用单一扰动让3D物体识别系统误判,且视角不变。
Targeted View-Invariant Adversarial Perturbations for 3D Object Recognition
- 设计通用扰动,跨视角保持攻击效果。
- 定向攻击准确率超95%,在不同扰动强度下稳定。
- 适合测试3D识别系统的抗攻击能力。
对抗攻击对3D物体识别构成重大挑战,尤其在多视角分析场景中。本文提出视图不变对抗扰动(VIAP),一种可生成跨视角有效对抗样本的新方法。与传统方法不同,VIAP支持定向攻击,能将物体识别为预设目标类别,仅需单一通用扰动。基于包含121种不同渲染3D物体的1,210张图像的数据集,我们验证了VIAP在定向与非定向攻击中的有效性。非定向扰动成功生成对3D变换鲁棒的单一对抗噪声;定向攻击在多种ε值下达到超过95%的顶级分类准确率。结果表明,VIAP在实际应用中具有潜力,如测试3D识别系统的鲁棒性。该方法为视图不变对抗鲁棒性设立了新基准,推动了3D物体识别领域的对抗机器学习发展。
原文摘要 · Abstract (English)
Adversarial attacks pose significant challenges in 3D object recognition, especially in scenarios involving multi-view analysis where objects can be observed from varying angles. This paper introduces View-Invariant Adversarial Perturbations (VIAP), a novel method for crafting robust adversarial examples that remain effective across multiple viewpoints. Unlike traditional methods, VIAP enables targeted attacks capable of manipulating recognition systems to classify objects as specific, pre-determined labels, all while using a single universal perturbation. Leveraging a dataset of 1,210 images across 121 diverse rendered 3D objects, we demonstrate the effectiveness of VIAP in both targeted and untargeted settings. Our untargeted perturbations successfully generate a singular adversarial noise robust to 3D transformations, while targeted attacks achieve exceptional results, with top-1 accuracies exceeding 95% across various epsilon values. These findings highlight VIAPs potential for real-world applications, such as testing the robustness of 3D recognition systems. The proposed method sets a new benchmark for view-invariant adversarial robustness, advancing the field of adversarial machine learning for 3D object recognition.
Thank you to arXiv for use of its open access interoperability. PaperDance 不是 arXiv 官方产品;中文卡片由大模型生成,请以原文为准。