通过扰动中轴变换增强点云攻击的迁移性与抗防御能力
Transferable and Undefendable Point Cloud Attacks via Medial Axis Transform
- 基于中轴变换表示,从几何结构层面生成对抗性扰动
- 在多个模型和防御策略下保持高攻击成功率,超越现有方法
- 适合研究3D模型鲁棒性或设计更强对抗样本的研究者
研究点云的对抗攻击对评估和提升3D深度学习模型的鲁棒性至关重要。然而,大多数现有攻击方法在理想白盒条件下设计,往往在未见模型间转移性有限,且对常见防御机制缺乏抵抗力。本文提出MAT-Adv,一种新型对抗攻击框架,通过显式扰动中轴变换(MAT)表示来增强攻击的迁移性和抗防御能力,从而在生成的点云中引入固有的对抗特性。具体而言,我们使用自编码器将输入点云投影到紧凑的MAT表示中,以捕捉点云的内在几何结构。通过对这些内在表示进行扰动,MAT-Adv引入了跨模型和防御策略仍有效的结构性对抗特征。为缓解过拟合和防止扰动坍塌,我们在优化过程中引入了丢弃策略,进一步提升了迁移性和抗防御能力。大量实验表明,MAT-Adv在迁移性和抗防御能力方面显著优于现有最先进方法。代码将在论文接受后公开。
原文摘要 · Abstract (English)
Studying adversarial attacks on point clouds is essential for evaluating and improving the robustness of 3D deep learning models. However, most existing attack methods are developed under ideal white-box settings and often suffer from limited transferability to unseen models and insufficient robustness against common defense mechanisms. In this paper, we propose MAT-Adv, a novel adversarial attack framework that enhances both transferability and undefendability by explicitly perturbing the medial axis transform (MAT) representations, in order to induce inherent adversarialness in the resulting point clouds. Specifically, we employ an autoencoder to project input point clouds into compact MAT representations that capture the intrinsic geometric structure of point clouds. By perturbing these intrinsic representations, MAT-Adv introduces structural-level adversarial characteristics that remain effective across diverse models and defense strategies. To mitigate overfitting and prevent perturbation collapse, we incorporate a dropout strategy into the optimization of MAT perturbations, further improving transferability and undefendability. Extensive experiments demonstrate that MAT-Adv significantly outperforms existing state-of-the-art methods in both transferability and undefendability. Codes will be made public upon paper acceptance.
Thank you to arXiv for use of its open access interoperability. PaperDance 不是 arXiv 官方产品;中文卡片由大模型生成,请以原文为准。