Local Aggressive Adversarial Attacks on 3D Point Cloud

05/19/2021
by   Yiming Sun, et al.
12

Deep neural networks are found to be prone to adversarial examples which could deliberately fool the model to make mistakes. Recently, a few of works expand this task from 2D image to 3D point cloud by using global point cloud optimization. However, the perturbations of global point are not effective for misleading the victim model. First, not all points are important in optimization toward misleading. Abundant points account considerable distortion budget but contribute trivially to attack. Second, the multi-label optimization is suboptimal for adversarial attack, since it consumes extra energy in finding multi-label victim model collapse and causes instance transformation to be dissimilar to any particular instance. Third, the independent adversarial and perceptibility losses, caring misclassification and dissimilarity separately, treat the updating of each point equally without a focus. Therefore, once perceptibility loss approaches its budget threshold, all points would be stock in the surface of hypersphere and attack would be locked in local optimality. Therefore, we propose a local aggressive adversarial attacks (L3A) to solve above issues. Technically, we select a bunch of salient points, the high-score subset of point cloud according to gradient, to perturb. Then a flow of aggressive optimization strategies are developed to reinforce the unperceptive generation of adversarial examples toward misleading victim models. Extensive experiments on PointNet, PointNet++ and DGCNN demonstrate the state-of-the-art performance of our method against existing adversarial attack methods.

READ FULL TEXT

page 1

page 2

page 3

page 4

research
08/27/2020

Minimal Adversarial Examples for Deep Learning on 3D Point Clouds

With the recent developments of convolutional neural networks, deep lear...
research
04/25/2021

3D Adversarial Attacks Beyond Point Cloud

Previous adversarial attacks on 3D point clouds mainly focus on add pert...
research
10/11/2020

IF-Defense: 3D Adversarial Point Cloud Defense via Implicit Function based Restoration

Point cloud is an important 3D data representation widely used in many e...
research
03/12/2023

Adaptive Local Adversarial Attacks on 3D Point Clouds for Augmented Reality

As the key technology of augmented reality (AR), 3D recognition and trac...
research
08/04/2020

AdvPC: Transferable Adversarial Perturbations on 3D Point Clouds

Deep neural networks are vulnerable to adversarial attacks, in which imp...
research
08/16/2019

Adversarial point perturbations on 3D objects

The importance of training robust neural network grows as 3D data is inc...
research
08/17/2022

Imperceptible and Robust Backdoor Attack in 3D Point Cloud

With the thriving of deep learning in processing point cloud data, recen...

Please sign up or login with your details

Forgot password? Click here to reset