Ada3Diff: Defending against 3D Adversarial Point Clouds via Adaptive Diffusion

11/29/2022
by   Kui Zhang, et al.
0

Deep 3D point cloud models are sensitive to adversarial attacks, which poses threats to safety-critical applications such as autonomous driving. Robust training and defend-by-denoise are typical strategies for defending adversarial perturbations, including adversarial training and statistical filtering, respectively. However, they either induce massive computational overhead or rely heavily upon specified noise priors, limiting generalized robustness against attacks of all kinds. This paper introduces a new defense mechanism based on denoising diffusion models that can adaptively remove diverse noises with a tailored intensity estimator. Specifically, we first estimate adversarial distortions by calculating the distance of the points to their neighborhood best-fit plane. Depending on the distortion degree, we choose specific diffusion time steps for the input point cloud and perform the forward diffusion to disrupt potential adversarial shifts. Then we conduct the reverse denoising process to restore the disrupted point cloud back to a clean distribution. This approach enables effective defense against adaptive attacks with varying noise budgets, achieving accentuated robustness of existing 3D deep recognition models.

READ FULL TEXT

page 1

page 2

page 3

page 4

research
08/21/2022

PointDP: Diffusion-driven Purification against Adversarial Attacks on 3D Point Cloud Recognition

3D Point cloud is becoming a critical data representation in many real-w...
research
11/24/2020

On the Adversarial Robustness of 3D Point Cloud Classification

3D point clouds play pivotal roles in various safety-critical fields, su...
research
09/16/2022

PointCAT: Contrastive Adversarial Training for Robust Point Cloud Recognition

Notwithstanding the prominent performance achieved in various applicatio...
research
11/22/2020

Nudge Attacks on Point-Cloud DNNs

The wide adaption of 3D point-cloud data in safety-critical applications...
research
08/10/2023

Critical Points ++: An Agile Point Cloud Importance Measure for Robust Classification, Adversarial Defense and Explainable AI

The ability to cope accurately and fast with Out-Of-Distribution (OOD) s...
research
03/08/2022

Shape-invariant 3D Adversarial Point Clouds

Adversary and invisibility are two fundamental but conflict characters o...
research
10/20/2021

Detecting Backdoor Attacks Against Point Cloud Classifiers

Backdoor attacks (BA) are an emerging threat to deep neural network clas...

Please sign up or login with your details

Forgot password? Click here to reset