{"id":"96053d55-7c35-4bed-a073-0f4f64c08d74","arxiv_id":"2508.11854","paper_version":2,"verdict":"UNVERDICTED","confidence":"LOW","novelty_score":7.0,"correctness_risk":"high","formal_verification":"none","parameter_count":2,"one_line_summary":"3D Gaussian Splatting's view-dependent shading can be weaponized to create viewpoint-specific adversarial camouflage that fools downstream object detectors without model access.","lead":"This paper proposes an attack method that hides adversarial content in 3D scene objects, using Gaussian Splatting's view-dependent shading so the object looks normal from most angles but fools object detectors from one specific viewpoint. It claims black-box success against popular detector families on both physical objects and synthetic scenes, which matters for safety-critical vision systems like autonomous navigation.","discovery_kind":"new_method","skeptic_critique":{"model":"deepseek-v4-flash","headline":"The physical-transfer step is the load-bearing assumption: 3DGS view-dependent textures must survive fabrication and still fool detectors at a single viewpoint, but no method or experiments are available to support it.","rationale":"The reader's UNVERDICTED verdict is appropriate: only the abstract is available because the supplied full text is a different arXiv paper (LARC, 2508.11860). The stress-test identifies the same weakest link as the reader: the transition from 3DGS renderer to a physical object must preserve viewpoint-dependent adversarial appearance, and the victim must observe the object from the single intended viewpoint. This is the least secure premise because 3DGS is a rasterization model, not a physical material model, and the visible manuscript provides no evidence of fabrication or physical capture. The novelty claim ('first attack') also cannot be checked. Since the central claim already cannot be verified, the appropriate disposition remains UNVERDICTED rather than ACCEPT or REJECT on the merits. Marking the verdict unchanged is not an endorsement; it preserves the reader's conclusion that verification is blocked until the actual manuscript and experimental artifacts are available.","tokens_in":10355,"tokens_out":5638,"duration_ms":77001,"concrete_test":"Restore the full ComplicitSplat manuscript and locate the real-world experiment; verify it includes an explicit fabrication protocol (material, printing/coating, mounting) and reports detection success per detector and per camera viewpoint, including off-target viewpoints. Then independently reproduce one reported physical condition: fabricate the adversarial texture with that protocol, capture it with a standard camera at the claimed target viewpoint (plus small pose perturbations), and run the claimed detector. If the target-viewpoint success rate is not far above chance or the off-target control is not benign, the 'real-world physical objects' generalization claim fails.","verdict_should_be":"UNCHANGED","load_bearing_attack":"The central claim is that ComplicitSplat produces viewpoint-specific camouflage that works on 'real-world capture of physical objects' against black-box detectors. For this to hold, two independent premises must be true: (1) the optimized 3DGS view-dependent appearance can be realized as a physical surface (printable/coatable material, correct lighting and camera optics), and (2) the attacker can place/control the victim camera at the specific viewpoint where the adversarial content appears. Neither is established. The supplied full text is a different manuscript (LARC, arXiv:2508.11860, constrained retrosynthesis), so there is no fabrication protocol, no per-condition detector results, no viewpoint-sensitivity analysis, and no comparison supporting the 'first' novelty claim. This matters because 3DGS shading is a rendering abstraction (spherical-harmonic coefficients, alpha-blended splats); its appearance is not guaranteed to transfer to a physical object under natural illumination. If the physical-transfer premise fails, the attack reduces to a synthetic-render-only result, and even then the single-viewpoint visibility requires a threat model in which the victim's camera pose is known or controllable. This is a load-bearing gap in the argument as presented.","agreement_with_reader":"agree"},"referee_report":{"model":"deepseek-v4-flash","summary":"The submission presents an abstract claiming 'ComplicitSplat', described as the first black-box attack that exploits standard 3D Gaussian Splatting shading to create viewpoint-specific camouflage, with experiments on real-world physical objects and synthetic scenes against single-stage, multi-stage, and transformer-based detectors. However, the supplied 'Full Text' is a different manuscript (arXiv:2508.11860, 'LARC: Towards Human-level Constrained Retrosynthesis Planning through an Agentic Framework'), which concerns LLM agents for chemistry and contains no material on 3DGS, adversarial attacks, or object detection. As submitted, the manuscript therefore consists only of an abstract plus an unrelated full text. No method, experiments, datasets, ablations, or quantitative results are available for ComplicitSplat.","tokens_in":10594,"tokens_out":2416,"duration_ms":33288,"significance":"If the claimed attack were fully demonstrated, it would be significant for safety-critical vision systems relying on 3DGS-based rendering, particularly autonomous navigation. The viewpoint-specific, black-box property would be a novel contribution. However, the significance cannot be assessed from this submission because there is no verifiable technical content: no optimization procedure, no threat model, no detector evaluation, no physical fabrication protocol, and no comparison with prior adversarial 3DGS work. The abstract alone is a plausible but unsubstantiated research proposal, not a refereed paper. The claimed real-world transfer and black-box generalization are exactly the load-bearing assertions that need experimental support, and none is present.","major_comments":[{"comment":"The supplied full text is a completely different manuscript on constrained retrosynthesis planning (LARC). It contains no description of ComplicitSplat's method, objective function, rendering/optimization pipeline, datasets, detector architectures, metrics, or baselines. Consequently, every technical claim in the abstract is unsupported by any evidence in the submission. This is a load-bearing omission that prevents review.","section":"Full Text (arXiv:2508.11860)"},{"comment":"The abstract claims the attack generalizes to physical objects, but no fabrication or physical-transfer methodology is described. It is not established that view-dependent appearance parametrized by 3DGS shading (e.g., spherical harmonics) survives manufacturing, lighting conditions, and camera optics to fool a detector at the target viewpoint. Without a protocol and per-condition results, this claim is unverifiable and cannot be accepted as a demonstrated result.","section":"Abstract, 'real-world capture of physical objects'"},{"comment":"The black-box claim is not supported by any experimental protocol. There is no statement of which surrogate models were used to optimize the camouflage, whether the tested detectors overlap with or share inductive biases with those surrogates, or how transfer was measured. As stated, the risk of circularity—where 'black-box' success is measured on models effectively included in the surrogate ensemble—cannot be ruled out. Concrete model lists and per-detector results are required.","section":"Abstract, 'without requiring access to model architecture or weights'"},{"comment":"The attack's practical threat relies on the assumption that the victim camera observes the object from a known or controllable viewpoint. No threat model, viewpoint-sensitivity analysis, or robustness to pose variation is provided. If this assumption fails, the claimed attack reduces to a synthetic-render-only curiosity. This is a central unsupported premise.","section":"Abstract, 'visible only from specific viewpoints'"}],"minor_comments":[{"comment":"Typographical and grammatical errors: 'a variety of popular detector - both single-stage, multi-stage, and transformer-based models' should be 'detectors — both single-stage, multi-stage, and transformer-based —'.","section":"Abstract"},{"comment":"The phrase 'To our knowledge, this is the first...' is not accompanied by a related-work comparison or citations; novelty claims require at least a brief positioning against prior adversarial rendering and 3DGS attacks.","section":"Abstract"},{"comment":"The submission file itself appears to be a different paper. If ComplicitSplat is the intended manuscript, the correct full text must be uploaded. This is not a minor formatting issue but a submission-integrity problem.","section":"Full Text"}],"recommendation":"reject","confidential_remarks":"To the editor: This submission cannot be reviewed as-is. The uploaded full text corresponds to arXiv:2508.11860 (LARC, constrained retrosynthesis), not to the abstract for ComplicitSplat. The paper therefore contains no method or evidence for its central claims. I recommend desk reject and allow the authors to resubmit a complete and correct manuscript. The abstract's claims about physical-object transfer and black-box generalization are substantial and would require careful experimental validation if the full paper is eventually submitted."},"author_rebuttal":null,"desk_editor":{"model":"deepseek-v4-flash","letter":"Quick take: the abstract describes something I haven't seen before – using 3DGS view-dependent shading to hide adversarial content that only appears from a specific viewpoint, with no white-box access to the target detector. That's a real departure from static patches and whole-scene poisoning, and the breadth of claimed targets (single-stage, multi-stage, transformer detectors on both synthetic and physical scenes) is impressive if true.\n\nProblem: the full text I was given is a chemistry paper (LARC, retrosynthesis). So I have no way to check methods, numbers, baselines, or the novelty claim. That's the first thing to fix.\n\nThe biggest soft spot, even from the abstract, is the physical-transfer step. 3DGS appearance is a rendering abstraction (spherical-harmonic coefficients, alpha-blended splats). Getting that onto a physical object that still fools a detector at one viewpoint under natural lighting is not a given. The abstract says 'real-world capture of physical objects' but gives no fabrication method, no per-condition numbers, no sensitivity analysis. If that step fails, the result is a synthetic-only attack, which is still interesting but much weaker. The other assumption is that the attacker controls the victim's viewing angle. That's a specific threat model that needs to be stated and justified.\n\nAlso, 'black-box' is doing a lot of work. The abstract says no architecture or weight access, but it doesn't say how many queries, what surrogate ensemble was used, or whether the detectors tested share inductive biases with the surrogates. The transfer-abstraction overlap could inflate success rates.\n\nWhat's genuinely good: the viewpoint-specific aspect is a new axis for adversarial camouflage, and the framing around safety-critical 3DGS deployment is fair. The claim that it works across detector families suggests they ran a real eval, but I can't see it.\n\nWho's this for? Adversarial ML and 3D vision people, especially anyone thinking about physical attacks on autonomous driving. If the experiments check out, it's a solid contribution. But right now I can't tell you if they do.\n\nRecommendation: don't desk reject based on the abstract. Ask the authors to supply the correct full text. If it matches, send it out for review with extra scrutiny on the physical-transfer experiments and the threat model. If the mismatch is a submission defect, that's a separate integrity issue.","headline":"Clever new attack idea, but I can't judge it: the supplied full text is a different paper, and the physical-transfer claim is unbacked.","tokens_in":11142,"tokens_out":3660,"would_cite":false,"duration_ms":40886,"reading_group":"maybe","serious_thinker":"unclear","would_accept_peer_review":true},"rs_alignment":null,"lean_confirmation":null,"pith_extraction":{"msc":[],"pacs":[],"model":"deepseek-v4-flash","headline":"ComplicitSplat embeds adversarial patterns into 3D scenes that are visible only from a single viewpoint, fooling detectors without any model access.","keywords":["3D Gaussian Splatting","adversarial attack","black-box attack","object detection","view-dependent camouflage","novel view synthesis","autonomous vehicle safety"],"falsifier":"Print or fabricate an object with ComplicitSplat's optimized appearance, place it in a real scene with a standard object detector, and record detections across a sweep of camera viewpoints. If the detector is not fooled at the target viewpoint, or is fooled from a wide range of viewpoints rather than only the intended one, the paper's real-world generalization claim fails; if the attack works physically as well as in synthetic renders, the claim is supported.","tokens_in":10221,"feed_emoji":"🎭","tokens_out":5488,"duration_ms":58451,"temperature":0.7,"pith_summary":"ComplicitSplat tries to show that 3D Gaussian Splatting—a fast-growing technique for reconstructing a scene from photos—gives an adversary a new way to hide attacks. The trick is to exploit the shading model's view-dependent behavior to bake a pattern into an object that looks benign from most angles but turns into detector-fooling content exactly when viewed from a spot the attacker chooses. The attack is black-box: it does not need the weights or architecture of the object detector it targets. The paper reports that the resulting camouflage fools single-stage, multi-stage, and transformer-based detectors, and that it transfers both to synthetic scenes and to real-world captures of physical objects. If these results hold, safety-critical systems like autonomous cars would need to treat a scene's appearance as attacker-controlled rather than trustworthy.","feed_headline":"3D camouflage fools detectors from a single angle","feed_subtitle":"ComplicitSplat embeds adversarial patterns in 3D scenes that appear only at one viewpoint, with no model access.","key_machinery":"The central object is ComplicitSplat itself: a method that exploits standard 3D Gaussian Splatting shading to generate view-dependent camouflage. 3DGS represents a scene as a set of Gaussian primitives whose appearance is computed through a differentiable splatting pipeline; ComplicitSplat adjusts these primitives' colors and textures so that a rendered object changes appearance with viewing angle. This mechanism is what makes the adversarial signal present in one rendering direction and absent in others, achieving viewpoint specificity without knowledge of the target detector's architecture or weights.","core_discovery":"The central claim is that ComplicitSplat is the first black-box attack that leverages standard 3D Gaussian Splatting (3DGS) shading to create viewpoint-specific camouflage. By optimizing colors and textures that change with viewing angle, the method embeds adversarial content in scene objects such that the object appears innocuous from most viewpoints but triggers detector failure from a specific viewpoint. The paper asserts this is the first 3DGS-based black-box attack on downstream object detectors, and that it generalizes across detector families (single-stage, multi-stage, transformer-based) on both synthetic scenes and real-world captures of physical objects, exposing a new safety risk","pith_inferences":["The most critical unresolved link is physical transfer: the abstract reports a real-world capture, but without a described fabrication method or per-condition numbers, a reader cannot tell whether the printed object preserved the view-dependent effect. A natural extension would be a systematic sweep over materials, printers, lighting, and camera lenses.","The attack's viewpoint specificity presupposes the attacker can predict or steer the victim camera's pose. A practical deployment would likely need to create multiple viewpoint-specific patches or a temporal sequence, since a moving vehicle's camera angle changes continuously.","The same shading-based hiding trick could plausibly be applied to other view-dependent rendering methods, not just 3DGS; the mechanism is the view-dependent shading itself, so the attack concept may be more general than the specific implementation."],"forward_implications":["A detector's output can be made unreliable by a physical object that appears unremarkable to human observers, because the adversarial pattern is gated by viewing angle.","Safety evaluation of perception systems should include attacks that manipulate scene appearance through the rendering or physical layer, not just image-level noise.","Autonomous navigation and robotics pipelines that rely on novel-view synthesis or 3D reconstruction inherit a new attack surface at the object level.","Because the attack is black-box, it transfers even when the target model's architecture and weights are hidden, widening the set of plausible attackers."],"supporting_citations":[],"fun_headline_variants":["Single-view 3D camouflage slips past detectors","First black-box 3DGS attack hides in one view","Viewpoint-specific 3D splatting fools object detectors","3D Gaussian splat camouflage defeats detectors at one angle","One-view 3D camouflage blinds popular detectors"],"cache_read_input_tokens":2816,"weakest_assumption_plain":"The load-bearing premise is that the view-dependent appearance created in the rendered 3D scene survives the transfer to a physically fabricated object—under real lighting, camera optics, and fabrication fidelity—and still fools the detector exactly at the chosen viewpoint.","fun_headline_variants_meta":{"raw":{"variants":["Single-view 3D camouflage slips past detectors","First black-box 3DGS attack hides in one view","Viewpoint-specific 3D splatting fools object detectors","3D Gaussian splat camouflage defeats detectors at one angle","One-view 3D camouflage blinds popular detectors"]},"model":"deepseek-v4-flash","effort":"low","cost_usd":0.000128,"raw_usage":{"total_tokens":922,"prompt_tokens":681,"completion_tokens":241,"prompt_tokens_details":{"cached_tokens":256},"prompt_cache_hit_tokens":256,"prompt_cache_miss_tokens":425,"completion_tokens_details":{"reasoning_tokens":162}},"tokens_in":425,"tokens_out":241,"duration_ms":3285,"temperature":1.0,"reasoning_tokens":162,"cache_read_input_tokens":256,"cache_creation_input_tokens":0},"cache_creation_input_tokens":0},"created_at":"2026-08-05T19:42:37.412598+00:00","model_set":{"reader":"deepseek-v4-flash"},"falsifier":"Print or fabricate an object with ComplicitSplat's optimized appearance, place it in a real scene with a standard object detector, and record detections across a sweep of camera viewpoints. If the detector is not fooled at the target viewpoint, or is fooled from a wide range of viewpoints rather than only the intended one, the paper's real-world generalization claim fails; if the attack works physically as well as in synthetic renders, the claim is supported.","supporting_citations":[],"review_version":1}