PointCA: Evaluating the Robustness of 3D Point Cloud Completion Models against Adversarial Examples
Shengshan Hu, Junwei Zhang, Wei Liu, Junhui Hou, Minghui Li, Leo Yu Zhang, Hai Jin, Lichao Sun
摘要
Point cloud completion, as the upstream procedure of 3D recognition and segmentation, has become an essential part of many tasks such as navigation and scene understanding. While various point cloud completion models have demonstrated their powerful capabilities, their robustness against adversarial attacks, which have been proven to be fatally malicious towards deep neural networks, remains unknown. In addition, existing attack approaches towards point cloud classifiers cannot be applied to the completion models due to different output forms and attack purposes. In order to evaluate the robustness of the completion models, we propose PointCA, the first adversarial attack against 3D point cloud completion models. PointCA can generate adversarial point clouds that maintain high similarity with the original ones, while being completed as another object with totally different semantic information. Specifically, we minimize the representation discrepancy between the adversarial example and the target point set to jointly explore the adversarial point clouds in the geometry space and the feature space. Furthermore, to launch a stealthier attack, we innovatively employ the neighbourhood density information to tailor the perturbation constraint, leading to geometry-aware and distribution-adaptive modifications for each point. Extensive experiments against different premier point cloud completion networks show that PointCA can cause the performance degradation from 77.9% to 16.7%, with the structure chamfer distance kept below 0.01. We conclude that existing completion models are severely vulnerable to adversarial examples, and state-of-the-art defenses for point cloud classification will be partially invalid when applied to incomplete and uneven point cloud data.
问问这篇 Paper
智能体会读完全文。
Lune 把这篇 Paper 索引到了每一个公式,引用它的顶会 Paper 也一样。你提问,回答直接引用原文。
引用它的顶会 Paper2
- AdvCLIP: Downstream-agnostic Adversarial Examples in Multimodal Contrastive LearningZiqi Zhou, Shengshan Hu, Minghui Li, Hangtao Zhang 等ACM MM 2023 · 被引用 62 次
- Securely Fine-tuning Pre-trained Encoders Against Adversarial ExamplesZiqi Zhou, Minghui Li, Wei Liu, Shengshan Hu 等S&P 2024 · 被引用 23 次
它引用的顶会 Paper19
- Towards Evaluating the Robustness of Neural NetworksNicholas Carlini, David A. WagnerS&P 2017 · 被引用 9,786 次
- PoinTr: Diverse Point Cloud Completion with Geometry-Aware TransformersXumin Yu, Yongming Rao, Ziyi Wang, Zuyan Liu 等ICCV 2021 · 被引用 592 次
- Unsupervised Point Cloud Pre-training via Occlusion CompletionHanchen Wang, Qi Liu, Xiangyu Yue, Joan Lasenby 等ICCV 2021 · 被引用 323 次
- DUP-Net: Denoiser and Upsampler Network for 3D Adversarial Point Clouds DefenseHang Zhou, Kejiang Chen, Weiming Zhang, Han Fang 等ICCV 2019 · 被引用 206 次
- Protecting Facial Privacy: Generating Adversarial Identity Masks via Style-robust Makeup TransferShengshan Hu, Xiaogeng Liu, Yechao Zhang, Minghui Li 等CVPR 2022 · 被引用 123 次
相关 Paper
- Minimal Adversarial Examples for Deep Learning on 3D Point CloudsJaeyeon Kim, Binh-Son Hua, Duc Thanh Nguyen, Sai-Kit YeungICCV 2021 · 被引用 73 次
- Robust Adversarial Objects against Deep Learning ModelsTzungyu Tsai, Kaichen Yang, Tsung-Yi Ho, Yier JinAAAI 2020 · 被引用 167 次
- CausalPC: Improving the Robustness of Point Cloud Classification by Causal Effect IdentificationYuanmin Huang, Mi Zhang, Daizong Ding, Erling Jiang 等CVPR 2024
- SymAttack: Symmetry-aware Imperceptible Adversarial Attacks on 3D Point CloudsKeke Tang, Zhensu Wang, Weilong Peng, Lujie Huang 等ACM MM 2024 · 被引用 10 次
- Benchmarking and Analyzing Robust Point Cloud Recognition: Bag of Tricks for Defending Adversarial ExamplesQiufan Ji, Lin Wang, Cong Shi, Shengshan Hu 等ICCV 2023 · 被引用 9 次
