首次揭示3D高斯溅射场景中的隐蔽后门攻击,可诱导导航误判。
GaussTrap: Stealthy Poisoning Attacks on 3D Gaussian Splatting for Targeted Scene Confusion
- 在特定视角注入恶意渲染,其他视角保持高质量
- 攻击后门不可察觉,但触发时导致场景混淆
- 适合关注3D视觉安全的自动驾驶与元宇宙开发者
随着3D高斯溅射(3DGS)在场景建模与新视角合成中取得突破,其在自动驾驶、增强现实等安全关键领域的快速应用迫切需要评估潜在安全风险。本文首次系统研究了3DGS管道中的后门威胁,发现攻击者可在推理阶段植入恶意视图,引发环境误判或空间失真。为此,提出GuassTrap——一种针对3DGS的隐蔽污染攻击方法。该方法通过三阶段流程(攻击、稳定、正常训练),在特定攻击视角注入隐蔽且视角一致的恶意渲染,同时在非目标视角保持高质量输出,实现攻击效果与感知真实性的联合优化。在合成与真实数据集上的大量实验表明,GuassTrap可有效嵌入难以察觉但有害的后门视图,同时维持正常视图的高质量渲染,验证了其鲁棒性、适应性与实用性。
原文摘要 · Abstract (English)
As 3D Gaussian Splatting (3DGS) emerges as a breakthrough in scene representation and novel view synthesis, its rapid adoption in safety-critical domains (e.g., autonomous systems, AR/VR) urgently demands scrutiny of potential security vulnerabilities. This paper presents the first systematic study of backdoor threats in 3DGS pipelines. We identify that adversaries may implant backdoor views to induce malicious scene confusion during inference, potentially leading to environmental misperception in autonomous navigation or spatial distortion in immersive environments. To uncover this risk, we propose GuassTrap, a novel poisoning attack method targeting 3DGS models. GuassTrap injects malicious views at specific attack viewpoints while preserving high-quality rendering in non-target views, ensuring minimal detectability and maximizing potential harm. Specifically, the proposed method consists of a three-stage pipeline (attack, stabilization, and normal training) to implant stealthy, viewpoint-consistent poisoned renderings in 3DGS, jointly optimizing attack efficacy and perceptual realism to expose security risks in 3D rendering. Extensive experiments on both synthetic and real-world datasets demonstrate that GuassTrap can effectively embed imperceptible yet harmful backdoor views while maintaining high-quality rendering in normal views, validating its robustness, adaptability, and practical applicability.
Thank you to arXiv for use of its open access interoperability. PaperDance 不是 arXiv 官方产品;中文卡片由大模型生成,请以原文为准。