Good Can Sometimes be Bad: A Unified Attack against 3D Point Cloud Classifier by a Flexible Isotropic Resampling
Linkun Fan, Jiahao Zhang, Juntao Zhang, Lei Zhang, Fazhi He, Daojun Han
摘要
To ensure the robustness of 3D point cloud Deep Neural Network(3D DNN), 3D adversarial attack targeting the inference stage and backdoor attack targeting the training stage are well studied. The success of both attacks usually requires a specified permissions that attacker must have. However, the obtainable permissions are uncertain due to the deployment environment changes in practical scenarios. This renders existing separately designed adversarial attack or backdoor attack ineffective. To solve this issue, this paper proposes a unified attack that can adapt to both 3D point cloud backdoor attack and adversarial attack, named UAtt3D. Furthermore, by observing existing attacks, their way to promise attack stealthiness is to limit the undesirable perturbation. This strategy requires moving the point position as little as possible, which restricts the attack intensity and is not suitable for our unified attack. Meanwhile, this strategy will inevitably cause a quality decrease on 3D point cloud due to the remaining malicious perturbation. Therefore, our UAtt3D explores a new avenue to guarantee attack stealthiness which improves the quality of attacked 3D point cloud rather than decreasing it. In detail, to simultaneously consider feature movement of adversarial attack and backdoor feature learning of backdoor attack, a flexible isotropic resampling is designed. It realigns the position of most points based on surface approximation and rays sampling. By fine tuning the resampled point cloud, adversarial point cloud and backdoored point cloud are obtained. Several experiments suggest that the proposed UAtt3D achieves outstanding stealthiness comparing with existing adversarial attacks and backdoor attacks from the subjective and objective perspective. Meanwhile, its attack efficiency is competitive.
问问这篇 Paper
智能体会读完全文。
Lune 把这篇 Paper 索引到了每一个公式,引用它的顶会 Paper 也一样。你提问,回答直接引用原文。
它引用的顶会 Paper18
- Revisiting Point Cloud Classification: A New Benchmark Dataset and Classification Model on Real-World DataMikaela Angelina Uy, Quang-Hieu Pham, Binh-Son Hua, Duc Thanh Nguyen 等ICCV 2019 · 被引用 1,003 次
- Walk in the Cloud: Learning Curves for Point Clouds Shape AnalysisTiange Xiang, Chaoyi Zhang, Yang Song, Jianhui Yu 等ICCV 2021 · 被引用 369 次
- Understanding and Improving Fast Adversarial TrainingMaksym Andriushchenko, Nicolas FlammarionNeurIPS 2020 · 被引用 366 次
- PointCloud Saliency MapsTianhang Zheng, Changyou Chen, Junsong Yuan, Bo Li 等ICCV 2019 · 被引用 265 次
- DUP-Net: Denoiser and Upsampler Network for 3D Adversarial Point Clouds DefenseHang Zhou, Kejiang Chen, Weiming Zhang, Han Fang 等ICCV 2019 · 被引用 206 次
相关 Paper
- PointBA: Towards Backdoor Attacks in 3D Point CloudXinke Li, Zhirui Chen, Yue Zhao, Zekun Tong 等ICCV 2021 · 被引用 62 次
- PointCRT: Detecting Backdoor in 3D Point Cloud via Corruption RobustnessShengshan Hu, Wei Liu, Minghui Li, Yechao Zhang 等ACM MM 2023 · 被引用 15 次
- Minimal Adversarial Examples for Deep Learning on 3D Point CloudsJaeyeon Kim, Binh-Son Hua, Duc Thanh Nguyen, Sai-Kit YeungICCV 2021 · 被引用 73 次
- A Backdoor Attack against 3D Point Cloud ClassifiersZhen Xiang, David J. Miller, Siheng Chen, Xi Li 等ICCV 2021 · 被引用 90 次
- On the Trade-off between Adversarial and Backdoor RobustnessCheng-Hsin Weng, Yan-Ting Lee, Shan-Hung WuNeurIPS 2020 · 被引用 70 次
