Adversarial Attack by Limited Point Cloud Surface Modifications

被引:3
作者
Arya, Atrin [1 ]
Naderi, Hanieh [1 ]
Kasaei, Shohreh [1 ]
机构
[1] Sharif Univ Technol, Dept Comp Engn, Tehran, Iran
来源
2023 6TH INTERNATIONAL CONFERENCE ON PATTERN RECOGNITION AND IMAGE ANALYSIS, IPRIA | 2023年
基金
美国国家科学基金会;
关键词
3D data point cloud; adversarial attack; defense;
D O I
10.1109/IPRIA59240.2023.10147168
中图分类号
TP18 [人工智能理论];
学科分类号
081104 ; 0812 ; 0835 ; 1405 ;
摘要
Recent research has revealed that the security of deep neural networks that directly process 3D point clouds to classify objects can be threatened by adversarial samples. Although existing adversarial attack methods achieve high success rates, they do not restrict the point modifications enough to preserve the point cloud appearance. To overcome this shortcoming, two constraints are proposed. These include applying hard boundary constraints on the number of modified points and on the point perturbation norms. Due to the restrictive nature of the problem, the search space contains many local maxima. The proposed method addresses this issue by using a high step-size at the beginning of the algorithm to search the main surface of the point cloud fast and effectively. Then, in order to converge to the desired output, the step-size is gradually decreased. To evaluate the performance of the proposed method, it is run on the ModelNet40 and ScanObjectNN datasets by employing the state-of-the-art point cloud classification models; including PointNet, PointNet++, and DGCNN. The obtained results show that it can perform successful attacks and achieve state-of-the-art results by only a limited number of point modifications while preserving the appearance of the point cloud. Moreover, due to the effective search algorithm, it can perform successful attacks in just a few steps. Additionally, the proposed step-size scheduling algorithm shows an improvement of up to 14.5% when adopted by other methods as well. The proposed method also performs effectively against popular defense methods.
引用
收藏
页数:8
相关论文
共 32 条
[1]   Pointwise Convolutional Neural Networks [J].
Binh-Son Hua ;
Minh-Khoi Tran ;
Yeung, Sai-Kit .
2018 IEEE/CVF CONFERENCE ON COMPUTER VISION AND PATTERN RECOGNITION (CVPR), 2018, :984-993
[2]   Towards Evaluating the Robustness of Neural Networks [J].
Carlini, Nicholas ;
Wagner, David .
2017 IEEE SYMPOSIUM ON SECURITY AND PRIVACY (SP), 2017, :39-57
[3]   Shape Completion using 3D-Encoder-Predictor CNNs and Shape Synthesis [J].
Dai, Angela ;
Qi, Charles Ruizhongtai ;
Niessner, Matthias .
30TH IEEE CONFERENCE ON COMPUTER VISION AND PATTERN RECOGNITION (CVPR 2017), 2017, :6545-6554
[4]  
Engstrom L, 2019, PR MACH LEARN RES, V97
[5]   AdvPC: Transferable Adversarial Perturbations on 3D Point Clouds [J].
Hamdi, Abdullah ;
Rojas, Sara ;
Thabet, Ali ;
Ghanem, Bernard .
COMPUTER VISION - ECCV 2020, PT XII, 2020, 12357 :241-257
[6]  
Goodfellow IJ, 2015, Arxiv, DOI arXiv:1412.6572
[7]   Minimal Adversarial Examples for Deep Learning on 3D Point Clouds [J].
Kim, Jaeyeon ;
Hua, Binh-Son ;
Duc Thanh Nguyen ;
Yeung, Sai-Kit .
2021 IEEE/CVF INTERNATIONAL CONFERENCE ON COMPUTER VISION (ICCV 2021), 2021, :7777-7786
[8]  
Li YY, 2018, ADV NEUR IN, V31
[9]  
Liu Daniel, 2019, 2019 IEEE International Conference on Image Processing (ICIP). Proceedings, P2279, DOI 10.1109/ICIP.2019.8803770
[10]  
Liu D., 2019, arXiv