AdvPC: Transferable Adversarial Perturbations on 3D Point Clouds

08/04/2020
by   Abdullah Hamdi, et al.
0

Deep neural networks are vulnerable to adversarial attacks, in which imperceptible perturbations to their input lead to erroneous network predictions. This phenomenon has been extensively studied in the image domain, and has only recently been extended to 3D point clouds. In this work, we present novel data-driven adversarial attacks against 3D point cloud networks. We aim to address the following problems in current 3D point cloud adversarial attacks: they do not transfer well between different networks, and they are easy to defend against via simple statistical methods. To this extent, we develop a new point cloud attack (dubbed AdvPC) that exploits the input data distribution by adding an adversarial loss, after Auto-Encoder reconstruction, to the objective it optimizes. AdvPC leads to perturbations that are resilient against current defenses, while remaining highly transferable compared to state-of-the-art attacks. We test AdvPC using four popular point cloud networks: PointNet, PointNet++ (MSG and SSG), and DGCNN. Our proposed attack increases the attack success rate by up to 40% for those transferred to unseen networks (transferability), while maintaining a high success rate on the attacked network. AdvPC also increases the ability to break defenses by up to 38% as compared to other baselines on the ModelNet40 dataset.

READ FULL TEXT

page 11

page 32

page 33

research
01/26/2022

Boosting 3D Adversarial Attacks with Attacking On Frequency

Deep neural networks (DNNs) have been shown to be vulnerable to adversar...
research
01/10/2019

Extending Adversarial Attacks and Defenses to Deep 3D Point Cloud Classifiers

3D object classification and segmentation using deep neural networks has...
research
04/07/2021

Universal Spectral Adversarial Attacks for Deformable Shapes

Machine learning models are known to be vulnerable to adversarial attack...
research
08/16/2019

Adversarial point perturbations on 3D objects

The importance of training robust neural network grows as 3D data is inc...
research
10/07/2021

Adversarial Attack by Limited Point Cloud Surface Modifications

Recent research has revealed that the security of deep neural networks t...
research
05/19/2021

Local Aggressive Adversarial Attacks on 3D Point Cloud

Deep neural networks are found to be prone to adversarial examples which...
research
09/21/2021

3D Point Cloud Completion with Geometric-Aware Adversarial Augmentation

With the popularity of 3D sensors in self-driving and other robotics app...

Please sign up or login with your details

Forgot password? Click here to reset