arXiv:2508.11854cs.CVcs.LG2025-08被引 1

用3D高斯点云伪装图像,让物体只在特定角度被检测到,实现黑盒攻击。

ComplicitSplat: Downstream Models are Vulnerable to Blackbox Attacks by 3D Gaussian Splat Camouflages

  • 利用3D高斯渲染特性,生成视角依赖的伪装纹理。
  • 在真实与合成场景中成功攻击多种主流检测器。
  • 无需模型结构信息,适用于自动驾驶等关键系统。

随着3D高斯点云(3DGS)在安全关键任务中快速普及,用于从静态图像高效生成新视角,攻击者如何篡改图像造成危害?我们提出ComplicitSplat,首个利用标准3DGS着色方法生成视角特异性伪装的技术——即随视角变化的颜色与纹理,将对抗性内容嵌入场景物体中,仅在特定视角可见,且无需访问模型架构或权重。大量实验表明,该方法可泛化至多种主流检测器,包括单阶段、多阶段及基于Transformer的模型,在真实物理对象采集与合成场景中均有效。据我们所知,这是首个基于3DGS的黑盒下游目标检测器攻击,揭示了自动驾驶及其他关键机器人系统中的新型安全风险。

原文摘要 · Abstract (English)

As 3D Gaussian Splatting (3DGS) gains rapid adoption in safety-critical tasks for efficient novel-view synthesis from static images, how might an adversary tamper images to cause harm? We introduce ComplicitSplat, the first attack that exploits standard 3DGS shading methods to create viewpoint-specific camouflage - colors and textures that change with viewing angle - to embed adversarial content in scene objects that are visible only from specific viewpoints and without requiring access to model architecture or weights. Our extensive experiments show that ComplicitSplat generalizes to successfully attack a variety of popular detector - both single-stage, multi-stage, and transformer-based models on both real-world capture of physical objects and synthetic scenes. To our knowledge, this is the first black-box attack on downstream object detectors using 3DGS, exposing a novel safety risk for applications like autonomous navigation and other mission-critical robotic systems.

3D高斯黑盒攻击视觉安全

Thank you to arXiv for use of its open access interoperability. PaperDance 不是 arXiv 官方产品;中文卡片由大模型生成,请以原文为准。