提出首个防御3D高斯溅射计算攻击的完整框架,保护重建系统安全
RemedyGS: Defend 3D Gaussian Splatting against Computation Cost Attacks
- 通过检测器识别污染纹理输入,用净化器恢复原始图像
- 在多种攻击下保持高防御效果,修复后图像与原图分布接近
- 适合部署在依赖3DGS的云服务或实时重建系统中
作为主流3D重建技术,3D高斯溅射(3DGS)已广泛应用于各类场景。近期研究揭示其存在严重漏洞,攻击者可通过计算成本攻击引发资源滥用甚至拒绝服务,阻碍3DGS的可靠部署。本文提出首个有效且全面的黑盒防御框架RemedyGS,以保护3DGS重建系统与服务。该框架包含两个核心组件:检测器用于识别携带污染纹理的攻击输入图像,净化器则从被攻击图像中恢复出良性图像,缓解攻击影响。此外,我们在净化器中引入对抗训练,强制恢复图像与原始自然图像在分布上对齐,从而提升防御性能。实验表明,该框架在白盒、黑盒及自适应攻击下均表现出色,兼顾安全性与重建质量,达到当前最优水平。
原文摘要 · Abstract (English)
As a mainstream technique for 3D reconstruction, 3D Gaussian splatting (3DGS) has been applied in a wide range of applications and services. Recent studies have revealed critical vulnerabilities in this pipeline and introduced computation cost attacks that lead to malicious resource occupancies and even denial-of-service (DoS) conditions, thereby hindering the reliable deployment of 3DGS. In this paper, we propose the first effective and comprehensive black-box defense framework, named RemedyGS, against such computation cost attacks, safeguarding 3DGS reconstruction systems and services. Our pipeline comprises two key components: a detector to identify the attacked input images with poisoned textures and a purifier to recover the benign images from their attacked counterparts, mitigating the adverse effects of these attacks. Moreover, we incorporate adversarial training into the purifier to enforce distributional alignment between the recovered and original natural images, thereby enhancing the defense efficacy. Experimental results demonstrate that our framework effectively defends against white-box, black-box, and adaptive attacks in 3DGS systems, achieving state-of-the-art performance in both safety and utility.
Thank you to arXiv for use of its open access interoperability. PaperDance 不是 arXiv 官方产品;中文卡片由大模型生成,请以原文为准。