arXiv:2507.00690cs.CVcs.CR2025-07被引 2

用笼形结构生成自然的3D点云对抗样本,提升攻击效果与隐蔽性。

Cage-Based Deformation for Transferable and Undefendable Point Cloud Attack

  • 基于笼形结构对点云进行有约束的变形,保证自然性。
  • 在三个数据集上实现更强的迁移性与抗防御能力。
  • 适合研究3D深度学习安全或对抗攻击的读者。

点云对抗攻击通常需满足严格的几何约束以保持合理性,但这类约束会限制攻击的迁移性和抗防御能力。尽管变形方法可作为替代方案,但现有无结构方法可能引入不自然扭曲,使对抗点云显得突兀,损害其合理性。本文提出CageAttack,一种基于笼形结构的变形框架,能生成自然的对抗点云。该方法先在目标物体周围构建笼形结构,为平滑、自然的变形提供结构基础;随后对笼形顶点施加扰动,扰动无缝传播至点云,确保变形始终符合物体内在属性并维持合理性。在三个数据集上的七个3D深度神经网络分类器上进行的大量实验表明,CageAttack在迁移性、抗防御性和合理性之间实现了更优平衡,优于当前最先进方法。代码将在接受后公开。

原文摘要 · Abstract (English)

Adversarial attacks on point clouds often impose strict geometric constraints to preserve plausibility; however, such constraints inherently limit transferability and undefendability. While deformation offers an alternative, existing unstructured approaches may introduce unnatural distortions, making adversarial point clouds conspicuous and undermining their plausibility. In this paper, we propose CageAttack, a cage-based deformation framework that produces natural adversarial point clouds. It first constructs a cage around the target object, providing a structured basis for smooth, natural-looking deformation. Perturbations are then applied to the cage vertices, which seamlessly propagate to the point cloud, ensuring that the resulting deformations remain intrinsic to the object and preserve plausibility. Extensive experiments on seven 3D deep neural network classifiers across three datasets show that CageAttack achieves a superior balance among transferability, undefendability, and plausibility, outperforming state-of-the-art methods. Codes will be made public upon acceptance.

点云攻击对抗样本3D安全

Thank you to arXiv for use of its open access interoperability. PaperDance 不是 arXiv 官方产品;中文卡片由大模型生成,请以原文为准。