023 · 13 citations
- GNeRF: GAN-based Neural Radiance Field without Posed CameraQuan Meng, Anpei Chen, Haimin Luo, Minye Wu et al.ICCV 2021 · 222 citations
- Aug-NeRF: Training Stronger Neural Radiance Fields with Triple-Level Physically-Grounded AugmentationsTianlong Chen, Peihao Wang, Zhiwen Fan, Zhangyang WangCVPR 2022 · 32 citations
- StealthAttack: Robust 3D Gaussian Splatting Poisoning via Density-Guided IllusionsBo-Hsu Ke, You-Zhe Xie, Yu-Lun Liu, Wei-Chen ChiuICCV 2025 · 3 citations
- GSNeRF: Generalizable Semantic Neural Radiance Fields with Enhanced 3D Scene UnderstandingZi-Ting Chou, Sheng-Yu Huang, I-Jieh Liu, Yu-Chiang Frank WangCVPR 2024
