PointBA: Towards Backdoor Attacks in 3D Point Cloud
Xinke Li, Zhirui Chen, Yue Zhao, Zekun Tong, Yabang Zhao, Andrew Lim, Joey Tianyi Zhou
摘要
3D deep learning has been increasingly more popular for a variety of tasks including many safety-critical applications. However, recently several works raise the security issues of 3D deep models. Although most of them consider adversarial attacks, we identify that backdoor attack is indeed a more serious threat to 3D deep learning systems but remains unexplored. We present the backdoor attacks in 3D point cloud with a unified framework that exploits the unique properties of 3D data and networks. In particular, we design two attack approaches on point cloud: the poison-label backdoor attack (PointPBA) and the clean- label backdoor attack (PointCBA). The first one is straight-forward and effective in practice, while the latter is more sophisticated assuming there are certain data inspections. The attack algorithms are mainly motivated and developed by 1) the recent discovery of 3D adversarial samples suggesting the vulnerability of deep models under spatial transformation; 2) the proposed feature disentanglement technique that manipulates the feature of the data through optimization methods and its potential to embed a new task. Extensive experiments show the efficacy of the PointPBA with over 95% success rate across various 3D datasets and models, and the more stealthy PointCBA with around 50% success rate. Our proposed backdoor attack in 3D point cloud is expected to perform as a baseline for improving the robustness of 3D deep models.
问问这篇 Paper
智能体会读完全文。
Lune 把这篇 Paper 索引到了每一个公式,引用它的顶会 Paper 也一样。你提问,回答直接引用原文。
引用它的顶会 Paper5
- Computation and Data Efficient Backdoor AttacksYutong Wu, Xingshuo Han, Han Qiu, Tianwei ZhangICCV 2023 · 被引用 17 次
- Fisher Information guided Purification against Backdoor AttacksNazmul Karim, Abdullah Al Arafat, Adnan Siraj Rakin, Zhishan Guo 等CCS 2024 · 被引用 4 次
- Influence-Based Fair Selection for Sample-Discriminative Backdoor AttackQi Wei, Shuo He, Jiahan Zhang, Lei Feng 等AAAI 2025 · 被引用 1 次
- Backdoor Attacks Against Deep Image Compression via Adaptive Frequency TriggerYi Yu, Yufei Wang, Wenhan Yang, Shijian Lu 等CVPR 2023
- MOBA: A Material-Oriented Backdoor Attack Against LiDAR-Based 3D Object Detection SystemsSaket Sanjeev Chaturvedi, Gaurav Bagwe, Lan Emily Zhang, Pan He 等AAAI 2026
它引用的顶会 Paper15
- Towards Evaluating the Robustness of Neural NetworksNicholas Carlini, David A. WagnerS&P 2017 · 被引用 9,786 次
- KPConv: Flexible and Deformable Convolution for Point CloudsHugues Thomas, Charles R. Qi, Jean-Emmanuel Deschaud, Beatriz Marcotegui 等ICCV 2019 · 被引用 3,193 次
- Hidden Trigger Backdoor AttacksAniruddha Saha, Akshayvarun Subramanya, Hamed PirsiavashAAAI 2020 · 被引用 743 次
- Blind Backdoors in Deep Learning ModelsEugene Bagdasaryan, Vitaly ShmatikovUSENIX Security 2021 · 被引用 372 次
- DensePoint: Learning Densely Contextual Representation for Efficient Point Cloud ProcessingYongcheng Liu, Bin Fan, Gaofeng Meng, Jiwen Lu 等ICCV 2019 · 被引用 295 次
相关 Paper
- A Backdoor Attack against 3D Point Cloud ClassifiersZhen Xiang, David J. Miller, Siheng Chen, Xi Li 等ICCV 2021 · 被引用 90 次
- Good Can Sometimes be Bad: A Unified Attack against 3D Point Cloud Classifier by a Flexible Isotropic ResamplingLinkun Fan, Jiahao Zhang, Juntao Zhang, Lei Zhang 等CVPR 2026
- PointCRT: Detecting Backdoor in 3D Point Cloud via Corruption RobustnessShengshan Hu, Wei Liu, Minghui Li, Yechao Zhang 等ACM MM 2023 · 被引用 15 次
- Minimal Adversarial Examples for Deep Learning on 3D Point CloudsJaeyeon Kim, Binh-Son Hua, Duc Thanh Nguyen, Sai-Kit YeungICCV 2021 · 被引用 73 次
- Seeing is Not Believing: Adversarial Natural Object Optimization for Hard-Label 3D Scene AttacksDaizong Liu, Wei HuCVPR 2025
