IF-Defense: 3D Adversarial Point Cloud Defense via Implicit Function based Restoration

by   Ziyi Wu, et al.

Point cloud is an important 3D data representation widely used in many essential applications. Leveraging deep neural networks, recent works have shown great success in processing 3D point clouds. However, those deep neural networks are vulnerable to various 3D adversarial attacks, which can be summarized as two primary types: point perturbation that affects local point distribution, and surface distortion that causes dramatic changes in geometry. In this paper, we propose a novel 3D adversarial point cloud defense method leveraging implicit function based restoration (IF-Defense) to address both the aforementioned attacks. It is composed of two steps: 1) it predicts an implicit function that captures the clean shape through a surface recovery module, and 2) restores a clean and complete point cloud via minimizing the difference between the attacked point cloud and the predicted implicit function under geometry- and distribution- aware constraints. Our experimental results show that IF-Defense achieves the state-of-the-art defense performance against all existing adversarial attacks on PointNet, PointNet++, DGCNN and PointConv. Comparing with previous methods, IF-Defense presents 20.02 classification accuracy against salient point dropping attack and 16.29 against LG-GAN attack on PointNet.


page 1

page 2

page 3

page 4


Boosting 3D Adversarial Attacks with Attacking On Frequency

Deep neural networks (DNNs) have been shown to be vulnerable to adversar...

Adversarial Attack and Defense on Point Sets

Emergence of the utility of 3D point cloud data in critical vision tasks...

Adversarial Attack by Limited Point Cloud Surface Modifications

Recent research has revealed that the security of deep neural networks t...

Robust Structured Declarative Classifiers for 3D Point Clouds: Defending Adversarial Attacks with Implicit Gradients

Deep neural networks for 3D point cloud classification, such as PointNet...

Local Aggressive Adversarial Attacks on 3D Point Cloud

Deep neural networks are found to be prone to adversarial examples which...

The art of defense: letting networks fool the attacker

Some deep neural networks are invariant to some input transformations, s...

Imperceptible and Robust Backdoor Attack in 3D Point Cloud

With the thriving of deep learning in processing point cloud data, recen...

Please sign up or login with your details

Forgot password? Click here to reset