NeRFool: Uncovering the Vulnerability of Generalizable Neural Radiance Fields against Adversarial Perturbations
Yonggan Fu, Ye Yuan, Souvik Kundu, Shang Wu, Shunyao Zhang, Yingyan Celine Lin
摘要
Generalizable Neural Radiance Fields (GNeRF) are one of the most promising real-world solutions for novel view synthesis, thanks to their cross-scene generalization capability and thus the possibility of instant rendering on new scenes. While adversarial robustness is essential for realworld applications, little study has been devoted to understanding its implication on GNeRF. We hypothesize that because GNeRF is implemented by conditioning on the source views from new scenes, which are often acquired from the Internet or third-party providers, there are potential new security concerns regarding its real-world applications. Meanwhile, existing understanding and solutions for neural networks' adversarial robustness may not be applicable to GNeRF, due to its 3D nature and uniquely diverse operations. To this end, we present NeRFool, which to the best of our knowledge is the first work that sets out to understand the adversarial robustness of GNeRF. Specifically, NeRFool unveils the vulnerability patterns and important insights regarding GNeRF's adversarial robustness. Built upon the above insights gained from NeRFool, we further develop NeRFool + , which integrates two techniques capable of effectively attacking GNeRF across a wide range of target views, and provide guidelines for defending against our proposed attacks. We believe that our NeRFool/NeRFool + lays the initial foundation for future innovations in developing robust realworld GNeRF solutions. Our codes are available at: https://github.com/GATECH-EIC/NeRFool .
问问这篇 Paper
智能体会读完全文。
Lune 把这篇 Paper 索引到了每一个公式,引用它的顶会 Paper 也一样。你提问,回答直接引用原文。
引用它的顶会 Paper6
- Geometry Cloak: Preventing TGS-based 3D Reconstruction from Copyrighted ImagesQi Song, Ziyuan Luo, Ka Chun Cheung, Simon See 等NeurIPS 2024 · 被引用 20 次
- StealthAttack: Robust 3D Gaussian Splatting Poisoning via Density-Guided IllusionsBo-Hsu Ke, You-Zhe Xie, Yu-Lun Liu, Wei-Chen ChiuICCV 2025 · 被引用 3 次
- PoInit-of-View: Poisoning Initialization of Views Transfers Across Multiple 3D Reconstruction SystemsWeijie Wang, Songlong Xing, Zhengyu Zhao, Nicu Sebe 等CVPR 2026 · 被引用 1 次
- WhisperSplat: Lossless Steganography in 3D Gaussian SplattingNicole Meng, Ronak Sahu, Miao Yin, Faysal Hossain Shezan 等ICML 2026
- Poison-splat: Computation Cost Attack on 3D Gaussian SplattingJiahao Lu, Yifan Zhang, Qiuhong Shen, Xinchao Wang 等ICLR 2025
它引用的顶会 Paper21
- Towards Evaluating the Robustness of Neural NetworksNicholas Carlini, David A. WagnerS&P 2017 · 被引用 9,786 次
- Fast is better than free: Revisiting adversarial trainingEric Wong, Leslie Rice, J. Zico KolterICLR 2020 · 被引用 1,352 次
- PlenOctrees for Real-time Rendering of Neural Radiance FieldsAlex Yu, Ruilong Li, Matthew Tancik, Hao Li 等ICCV 2021 · 被引用 1,284 次
- Overfitting in adversarially robust deep learningLeslie Rice, Eric Wong, J. Zico KolterICML 2020 · 被引用 935 次
- FastNeRF: High-Fidelity Neural Rendering at 200FPSStephan J. Garbin, Marek Kowalski, Matthew Johnson, Jamie Shotton 等ICCV 2021 · 被引用 778 次
相关 Paper
- Advancing Adversarial Robustness in GNeRFs: The IL2-NeRF AttackNicole Meng, Caleb Manicke, Ronak Sahu, Caiwen Ding 等CVPR 2025
- ViewFool: Evaluating the Robustness of Visual Recognition to Adversarial ViewpointsYinpeng Dong, Shouwei Ruan, Hang Su, Caixin Kang 等NeurIPS 2022 · 被引用 72 次
- GNeRF: GAN-based Neural Radiance Field without Posed CameraQuan Meng, Anpei Chen, Haimin Luo, Minye Wu 等ICCV 2021 · 被引用 222 次
- GeoNeRF: Generalizing NeRF with Geometry PriorsMohammad Mahdi Johari, Yann Lepoittevin, François FleuretCVPR 2022 · 被引用 154 次
- Gen-NeRF: Efficient and Generalizable Neural Radiance Fields via Algorithm-Hardware Co-DesignYonggan Fu, Zhifan Ye, Jiayi Yuan, Shunyao Zhang 等ISCA 2023 · 被引用 34 次
