On the Adversarial Robustness of 3D Point Cloud Classification

11/24/2020
by   Jiachen Sun, et al.
0

3D point clouds play pivotal roles in various safety-critical fields, such as autonomous driving, which desires the corresponding deep neural networks to be robust to adversarial perturbations. Though a few defenses against adversarial point cloud classification have been proposed, it remains unknown whether they can provide real robustness. To this end, we perform the first security analysis of state-of-the-art defenses and design adaptive attacks on them. Our 100 still vulnerable. Since adversarial training (AT) is believed to be the most effective defense, we present the first in-depth study showing how AT behaves in point cloud classification and identify that the required symmetric function (pooling operation) is paramount to the model's robustness under AT. Through our systematic analysis, we find that the default used fixed pooling operations (e.g., MAX pooling) generally weaken AT's performance in point cloud classification. Still, sorting-based parametric pooling operations can significantly improve the models' robustness. Based on the above insights, we further propose DeepSym, a deep symmetric pooling operation, to architecturally advance the adversarial robustness under AT to 47.0 nominal accuracy, outperforming the original design and a strong baseline by 28.5

READ FULL TEXT

page 6

page 18

research
03/03/2023

PointCert: Point Cloud Classification with Deterministic Certified Robustness Guarantees

Point cloud classification is an essential component in many security-cr...
research
06/08/2023

Equivariant vs. Invariant Layers: A Comparison of Backbone and Pooling for Point Cloud Classification

Learning from set-structured data, such as point clouds, has gained sign...
research
11/29/2022

Ada3Diff: Defending against 3D Adversarial Point Clouds via Adaptive Diffusion

Deep 3D point cloud models are sensitive to adversarial attacks, which p...
research
06/21/2021

Robust Pooling through the Data Mode

The task of learning from point cloud data is always challenging due to ...
research
08/21/2022

PointDP: Diffusion-driven Purification against Adversarial Attacks on 3D Point Cloud Recognition

3D Point cloud is becoming a critical data representation in many real-w...
research
09/16/2022

PointCAT: Contrastive Adversarial Training for Robust Point Cloud Recognition

Notwithstanding the prominent performance achieved in various applicatio...
research
03/30/2021

Robustness Certification for Point Cloud Models

The use of deep 3D point cloud models in safety-critical applications, s...

Please sign up or login with your details

Forgot password? Click here to reset