针对3D点云分割中源域被攻击的问题,提出抗干扰自适应框架。
Robust Unsupervised Domain Adaptation for 3D Point Cloud Segmentation Under Source Adversarial Attacks
- 设计隐蔽对抗攻击生成污染点云,构造新数据集AdvSynLiDAR
- 引入鲁棒长尾损失与解码分支,提升对少数类的建模能力
- 在对抗污染源域下仍保持高精度,适合鲁棒点云分割场景
无监督域适应(UDA)框架在干净数据上表现出良好泛化能力,但现有方法忽略了源域本身被攻击时的鲁棒性问题。为此,我们设计了一种隐蔽的对抗点云生成攻击,在仅对点云表面施加微小扰动的情况下即可显著污染数据集。基于此,构建了包含合成污染激光雷达点云的新数据集AdvSynLiDAR。进一步提出对抗适应框架(AAF),通过将关键点敏感损失扩展为鲁棒长尾损失(RLT损失),并引入解码分支,使模型在预训练阶段关注长尾类别,并在适配阶段利用高置信度解码信息恢复点云结构。在AdvSynLiDAR数据集上的评估表明,本方法能有效缓解源域受对抗扰动时的性能下降,提升3D点云语义分割中无监督域适应的鲁棒性。
原文摘要 · Abstract (English)
Unsupervised domain adaptation (UDA) frameworks have shown good generalization capabilities for 3D point cloud semantic segmentation models on clean data. However, existing works overlook adversarial robustness when the source domain itself is compromised. To comprehensively explore the robustness of the UDA frameworks, we first design a stealthy adversarial point cloud generation attack that can significantly contaminate datasets with only minor perturbations to the point cloud surface. Based on that, we propose a novel dataset, AdvSynLiDAR, comprising synthesized contaminated LiDAR point clouds. With the generated corrupted data, we further develop the Adversarial Adaptation Framework (AAF) as the countermeasure. Specifically, by extending the key point sensitive (KPS) loss towards the Robust Long-Tail loss (RLT loss) and utilizing a decoder branch, our approach enables the model to focus on long-tail classes during the pre-training phase and leverages high-confidence decoded point cloud information to restore point cloud structures during the adaptation phase. We evaluated our AAF method on the AdvSynLiDAR dataset, where the results demonstrate that our AAF method can mitigate performance degradation under source adversarial perturbations for UDA in the 3D point cloud segmentation application.
Thank you to arXiv for use of its open access interoperability. PaperDance 不是 arXiv 官方产品;中文卡片由大模型生成,请以原文为准。