通过点到表面场提升点云攻击的隐蔽性,让干扰更难被察觉。
Imperceptible Adversarial Attacks on Point Clouds Guided by Point-to-Surface Field
- 利用点到表面场引导扰动方向,使点回溯至原始表面。
- 在多个数据集上实现更强隐蔽性,攻击效果优于现有方法。
- 适合研究3D模型鲁棒性或对抗攻击的开发者参考。
点云的对抗攻击对评估和提升三维深度学习模型的抗干扰能力至关重要。传统方法严格限制点的位移,难以平衡隐蔽性与攻击有效性。本文认为点云对抗攻击隐蔽性不足源于点偏离原始表面,为此提出一种新颖的点到表面(P2S)场,通过将点拉回原始表面来调整扰动方向。具体地,使用去噪网络学习编码形状表面的对数密度函数梯度场,并在攻击中引入距离感知的扰动方向调整,从而增强隐蔽性。大量实验表明,基于P2S场的攻击更具隐蔽性,性能超越当前最优方法。
原文摘要 · Abstract (English)
Adversarial attacks on point clouds are crucial for assessing and improving the adversarial robustness of 3D deep learning models. Traditional solutions strictly limit point displacement during attacks, making it challenging to balance imperceptibility with adversarial effectiveness. In this paper, we attribute the inadequate imperceptibility of adversarial attacks on point clouds to deviations from the underlying surface. To address this, we introduce a novel point-to-surface (P2S) field that adjusts adversarial perturbation directions by dragging points back to their original underlying surface. Specifically, we use a denoising network to learn the gradient field of the logarithmic density function encoding the shape's surface, and apply a distance-aware adjustment to perturbation directions during attacks, thereby enhancing imperceptibility. Extensive experiments show that adversarial attacks guided by our P2S field are more imperceptible, outperforming state-of-the-art methods.
Thank you to arXiv for use of its open access interoperability. PaperDance 不是 arXiv 官方产品;中文卡片由大模型生成,请以原文为准。