针对6自由度姿态估计的后门攻击,用3D触发器精准操控物体位置和朝向。
6DAttack: Backdoor Attacks in the 6DoF Pose Estimation
- 设计3D物体触发器,实现对连续位姿参数的精准控制。
- 攻击成功率高达100%,且干净样本准确率仍保持在100%。
- 现有防御方法无效,适用于机器人与自动驾驶等高危场景。
深度学习推动了六自由度(6DoF)物体姿态估计的发展,广泛应用于机器人、增强现实/虚拟现实及自动驾驶系统。然而,后门攻击带来了严重安全风险。尽管多数研究聚焦于2D视觉任务,6DoF姿态估计仍缺乏探索。不同于仅改变类别的传统后门,6DoF攻击需控制连续的平移与旋转参数,使2D方法失效。本文提出6DAttack框架,采用3D物体触发器诱导可控错误姿态,同时保持正常行为。在PVNet、DenseFusion和PoseDiffusion模型上,基于LINEMOD、YCB-Video和CO3D数据集的评估显示,攻击成功率(ASR)极高,且干净性能不受影响。后门模型达到最高100%的清洁ADD准确率和100%的ASR,触发样本的ADD-P达97.70%。此外,一种代表性防御方法仍无法有效应对。研究揭示了6DoF姿态估计中一个严重且被忽视的安全威胁。
原文摘要 · Abstract (English)
Deep learning advances have enabled accurate six-degree-of-freedom (6DoF) object pose estimation, widely used in robotics, AR/VR, and autonomous systems. However, backdoor attacks pose significant security risks. While most research focuses on 2D vision, 6DoF pose estimation remains largely unexplored. Unlike traditional backdoors that only change classes, 6DoF attacks must control continuous parameters like translation and rotation, rendering 2D methods inapplicable. We propose 6DAttack, a framework using 3D object triggers to induce controlled erroneous poses while maintaining normal behavior. Evaluations on PVNet, DenseFusion, and PoseDiffusion across LINEMOD, YCB-Video, and CO3D show high attack success rates (ASRs) without compromising clean performance. Backdoored models achieve up to 100% clean ADD accuracy and 100% ASR, with triggered samples reaching 97.70% ADD-P. Furthermore, a representative defense remains ineffective. Our findings reveal a serious, underexplored threat to 6DoF pose estimation.
Thank you to arXiv for use of its open access interoperability. PaperDance 不是 arXiv 官方产品;中文卡片由大模型生成,请以原文为准。