首次系统研究3D视觉语言模型的对抗鲁棒性,发现其易受无目标攻击但对有目标攻击较敏感。
On the Adversarial Robustness of 3D Large Vision-Language Models
- 提出两种攻击策略:视觉特征扰动与输出序列篡改,评估多维度鲁棒性。
- 3D VLM在无目标攻击下显著脆弱,但比2D模型更难被诱导生成有害输出。
- 研究揭示3D模型安全风险,适用于高安全性场景部署前的可靠性评估。
3D视觉语言模型(如PointLLM和GPT4Point)在3D理解任务中展现出强大的推理与泛化能力,但其对抗鲁棒性仍缺乏研究。已有2D VLM研究表明,视觉输入融合会显著增加模型对对抗攻击的脆弱性,导致生成有毒或误导性输出。本文首次对基于点云的3D VLMs开展系统性对抗鲁棒性研究,提出两种互补攻击策略: - 视觉攻击(Vision Attack):扰动3D编码器与投影器生成的视觉标记特征,评估视觉-语言对齐的鲁棒性; - 标题攻击(Caption Attack):直接操纵输出标记序列,评估端到端系统的鲁棒性。 每种攻击均包含无目标与有目标变体,分别衡量普遍脆弱性与可控操控风险。实验表明,3D VLM在无目标攻击下表现出显著脆弱性,但相比2D模型,在有目标攻击下对特定有害输出的诱导更具韧性。这一发现凸显提升3D VLM对抗鲁棒性的紧迫性,尤其在安全关键应用中。
原文摘要 · Abstract (English)
3D Vision-Language Models (VLMs), such as PointLLM and GPT4Point, have shown strong reasoning and generalization abilities in 3D understanding tasks. However, their adversarial robustness remains largely unexplored. Prior work in 2D VLMs has shown that the integration of visual inputs significantly increases vulnerability to adversarial attacks, making these models easier to manipulate into generating toxic or misleading outputs. In this paper, we investigate whether incorporating 3D vision similarly compromises the robustness of 3D VLMs. To this end, we present the first systematic study of adversarial robustness in point-based 3D VLMs. We propose two complementary attack strategies: \textit{Vision Attack}, which perturbs the visual token features produced by the 3D encoder and projector to assess the robustness of vision-language alignment; and \textit{Caption Attack}, which directly manipulates output token sequences to evaluate end-to-end system robustness. Each attack includes both untargeted and targeted variants to measure general vulnerability and susceptibility to controlled manipulation. Our experiments reveal that 3D VLMs exhibit significant adversarial vulnerabilities under untargeted attacks, while demonstrating greater resilience against targeted attacks aimed at forcing specific harmful outputs, compared to their 2D counterparts. These findings highlight the importance of improving the adversarial robustness of 3D VLMs, especially as they are deployed in safety-critical applications.
Thank you to arXiv for use of its open access interoperability. PaperDance 不是 arXiv 官方产品;中文卡片由大模型生成,请以原文为准。