DUP-Net: Denoiser and Upsampler Network for 3D Adversarial Point Clouds Defense
Hang Zhou, Kejiang Chen, Weiming Zhang, Han Fang, Wenbo Zhou, Nenghai Yu
摘要
Neural networks are vulnerable to adversarial examples, which poses a threat to their application in security sensitive systems. We propose a Denoiser and UPsampler Network (DUP-Net) structure as defenses for 3D adversarial point cloud classification, where the two modules reconstruct surface smoothness by dropping or adding points. In this paper, statistical outlier removal (SOR) and a data-driven upsampling network are considered as denoiser and upsampler respectively. Compared with baseline defenses, DUP-Net has three advantages. First, with DUP-Net as a defense, the target model is more robust to white-box adversarial attacks. Second, the statistical outlier removal provides added robustness since it is a non-differentiable denoising operation. Third, the upsampler network can be trained on a small dataset and defends well against adversarial attacks generated from other point cloud datasets. We conduct various experiments to validate that DUP-Net is very effective as defense in practice. Our best defense eliminates 83.8% of C&W and l2 loss based attack (point shifting), 50.0% of C&W and Hausdorff distance loss based attack (point adding) and 9.0% of saliency map based attack (point dropping) under 200 dropped points on PointNet.
问问这篇 Paper
智能体会读完全文。
Lune 把这篇 Paper 索引到了每一个公式,引用它的顶会 Paper 也一样。你提问,回答直接引用原文。
引用它的顶会 Paper39
- Robust Adversarial Objects against Deep Learning ModelsTzungyu Tsai, Kaichen Yang, Tsung-Yi Ho, Yier JinAAAI 2020 · 被引用 167 次
- Shape-invariant 3D Adversarial Point CloudsQidong Huang, Xiaoyi Dong, Dongdong Chen, Hang Zhou 等CVPR 2022 · 被引用 88 次
- Minimal Adversarial Examples for Deep Learning on 3D Point CloudsJaeyeon Kim, Binh-Son Hua, Duc Thanh Nguyen, Sai-Kit YeungICCV 2021 · 被引用 73 次
- Adversarially Robust 3D Point Cloud Recognition Using Self-SupervisionsJiachen Sun, Yulong Cao, Christopher B. Choy, Zhiding Yu 等NeurIPS 2021 · 被引用 64 次
- PointBA: Towards Backdoor Attacks in 3D Point CloudXinke Li, Zhirui Chen, Yue Zhao, Zekun Tong 等ICCV 2021 · 被引用 62 次
它引用的顶会 Paper2
相关 Paper
- Efficient Joint Gradient Based Attack Against SOR Defense for 3D Point Cloud ClassificationChengcheng Ma, Weiliang Meng, Baoyuan Wu, Shibiao Xu 等ACM MM 2020 · 被引用 49 次
- PointGuard: Provably Robust 3D Point Cloud ClassificationHongbin Liu, Jinyuan Jia, Neil Zhenqiang GongCVPR 2021
- CAP: Robust Point Cloud Classification via Semantic and Structural ModelingDaizong Ding, Erling Jiang, Yuanmin Huang, Mi Zhang 等CVPR 2023
- Benchmarking and Analyzing Robust Point Cloud Recognition: Bag of Tricks for Defending Adversarial ExamplesQiufan Ji, Lin Wang, Cong Shi, Shengshan Hu 等ICCV 2023 · 被引用 9 次
- Robust Structured Declarative Classifiers for 3D Point Clouds: Defending Adversarial Attacks with Implicit GradientsKaidong Li, Ziming Zhang, Cuncong Zhong, Guanghui WangCVPR 2022 · 被引用 24 次
