iBA: Backdoor Attack on 3D Point Cloud via Reconstructing Itself
arXiv:2403.05847 · doi:10.1109/TIFS.2024.3452630
Abstract
The widespread deployment of Deep Neural Networks (DNNs) for 3D point cloud processing starkly contrasts with their susceptibility to security breaches, notably backdoor attacks. These attacks hijack DNNs during training, embedding triggers in the data that, once activated, cause the network to make predetermined errors while maintaining normal performance on unaltered data. This vulnerability poses significant risks, especially given the insufficient research on robust defense mechanisms for 3D point cloud networks against such sophisticated threats. Existing attacks either struggle to resist basic point cloud pre-processing methods, or rely on delicate manual design. Exploring simple, effective, imperceptible, and difficult-to-defend triggers in 3D point clouds is still challenging.To address these challenges, we introduce MirrorAttack, a novel effective 3D backdoor attack method, which implants the trigger by simply reconstructing a clean point cloud with an auto-encoder. The data-driven nature of the MirrorAttack obviates the need for complex manual design. Minimizing the reconstruction loss automatically improves imperceptibility. Simultaneously, the reconstruction network endows the trigger with pronounced nonlinearity and sample specificity, rendering traditional preprocessing techniques ineffective in eliminating it. A trigger smoothing module based on spherical harmonic transformation is also attached to regulate the intensity of the attack.Both quantitive and qualitative results verify the effectiveness of our method. We achieve state-of-the-art ASR on different types of victim models with the intervention of defensive techniques. Moreover, the minimal perturbation introduced by our trigger, as assessed by various metrics, attests to the method's stealth, ensuring its imperceptibility.
16 pages. in IEEE Transactions on Information Forensics and Security (2024)
References in corpus (11)
- Adam: A Method for Stochastic Optimization
- Deep Learning using Rectified Linear Units (ReLU)
- PCT: Point cloud transformer
- Targeted Backdoor Attacks on Deep Learning Systems Using Data Poisoning
- Rethinking Network Design and Local Geometry in Point Cloud: A Simple Residual MLP Framework
- WaNet -- Imperceptible Warping-based Backdoor Attack
- Poisoning MorphNet for Clean-Label Backdoor Attack to Point Clouds
- Be Careful with Rotation: A Uniform Backdoor Pattern for 3D Shape
- Rethinking Backdoor Attacks
- Towards Class-agnostic Tracking Using Feature Decorrelation in Point Clouds
- Demystifying Poisoning Backdoor Attacks from a Statistical Perspective