用扩散模型生成难察觉的3D点云对抗样本,提升黑盒攻击效果。
Generating Adversarial Point Clouds Using Diffusion Model
- 用3D扩散模型以点云压缩特征为先验,逆向生成对抗点。
- 在黑盒设置下攻击成功率显著提升,且扰动更难被察觉。
- 适用于评估自动驾驶等关键场景中点云模型的安全性。
针对3D点云分类模型的对抗攻击揭示了深度学习模型的潜在漏洞,可能在自动驾驶等关键应用中带来安全风险。现有对抗攻击方法多为白盒攻击,虽成功率高、扰动隐蔽,但实际应用受限;而黑盒攻击在真实场景中更贴近实际,但性能较差。本文提出一种新型黑盒对抗样本生成方法,利用3D扩散模型,在不依赖目标模型内部信息的前提下,通过点云压缩特征作为先验,引导反向扩散过程向干净样本添加对抗点。随后,利用反向过程将其他类别的分布转化为对抗点并注入点云,从而生成高效且隐蔽的对抗样本。
原文摘要 · Abstract (English)
Adversarial attack methods for 3D point cloud classification reveal the vulnerabilities of point cloud recognition models. This vulnerability could lead to safety risks in critical applications that use deep learning models, such as autonomous vehicles. To uncover the deficiencies of these models, researchers can evaluate their security through adversarial attacks. However, most existing adversarial attack methods are based on white-box attacks. While these methods achieve high attack success rates and imperceptibility, their applicability in real-world scenarios is limited. Black-box attacks, which are more meaningful in real-world scenarios, often yield poor results. This paper proposes a novel black-box adversarial example generation method that utilizes a diffusion model to improve the attack success rate and imperceptibility in the black-box setting, without relying on the internal information of the point cloud classification model to generate adversarial samples. We use a 3D diffusion model to use the compressed features of the point cloud as prior knowledge to guide the reverse diffusion process to add adversarial points to clean examples. Subsequently, its reverse process is employed to transform the distribution of other categories into adversarial points, which are then added to the point cloud.
Thank you to arXiv for use of its open access interoperability. PaperDance 不是 arXiv 官方产品;中文卡片由大模型生成,请以原文为准。