通过拓扑结构生成难以察觉的点云对抗样本。
Topo-ADV: Generating Topology-Driven Imperceptible Adversarial Point Clouds
- 利用持久同调优化拓扑特征,实现可微分的对抗攻击
- 在多个数据集上达100%攻击成功率且几何不可察觉
- 适合研究模型安全与拓扑漏洞的学者参考
三维点云深度学习在物体分类与识别中取得显著进展,但近期研究显示其仍易受对抗扰动影响。现有3D攻击主要操纵点位置、曲率或表面结构,隐含假设保持全局形状即保留语义内容。本文挑战这一假设,提出首个面向点云深度学习的拓扑驱动对抗攻击方法——Topo-ADV。核心思想是:三维物体的同调结构构成未被探索的脆弱面。我们设计了一个端到端可微框架,将持久同调作为显式优化目标,支持梯度驱动的拓扑特征操控。通过可微拓扑表示嵌入持久图谱,方法联合优化三项目标:(i) 拓扑差异损失以改变持久性,(ii) 误分类目标,(iii) 几何不可察觉约束以保持视觉合理性。实验表明,微小的拓扑驱动扰动在ModelNet40、ShapeNet Part和ScanObjectNN等基准数据集上对PointNet和DGCNN分类器均实现高达100%的攻击成功率,且在几何上与原点云无法区分,优于当前最先进方法在多种感知度指标上的表现。
原文摘要 · Abstract (English)
Deep neural networks for 3D point cloud understanding have achieved remarkable success in object classification and recognition, yet recent work shows that these models remain highly vulnerable to adversarial perturbations. Existing 3D attacks predominantly manipulate geometric properties such as point locations, curvature, or surface structure, implicitly assuming that preserving global shape fidelity preserves semantic content. In this work, we challenge this assumption and introduce the first topology-driven adversarial attack for point cloud deep learning. Our key insight is that the homological structure of a 3D object constitutes a previously unexplored vulnerability surface. We propose Topo-ADV, an end-to-end differentiable framework that incorporates persistent homology as an explicit optimization objective, enabling gradient-based manipulation of topological features during adversarial example generation. By embedding persistence diagrams through differentiable topological representations, our method jointly optimizes (i) a topology divergence loss that alters persistence, (ii) a misclassification objective, and (iii) geometric imperceptibility constraints that preserve visual plausibility. Experiments demonstrate that subtle topology-driven perturbations consistently achieve up to 100% attack success rates on benchmark datasets such as ModelNet40, ShapeNet Part, and ScanObjectNN using PointNet and DGCNN classifiers, while remaining geometrically indistinguishable from the original point clouds, beating state-of-the-art methods on various perceptibility metrics.
Thank you to arXiv for use of its open access interoperability. PaperDance 不是 arXiv 官方产品;中文卡片由大模型生成,请以原文为准。