Robustness Certification for Point Cloud Models
Tobias Lorenz, Anian Ruoss, Mislav Balunovic, Gagandeep Singh, Martin T. Vechev
Abstract
The use of deep 3D point cloud models in safety-critical applications, such as autonomous driving, dictates the need to certify the robustness of these models to real-world trans-formations. This is technically challenging, as it requires a scalable verifier tailored to point cloud models that handles a wide range of semantic 3D transformations. In this work, we address this challenge and introduce 3DCertify, the first verifier able to certify the robustness of point cloud models. 3DCertify is based on two key insights: (i) a generic relaxation based on first-order Taylor approximations, applicable to any differentiable transformation, and (ii) a precise relaxation for global feature pooling, which is more complex than pointwise activations (e.g., ReLU or sigmoid) but commonly employed in point cloud models. We demonstrate the effectiveness of 3DCertify by performing an extensive evaluation on a wide range of 3D transformations (e.g., rotation, twisting) for both classification and part segmentation tasks. For example, we can certify robustness against rotations by ±60° for 95.7% of point clouds, and our max pool relaxation increases certification by up to 15.6%.
Ask about this paper
Your agent reads all of it.
Lune indexed this paper to the last equation, along with the top-tier papers that cite it. Ask a question and the answer quotes them.
Your agent calls
Luneget_paper_fulltext
Free to start. No credit card required.
Terminal
Install the CLIlune papers fulltext ea60b356-2b54-4fbb-b41a-02c748fae485Cited by top-tier papers12
- Adversarially Robust 3D Point Cloud Recognition Using Self-SupervisionsJiachen Sun, Yulong Cao, Christopher B. Choy, Zhiding Yu et al.NeurIPS 2021 · 64 citations
- Scalable Certified Segmentation via Randomized SmoothingMarc Fischer, Maximilian Baader, Martin T. VechevICML 2021 · 49 citations
- TPC: Transformation-Specific Smoothing for Point Cloud ModelsWenda Chu, Linyi Li, Bo LiICML 2022 · 14 citations
- Invariance-Aware Randomized Smoothing CertificatesJan Schuchardt, Stephan GünnemannNeurIPS 2022 · 8 citations
- 3DeformRS: Certifying Spatial Deformations on Point CloudsGabriel Pérez S., Juan C. Pérez, Motasem Alfarra, Silvio Giancola et al.CVPR 2022 · 5 citations
Builds on17
- Fast is better than free: Revisiting adversarial trainingEric Wong, Leslie Rice, J. Zico KolterICLR 2020 · 1,352 citations
- On Adaptive Attacks to Adversarial Example DefensesFlorian Tramèr, Nicholas Carlini, Wieland Brendel, Aleksander MadryNeurIPS 2020 · 1,026 citations
- Certified Robustness to Adversarial Examples with Differential PrivacyMathias Lécuyer, Vaggelis Atlidakis, Roxana Geambasu, Daniel Hsu et al.S&P 2019 · 1,022 citations
- AI2: Safety and Robustness Certification of Neural Networks with Abstract InterpretationTimon Gehr, Matthew Mirman, Dana Drachsler-Cohen, Petar Tsankov et al.S&P 2018 · 987 citations
- Formal Security Analysis of Neural Networks using Symbolic IntervalsShiqi Wang, Kexin Pei, Justin Whitehouse, Junfeng Yang et al.USENIX Security 2018 · 523 citations
Related papers
- PointCert: Point Cloud Classification with Deterministic Certified Robustness GuaranteesJinghuai Zhang, Jinyuan Jia, Hongbin Liu, Neil Zhenqiang GongCVPR 2023
- Certified L2-Norm Robustness of 3D Point Cloud Recognition in the Frequency DomainLiang Zhou, Qiming Wang, Tianze ChenAAAI 2026
- PointGuard: Provably Robust 3D Point Cloud ClassificationHongbin Liu, Jinyuan Jia, Neil Zhenqiang GongCVPR 2021
- Efficient Certification of Spatial RobustnessAnian Ruoss, Maximilian Baader, Mislav Balunovic, Martin T. VechevAAAI 2021 · 26 citations
- Provable Defense Against Geometric TransformationsRem Yang, Jacob Laurel, Sasa Misailovic, Gagandeep SinghICLR 2023 · 1 citation
