用微小扰动块破坏多视角3D重建,保护隐私不被滥用。
PatchPoison: Poisoning Multi-View Datasets to Degrade 3D Reconstruction
- 在每张图边缘加高频棋盘块,干扰特征匹配
- 使3DGS重建误差提升6.8倍,人眼难察觉
- 无需修改流程,内容创作者可直接使用
3D高斯点阵(3DGS)最近实现了从随意拍摄的多视角图像中生成高度逼真的3D重建。然而,这种易用性引发了隐私担忧:公开的图像或视频可能被用于未经授权地重建场景或物体的详细3D模型。我们提出PatchPoison,一种轻量级的数据集投毒方法,以阻止未经授权的3D重建。与全局扰动不同,PatchPoison在多视角数据集中的每张图像边缘注入一个小型高频对抗性补丁(结构化棋盘),该补丁旨在通过引入虚假对应关系,系统性地扭曲SfM流水线(如COLMAP)中的相机位姿估计。由此导致下游3DGS优化偏离正确场景几何。在NeRF-Synthetic基准上,插入12×12像素的补丁使重建误差在LPIPS指标上增加6.8倍,而中毒图像对人类观察者仍保持无害。PatchPoison无需修改现有流程,为内容创作者提供一种即插即用的多视角数据保护方案。
原文摘要 · Abstract (English)
3D Gaussian Splatting (3DGS) has recently enabled highly photorealistic 3D reconstruction from casually captured multi-view images. However, this accessibility raises a privacy concern: publicly available images or videos can be exploited to reconstruct detailed 3D models of scenes or objects without the owner's consent. We present PatchPoison, a lightweight dataset-poisoning method that prevents unauthorized 3D reconstruction. Unlike global perturbations, PatchPoison injects a small high-frequency adversarial patch, a structured checkerboard, into the periphery of each image in a multi-view dataset. The patch is designed to corrupt the feature-matching stage of Structure-from-Motion (SfM) pipelines such as COLMAP by introducing spurious correspondences that systematically misalign estimated camera poses. Consequently, downstream 3DGS optimization diverges from the correct scene geometry. On the NeRF-Synthetic benchmark, inserting a 12 X 12 pixel patch increases reconstruction error by 6.8x in LPIPS, while the poisoned images remain unobtrusive to human viewers. PatchPoison requires no pipeline modifications, offering a practical, "drop-in" preprocessing step for content creators to protect their multi-view data.
Thank you to arXiv for use of its open access interoperability. PaperDance 不是 arXiv 官方产品;中文卡片由大模型生成,请以原文为准。