Poisoning MorphNet for Clean-Label Backdoor Attack to Point Clouds

05/11/2021
by   Guiyu Tian, et al.
0

This paper presents Poisoning MorphNet, the first backdoor attack method on point clouds. Conventional adversarial attack takes place in the inference stage, often fooling a model by perturbing samples. In contrast, backdoor attack aims to implant triggers into a model during the training stage, such that the victim model acts normally on the clean data unless a trigger is present in a sample. This work follows a typical setting of clean-label backdoor attack, where a few poisoned samples (with their content tampered yet labels unchanged) are injected into the training set. The unique contributions of MorphNet are two-fold. First, it is key to ensure the implanted triggers both visually imperceptible to humans and lead to high attack success rate on the point clouds. To this end, MorphNet jointly optimizes two objectives for sample-adaptive poisoning: a reconstruction loss that preserves the visual similarity between benign / poisoned point clouds, and a classification loss that enforces a modern recognition model of point clouds tends to mis-classify the poisoned sample to a pre-specified target category. This implicitly conducts spectral separation over point clouds, hiding sample-adaptive triggers in fine-grained high-frequency details. Secondly, existing backdoor attack methods are mainly designed for image data, easily defended by some point cloud specific operations (such as denoising). We propose a third loss in MorphNet for suppressing isolated points, leading to improved resistance to denoising-based defense. Comprehensive evaluations are conducted on ModelNet40 and ShapeNetcorev2. Our proposed Poisoning MorphNet outstrips all previous methods with clear margins.

READ FULL TEXT

page 1

page 2

page 3

page 4

research
01/26/2022

Boosting 3D Adversarial Attacks with Attacking On Frequency

Deep neural networks (DNNs) have been shown to be vulnerable to adversar...
research
04/09/2019

3D Point Cloud Denoising via Deep Neural Network based Local Surface Estimation

We present a neural-network-based architecture for 3D point cloud denois...
research
11/01/2020

LG-GAN: Label Guided Adversarial Network for Flexible Targeted Attack of Point Cloud-based Deep Networks

Deep neural networks have made tremendous progress in 3D point-cloud rec...
research
04/16/2019

Total Denoising: Unsupervised Learning of 3D Point Cloud Cleaning

We show that denoising of 3D point clouds can be learned unsupervised, d...
research
03/11/2022

PD-Flow: A Point Cloud Denoising Framework with Normalizing Flows

Point cloud denoising aims to restore clean point clouds from raw observ...
research
08/10/2023

Critical Points ++: An Agile Point Cloud Importance Measure for Robust Classification, Adversarial Defense and Explainable AI

The ability to cope accurately and fast with Out-Of-Distribution (OOD) s...
research
02/09/2023

Imperceptible Sample-Specific Backdoor to DNN with Denoising Autoencoder

The backdoor attack poses a new security threat to deep neural networks....

Please sign up or login with your details

Forgot password? Click here to reset