PointGuard: Provably Robust 3D Point Cloud Classification
Hongbin Liu, Jinyuan Jia, Neil Zhenqiang Gong
摘要
3D point cloud classification has many safety-critical applications such as autonomous driving and robotic grasping. However, several studies showed that it is vulnerable to adversarial attacks. In particular, an attacker can make a classifier predict an incorrect label for a 3D point cloud via carefully modifying, adding, and/or deleting a small number of its points. Randomized smoothing is state-of-the-art technique to build certifiably robust 2D image classifiers. However, when applied to 3D point cloud classification, randomized smoothing can only certify robustness against adversarially modified points. In this work, we propose PointGuard, the first defense that has provable robustness guarantees against adversarially modified, added, and/or deleted points. Specifically, given a 3D point cloud and an arbitrary point cloud classifier, our PointGuard first creates multiple subsampled point clouds, each of which contains a random subset of the points in the original point cloud; then our PointGuard predicts the label of the original point cloud as the majority vote among the labels of the subsampled point clouds predicted by the point cloud classifier. Our first major theoretical contribution is that we show PointGuard provably predicts the same label for a 3D point cloud when the number of adversarially modified, added, and/or deleted points is bounded. Our second major theoretical contribution is that we prove the tightness of our derived bound when no assumptions on the point cloud classifier are made. Moreover, we design an efficient algorithm to compute our certified robustness guarantees. We also empirically evaluate Point-Guard on ModelNet40 and ScanNet benchmark datasets.
问问这篇 Paper
智能体会读完全文。
Lune 把这篇 Paper 索引到了每一个公式,引用它的顶会 Paper 也一样。你提问,回答直接引用原文。
引用它的顶会 Paper28
- Shape-invariant 3D Adversarial Point CloudsQidong Huang, Xiaoyi Dong, Dongdong Chen, Hang Zhou 等CVPR 2022 · 被引用 88 次
- Boosting Randomized Smoothing with Variance Reduced ClassifiersMiklós Z. Horváth, Mark Niklas Müller, Marc Fischer, Martin T. VechevICLR 2022 · 被引用 56 次
- Text-CRS: A Generalized Certified Robustness Framework against Textual Adversarial AttacksXinyu Zhang, Hanbin Hong, Yuan Hong, Peng Huang 等S&P 2024 · 被引用 41 次
- Robustness Certification for Point Cloud ModelsTobias Lorenz, Anian Ruoss, Mislav Balunovic, Gagandeep Singh 等ICCV 2021 · 被引用 29 次
- Almost Tight L0-norm Certified Robustness of Top-k Predictions against Adversarial PerturbationsJinyuan Jia, Binghui Wang, Xiaoyu Cao, Hongbin Liu 等ICLR 2022 · 被引用 26 次
它引用的顶会 Paper12
- Certified Robustness to Adversarial Examples with Differential PrivacyMathias Lécuyer, Vaggelis Atlidakis, Roxana Geambasu, Daniel Hsu 等S&P 2019 · 被引用 1,022 次
- PointCloud Saliency MapsTianhang Zheng, Changyou Chen, Junsong Yuan, Bo Li 等ICCV 2019 · 被引用 265 次
- DUP-Net: Denoiser and Upsampler Network for 3D Adversarial Point Clouds DefenseHang Zhou, Kejiang Chen, Weiming Zhang, Han Fang 等ICCV 2019 · 被引用 206 次
- Robust Adversarial Objects against Deep Learning ModelsTzungyu Tsai, Kaichen Yang, Tsung-Yi Ho, Yier JinAAAI 2020 · 被引用 167 次
- Intrinsic Certified Robustness of Bagging against Data Poisoning AttacksJinyuan Jia, Xiaoyu Cao, Neil Zhenqiang GongAAAI 2021 · 被引用 155 次
相关 Paper
- PointCert: Point Cloud Classification with Deterministic Certified Robustness GuaranteesJinghuai Zhang, Jinyuan Jia, Hongbin Liu, Neil Zhenqiang GongCVPR 2023
- Certified L2-Norm Robustness of 3D Point Cloud Recognition in the Frequency DomainLiang Zhou, Qiming Wang, Tianze ChenAAAI 2026
- MultiGuard: Provably Robust Multi-label Classification against Adversarial ExamplesJinyuan Jia, Wenjie Qu, Neil Zhenqiang GongNeurIPS 2022 · 被引用 22 次
- CAP: Robust Point Cloud Classification via Semantic and Structural ModelingDaizong Ding, Erling Jiang, Yuanmin Huang, Mi Zhang 等CVPR 2023
- Efficient Joint Gradient Based Attack Against SOR Defense for 3D Point Cloud ClassificationChengcheng Ma, Weiliang Meng, Baoyuan Wu, Shibiao Xu 等ACM MM 2020 · 被引用 49 次
