arXiv:2601.23102cs.CV2026-01被引 1

提出新攻击框架CoSA,让点云对抗样本跨模型更有效。

Rethinking Transferable Adversarial Attacks on Point Clouds from a Compact Subspace Perspective

  • 在共享低维语义空间中生成对抗扰动,减少模型依赖。
  • 在多个数据集和模型上超越现有方法,转移成功率更高。
  • 适合研究点云安全与鲁棒性,尤其关注跨模型攻击的场景。

点云的可迁移对抗攻击仍具挑战性,因现有方法常依赖特定模型梯度或启发式规则,限制其对未见架构的泛化能力。本文从紧凑子空间视角重新思考对抗可迁移性,提出CoSA框架,该框架在共享的低维语义空间中操作。具体而言,每个点云被表示为捕捉共性语义结构的类别专属原型的紧凑组合,而对抗扰动则在低秩子空间中优化,以引发一致且架构无关的变化。该设计抑制了模型依赖噪声,将扰动约束于语义有意义方向,从而在不依赖代理模型特有特征的前提下提升跨模型迁移性。在多个数据集和网络架构上的大量实验表明,CoSA持续优于当前最优可迁移攻击方法,同时在常见防御策略下保持良好的不可察觉性和鲁棒性。代码将在论文接受后公开。

原文摘要 · Abstract (English)

Transferable adversarial attacks on point clouds remain challenging, as existing methods often rely on model-specific gradients or heuristics that limit generalization to unseen architectures. In this paper, we rethink adversarial transferability from a compact subspace perspective and propose CoSA, a transferable attack framework that operates within a shared low-dimensional semantic space. Specifically, each point cloud is represented as a compact combination of class-specific prototypes that capture shared semantic structure, while adversarial perturbations are optimized within a low-rank subspace to induce coherent and architecture-agnostic variations. This design suppresses model-dependent noise and constrains perturbations to semantically meaningful directions, thereby improving cross-model transferability without relying on surrogate-specific artifacts. Extensive experiments on multiple datasets and network architectures demonstrate that CoSA consistently outperforms state-of-the-art transferable attacks, while maintaining competitive imperceptibility and robustness under common defense strategies. Codes will be made public upon paper acceptance.

点云攻击对抗样本可迁移性

Thank you to arXiv for use of its open access interoperability. PaperDance 不是 arXiv 官方产品;中文卡片由大模型生成,请以原文为准。