arXiv:2412.02803cs.CVcs.AI2024-12中稿 · NeurIPS被引 14

针对3D高斯点云模型,提出隐蔽对抗噪声攻击方法。

Gaussian Splatting Under Attack: Investigating Adversarial Noise in 3D Objects

  • 设计掩码迭代FGSM方法,聚焦目标区域注入对抗噪声
  • 使CLIP模型在3D物体识别准确率从95.4%降至12.5%
  • 攻击几乎不可见,适用于自动驾驶等高危场景

3D高斯点云已推动辐射场重建发展,实现高质量视图合成与快速渲染。尽管2D图像上的对抗攻击研究成熟,但对3D模型的影响仍待探索。本文提出掩码迭代快速梯度符号法(M-IFGSM),专门针对CLIP视觉语言模型生成对抗噪声,通过聚焦遮蔽区域的扰动,破坏其零样本物体检测能力。基于Common Objects 3D(CO3D)数据集中的8个物体,实验显示该方法显著降低模型准确率与置信度:训练图像的top-1准确率由95.4%降至12.5%,测试图像由91.2%降至35.4%。对抗噪声对人眼近乎不可察觉,凸显3D模型在自动驾驶、机器人和监控等关键应用中的安全风险。本研究揭示了现代3D视觉模型(包括辐射场)的脆弱性,推动更鲁棒防御机制的发展。

原文摘要 · Abstract (English)

3D Gaussian Splatting has advanced radiance field reconstruction, enabling high-quality view synthesis and fast rendering in 3D modeling. While adversarial attacks on object detection models are well-studied for 2D images, their impact on 3D models remains underexplored. This work introduces the Masked Iterative Fast Gradient Sign Method (M-IFGSM), designed to generate adversarial noise targeting the CLIP vision-language model. M-IFGSM specifically alters the object of interest by focusing perturbations on masked regions, degrading the performance of CLIP's zero-shot object detection capability when applied to 3D models. Using eight objects from the Common Objects 3D (CO3D) dataset, we demonstrate that our method effectively reduces the accuracy and confidence of the model, with adversarial noise being nearly imperceptible to human observers. The top-1 accuracy in original model renders drops from 95.4\% to 12.5\% for train images and from 91.2\% to 35.4\% for test images, with confidence levels reflecting this shift from true classification to misclassification, underscoring the risks of adversarial attacks on 3D models in applications such as autonomous driving, robotics, and surveillance. The significance of this research lies in its potential to expose vulnerabilities in modern 3D vision models, including radiance fields, prompting the development of more robust defenses and security measures in critical real-world applications.

3D安全对抗攻击高斯点云

Thank you to arXiv for use of its open access interoperability. PaperDance 不是 arXiv 官方产品;中文卡片由大模型生成,请以原文为准。