首个实现3D点云多目标后门攻击的方法,用球形触发器统一控制多个目标
STONE: Pioneering the One-to-N Universal Backdoor Threat in 3D Point Cloud
- 设计可配置的球形触发器,通过参数化空间属性实现一触多控
- 在黑盒和脏标签条件下攻击成功率最高达100%,且不影响正常数据准确率
- 首次提供3D模型中多目标后门的理论基础,适合安全与防御研究者
后门攻击对深度学习构成严重威胁,尤其在自动驾驶和机器人等高安全性3D领域。现有针对3D点云的攻击大多局限于一对一模式,而更灵活通用的一对多(one-to-N)多目标后门威胁尚未被充分探索,缺乏理论与实践基础。为此,我们提出STONE(Spherical Trigger One-to-N universal backdoor Enabling),首个通过可配置球形触发器实现该威胁的方法。其参数化的空间属性构建动态密钥空间,使单个触发器可映射至多个目标标签。理论上,我们基于神经正切核(NTK)分析,首次为3D模型中的一对多映射提供了形式化基础。实证上,大量评估显示攻击成功率高达100%,且不损害干净数据准确性。本工作建立了3D视觉中脏标签与黑盒场景下多目标后门威胁的基础基准,是保障未来智能系统安全的关键一步。
原文摘要 · Abstract (English)
Backdoor attacks pose a critical threat to deep learning, especially in safety-sensitive 3D domains such as autonomous driving and robotics. While potent, existing attacks on 3D point clouds are predominantly limited to one-to-one paradigms. The more flexible and universal one-to-N multi-target backdoor threat remains largely unexplored, lacking both theoretical and practical foundations. To bridge this gap, we propose STONE (Spherical Trigger One-to-N universal backdoor Enabling), the first method to instantiate this threat via a configurable spherical trigger design. Its parameterized spatial properties establish a dynamic key space, enabling a single trigger to map to multiple target labels. Theoretically, we ground STONE in a Neural Tangent Kernel (NTK) analysis, providing the first formal basis for one-to-N mappings in 3D models. Empirically, extensive evaluations demonstrate high attack success rates (up to 100\%) without compromising clean-data accuracy. This work establishes a foundational benchmark for multi-target backdoor threats under dirty-label and black-box settings in 3D vision -- a crucial step toward securing future intelligent systems.
Thank you to arXiv for use of its open access interoperability. PaperDance 不是 arXiv 官方产品;中文卡片由大模型生成,请以原文为准。