Pith. sign in

REVIEW 2 cited by

Towards Transferable Targeted 3D Adversarial Attack in the Physical World

Not yet reviewed by Pith; the record is open.

This paper has not been read by Pith yet. Machine review is queued; the pith claim, tier, and objections will appear here once it completes.

SPECIMEN: schema-true, not a live event

T0 review · schema-true

One-sentence machine reading of the paper's core claim.

pith:XXXXXXXX · record.json · timestamp

arxiv 2312.09558 v3 pith:VXXAZX7M submitted 2023-12-15 cs.CV

classification cs.CV
keywords adversarialtransferabletargetedattackstransferabilitytt3dexamplesexisting
verification ladder T0 review T1 audit T2 compute T3 formal
0 comments
read the original abstract

Compared with transferable untargeted attacks, transferable targeted adversarial attacks could specify the misclassification categories of adversarial samples, posing a greater threat to security-critical tasks. In the meanwhile, 3D adversarial samples, due to their potential of multi-view robustness, can more comprehensively identify weaknesses in existing deep learning systems, possessing great application value. However, the field of transferable targeted 3D adversarial attacks remains vacant. The goal of this work is to develop a more effective technique that could generate transferable targeted 3D adversarial examples, filling the gap in this field. To achieve this goal, we design a novel framework named TT3D that could rapidly reconstruct from few multi-view images into Transferable Targeted 3D textured meshes. While existing mesh-based texture optimization methods compute gradients in the high-dimensional mesh space and easily fall into local optima, leading to unsatisfactory transferability and distinct distortions, TT3D innovatively performs dual optimization towards both feature grid and Multi-layer Perceptron (MLP) parameters in the grid-based NeRF space, which significantly enhances black-box transferability while enjoying naturalness. Experimental results show that TT3D not only exhibits superior cross-model transferability but also maintains considerable adaptability across different renders and vision tasks. More importantly, we produce 3D adversarial examples with 3D printing techniques in the real world and verify their robust performance under various scenarios.

Discussion (0). Continue with ORCID to comment.

Forward citations

Cited by 2 Pith papers

Reviewed papers in the Pith corpus that reference this work. Sorted by Pith novelty score. Full citation record

  1. Rigid Body Adversarial Attacks

    cs.CV 2025-02 conditional novelty 6.0 of 10

    The authors optimize internal material distributions to create objects indistinguishable in rigid-body simulation but with dramatically different deformable-simulation trajectories.

  2. AdvIRL: Reinforcement Learning-Based Adversarial Attacks on 3D NeRF Models

    cs.CV 2024-12 reject novelty 4.0 of 10

    AdvIRL uses PPO to adjust Instant-NGP parameters so that CLIP misclassifies rendered 3D objects, with results on banana, truck, horse, and lighthouse scenes.

Pith tools