PointBA: Towards Backdoor Attacks in 3D Point Cloud
Xinke Li, Zhirui Chen, Yue Zhao, Zekun Tong, Yabang Zhao, Andrew Lim, Joey Tianyi Zhou
Abstract
3D deep learning has been increasingly more popular for a variety of tasks including many safety-critical applications. However, recently several works raise the security issues of 3D deep models. Although most of them consider adversarial attacks, we identify that backdoor attack is indeed a more serious threat to 3D deep learning systems but remains unexplored. We present the backdoor attacks in 3D point cloud with a unified framework that exploits the unique properties of 3D data and networks. In particular, we design two attack approaches on point cloud: the poison-label backdoor attack (PointPBA) and the clean- label backdoor attack (PointCBA). The first one is straight-forward and effective in practice, while the latter is more sophisticated assuming there are certain data inspections. The attack algorithms are mainly motivated and developed by 1) the recent discovery of 3D adversarial samples suggesting the vulnerability of deep models under spatial transformation; 2) the proposed feature disentanglement technique that manipulates the feature of the data through optimization methods and its potential to embed a new task. Extensive experiments show the efficacy of the PointPBA with over 95% success rate across various 3D datasets and models, and the more stealthy PointCBA with around 50% success rate. Our proposed backdoor attack in 3D point cloud is expected to perform as a baseline for improving the robustness of 3D deep models.
Ask about this paper
Your agent reads all of it.
Lune indexed this paper to the last equation, along with the top-tier papers that cite it. Ask a question and the answer quotes them.
Your agent calls
Luneget_paper_fulltext
Free to start. No credit card required.
Terminal
Install the CLIlune papers fulltext c30bf16c-6319-403c-a642-1375c44a9546Cited by top-tier papers5
- Computation and Data Efficient Backdoor AttacksYutong Wu, Xingshuo Han, Han Qiu, Tianwei ZhangICCV 2023 · 17 citations
- Fisher Information guided Purification against Backdoor AttacksNazmul Karim, Abdullah Al Arafat, Adnan Siraj Rakin, Zhishan Guo et al.CCS 2024 · 4 citations
- Influence-Based Fair Selection for Sample-Discriminative Backdoor AttackQi Wei, Shuo He, Jiahan Zhang, Lei Feng et al.AAAI 2025 · 1 citation
- Backdoor Attacks Against Deep Image Compression via Adaptive Frequency TriggerYi Yu, Yufei Wang, Wenhan Yang, Shijian Lu et al.CVPR 2023
- MOBA: A Material-Oriented Backdoor Attack Against LiDAR-Based 3D Object Detection SystemsSaket Sanjeev Chaturvedi, Gaurav Bagwe, Lan Emily Zhang, Pan He et al.AAAI 2026
Builds on15
- Towards Evaluating the Robustness of Neural NetworksNicholas Carlini, David A. WagnerS&P 2017 · 9,786 citations
- KPConv: Flexible and Deformable Convolution for Point CloudsHugues Thomas, Charles R. Qi, Jean-Emmanuel Deschaud, Beatriz Marcotegui et al.ICCV 2019 · 3,193 citations
- Hidden Trigger Backdoor AttacksAniruddha Saha, Akshayvarun Subramanya, Hamed PirsiavashAAAI 2020 · 743 citations
- Blind Backdoors in Deep Learning ModelsEugene Bagdasaryan, Vitaly ShmatikovUSENIX Security 2021 · 372 citations
- DensePoint: Learning Densely Contextual Representation for Efficient Point Cloud ProcessingYongcheng Liu, Bin Fan, Gaofeng Meng, Jiwen Lu et al.ICCV 2019 · 295 citations
Related papers
- A Backdoor Attack against 3D Point Cloud ClassifiersZhen Xiang, David J. Miller, Siheng Chen, Xi Li et al.ICCV 2021 · 90 citations
- Good Can Sometimes be Bad: A Unified Attack against 3D Point Cloud Classifier by a Flexible Isotropic ResamplingLinkun Fan, Jiahao Zhang, Juntao Zhang, Lei Zhang et al.CVPR 2026
- PointCRT: Detecting Backdoor in 3D Point Cloud via Corruption RobustnessShengshan Hu, Wei Liu, Minghui Li, Yechao Zhang et al.ACM MM 2023 · 15 citations
- Minimal Adversarial Examples for Deep Learning on 3D Point CloudsJaeyeon Kim, Binh-Son Hua, Duc Thanh Nguyen, Sai-Kit YeungICCV 2021 · 73 citations
- Seeing is Not Believing: Adversarial Natural Object Optimization for Hard-Label 3D Scene AttacksDaizong Liu, Wei HuCVPR 2025
