首次系统梳理基于可微渲染的对抗攻击方法
RenderBender: A Survey on Adversarial Attacks Using Differentiable Rendering
- 构建统一框架整合多种攻击目标与场景操控方式
- 揭示现有研究在真实复杂场景中的防御短板
- 适合关注3D对抗攻击与可微渲染交叉领域的研究者
可微渲染技术如高斯溅射和神经辐射场,已成为生成高保真三维物体与场景模型的强大工具。其生成物理上合理且可微的场景模型的能力,是实现对深度神经网络产生物理可信对抗攻击的关键要素。然而,对抗机器学习领域尚未充分挖掘这一潜力,部分原因在于攻击目标(如误分类、误检测)多样,以及可实现目标的场景操控手段广泛(如改变纹理、网格)。本综述首次提出统一框架,整合不同攻击目标与任务,便于对比现有工作、识别研究空白,并指明未来方向——从拓展攻击目标与任务以适应新模态、前沿模型、工具与流程,到强调在复杂场景中研究真实世界威胁的重要性。
原文摘要 · Abstract (English)
Differentiable rendering techniques like Gaussian Splatting and Neural Radiance Fields have become powerful tools for generating high-fidelity models of 3D objects and scenes. Their ability to produce both physically plausible and differentiable models of scenes are key ingredient needed to produce physically plausible adversarial attacks on DNNs. However, the adversarial machine learning community has yet to fully explore these capabilities, partly due to differing attack goals (e.g., misclassification, misdetection) and a wide range of possible scene manipulations used to achieve them (e.g., alter texture, mesh). This survey contributes the first framework that unifies diverse goals and tasks, facilitating easy comparison of existing work, identifying research gaps, and highlighting future directions - ranging from expanding attack goals and tasks to account for new modalities, state-of-the-art models, tools, and pipelines, to underscoring the importance of studying real-world threats in complex scenes.
Thank you to arXiv for use of its open access interoperability. PaperDance 不是 arXiv 官方产品;中文卡片由大模型生成,请以原文为准。