首次利用视角依赖的高斯外观植入隐蔽攻击,威胁自动驾驶等安全应用。
3D Gaussian Splat Vulnerabilities
- 利用视角变化的高斯颜色纹理嵌入恶意内容,仅特定角度可见。
- 无需训练数据,直接扰动3D高斯点,欺骗多阶段目标检测器。
- 揭示3DGS在自动驾驶中的新风险,适合关注三维场景安全的研究者。
随着3D高斯泼溅(3DGS)在安全关键应用中日益普及,攻击者如何操纵场景造成危害?我们提出CLOAK,首个利用视角依赖的高斯外观——随视角变化的颜色与纹理——来嵌入仅从特定视角可见的对抗性内容的攻击方法。我们进一步演示了DAGGER,一种无需访问底层训练数据的定向对抗攻击,通过投影梯度下降直接扰动3D高斯点,欺骗多阶段目标检测器(如Faster R-CNN)。这些攻击揭示了3DGS中未被充分探索的漏洞,为机器人学习在自主导航及其他安全关键3DGS应用中引入了新的潜在威胁。
原文摘要 · Abstract (English)
With 3D Gaussian Splatting (3DGS) being increasingly used in safety-critical applications, how can an adversary manipulate the scene to cause harm? We introduce CLOAK, the first attack that leverages view-dependent Gaussian appearances - colors and textures that change with viewing angle - to embed adversarial content visible only from specific viewpoints. We further demonstrate DAGGER, a targeted adversarial attack directly perturbing 3D Gaussians without access to underlying training data, deceiving multi-stage object detectors e.g., Faster R-CNN, through established methods such as projected gradient descent. These attacks highlight underexplored vulnerabilities in 3DGS, introducing a new potential threat to robotic learning for autonomous navigation and other safety-critical 3DGS applications.
Thank you to arXiv for use of its open access interoperability. PaperDance 不是 arXiv 官方产品;中文卡片由大模型生成,请以原文为准。