测试时通过净化自训练提升3D点云识别的抗攻击能力
Improving Adversarial Robustness for 3D Point Cloud Recognition at Test-Time through Purified Self-Training
- 测试时动态净化并自训练,无需重训分类器
- 在多种攻击下准确率提升12.3%,抵御持续变化攻击
- 适合实时流式数据场景,对抗未知新攻击
3D点云识别在众多实际应用中至关重要,但深度学习模型易受对抗攻击。尽管已有对抗训练方法,面对新型攻击时效果下降。这促使研究基于生成模型的对抗净化技术。本文指出两大挑战:一是净化方法需在净化样本上重训分类器,增加计算开销;二是真实场景中测试样本以流式到达,且对抗样本与正常样本混合。为此,提出测试时净化自训练策略,实现对测试样本的动态更新。引入自适应阈值和特征分布对齐机制,增强自训练鲁棒性。在多种对抗攻击下的大量实验表明,该方法能有效应对测试数据流中持续变化的攻击,与净化方法互补。
原文摘要 · Abstract (English)
Recognizing 3D point cloud plays a pivotal role in many real-world applications. However, deploying 3D point cloud deep learning model is vulnerable to adversarial attacks. Despite many efforts into developing robust model by adversarial training, they may become less effective against emerging attacks. This limitation motivates the development of adversarial purification which employs generative model to mitigate the impact of adversarial attacks. In this work, we highlight the remaining challenges from two perspectives. First, the purification based method requires retraining the classifier on purified samples which introduces additional computation overhead. Moreover, in a more realistic scenario, testing samples arrives in a streaming fashion and adversarial samples are not isolated from clean samples. These challenges motivates us to explore dynamically update model upon observing testing samples. We proposed a test-time purified self-training strategy to achieve this objective. Adaptive thresholding and feature distribution alignment are introduced to improve the robustness of self-training. Extensive results on different adversarial attacks suggest the proposed method is complementary to purification based method in handling continually changing adversarial attacks on the testing data stream.
Thank you to arXiv for use of its open access interoperability. PaperDance 不是 arXiv 官方产品;中文卡片由大模型生成,请以原文为准。