arXiv:2510.02314cs.CV2025-10ICCV被引 9

通过密度引导在3D高斯点云中植入隐蔽幻象,实现鲁棒的视觉欺骗攻击。

StealthAttack: Robust 3D Gaussian Splatting Poisoning via Density-Guided Illusions

  • 基于核密度估计定位低密度区,精准注入高斯点制造视点依赖幻觉
  • 攻击仅影响特定视角,对其他视角几乎无干扰,隐蔽性强
  • 提出评估协议,适用于未来对抗攻击研究,适合安全与防御方向学者

3D场景表示方法如神经辐射场(NeRF)和3D高斯喷溅(3DGS)显著推动了新视角合成的发展。随着这些方法日益普及,其安全性问题亟需关注。本文分析3DGS对图像级投毒攻击的脆弱性,并提出一种新的密度引导投毒方法。该方法通过核密度估计(KDE)识别低密度区域,战略性地注入高斯点,在被污染视角下嵌入视角依赖的幻觉物体,同时对无辜视角影响极小。此外,引入自适应噪声策略破坏多视角一致性,进一步提升攻击效果。本文还提出基于KDE的评估协议,系统化衡量攻击难度,为后续研究提供客观基准。大量实验表明,本方法优于现有最先进技术。

原文摘要 · Abstract (English)

3D scene representation methods like Neural Radiance Fields (NeRF) and 3D Gaussian Splatting (3DGS) have significantly advanced novel view synthesis. As these methods become prevalent, addressing their vulnerabilities becomes critical. We analyze 3DGS robustness against image-level poisoning attacks and propose a novel density-guided poisoning method. Our method strategically injects Gaussian points into low-density regions identified via Kernel Density Estimation (KDE), embedding viewpoint-dependent illusory objects clearly visible from poisoned views while minimally affecting innocent views. Additionally, we introduce an adaptive noise strategy to disrupt multi-view consistency, further enhancing attack effectiveness. We propose a KDE-based evaluation protocol to assess attack difficulty systematically, enabling objective benchmarking for future research. Extensive experiments demonstrate our method's superior performance compared to state-of-the-art techniques. Project page: https://hentci.github.io/stealthattack/

3D生成对抗攻击高斯喷溅

Thank you to arXiv for use of its open access interoperability. PaperDance 不是 arXiv 官方产品;中文卡片由大模型生成,请以原文为准。