Adversarial Attack and Defense on Point Sets
arXiv:1902.10899
Abstract
Emergence of the utility of 3D point cloud data in safety-critical vision tasks (e.g., ADAS) urges researchers to pay more attention to the robustness of 3D representations and deep networks. To this end, we develop an attack and defense scheme, dedicated to 3D point cloud data, for preventing 3D point clouds from manipulated as well as pursuing noise-tolerable 3D representation. A set of novel 3D point cloud attack operations are proposed via pointwise gradient perturbation and adversarial point attachment / detachment. We then develop a flexible perturbation-measurement scheme for 3D point cloud data to detect potential attack data or noisy sensing data. Notably, the proposed defense methods are even effective to detect the adversarial point clouds generated by a proof-of-concept attack directly targeting the defense. Transferability of adversarial attacks between several point cloud networks is addressed, and we propose an momentum-enhanced pointwise gradient to improve the attack transferability. We further analyze the transferability from adversarial point clouds to grid CNNs and the inverse. Extensive experimental results on common point cloud benchmarks demonstrate the validity of the proposed 3D attack and defense framework.
References in corpus (6)
- Delving into Transferable Adversarial Examples and Black-box Attacks
- Towards Deep Neural Network Architectures Robust to Adversarial Examples
- Countering Adversarial Images using Input Transformations
- VoxelNet: End-to-End Learning for Point Cloud Based 3D Object Detection
- The Limitations of Model Uncertainty in Adversarial Settings
- Approximation capability of neural networks on spaces of probability measures and tree-structured domains
Cited by in corpus (18)
- Towards Robust LiDAR-based Perception in Autonomous Driving: General Black-box Adversarial Sensor Attack and Countermeasures
- 3D-VField: Adversarial Augmentation of Point Clouds for Domain Generalization in 3D Object Detection
- Learning Black-Box Attackers with Transferable Priors and Query Feedback
- IF-Defense: 3D Adversarial Point Cloud Defense via Implicit Function based Restoration
- Towards Universal Physical Attacks On Cascaded Camera-Lidar 3D Object Detection Models
- Probabilistic Radiomics: Ambiguous Diagnosis with Controllable Shape Analysis
- DUP-Net: Denoiser and Upsampler Network for 3D Adversarial Point Clouds Defense
- Exploring Adversarial Robustness of Multi-Sensor Perception Systems in Self Driving
- Physically Realizable Adversarial Examples for LiDAR Object Detection
- ShapeAdv: Generating Shape-Aware Adversarial 3D Point Clouds
- PointGuard: Provably Robust 3D Point Cloud Classification
- Adversarial shape perturbations on 3D point clouds
- On Isometry Robustness of Deep 3D Point Cloud Models under Adversarial Attacks
- Nudge Attacks on Point-Cloud DNNs
- 3D Point Cloud Completion with Geometric-Aware Adversarial Augmentation
- Local Aggressive Adversarial Attacks on 3D Point Cloud
- Generating Unrestricted 3D Adversarial Point Clouds
- Explainability-Aware One Point Attack for Point Cloud Neural Networks