Pith. sign in

REVIEW 3 cited by

Poison-splat: Computation Cost Attack on 3D Gaussian Splatting

Not yet reviewed by Pith; the record is open.

This paper has not been read by Pith yet. Machine review is queued; the pith claim, tier, and objections will appear here once it completes.

SPECIMEN: schema-true, not a live event

T0 review · schema-true

One-sentence machine reading of the paper's core claim.

pith:XXXXXXXX · record.json · timestamp

arxiv 2410.08190 v2 pith:KXSAER56 submitted 2024-10-10 cs.CV cs.CRcs.GRcs.LG

classification cs.CVcs.CRcs.GRcs.LG
keywords attackcomputationcostpoison-splatgaussianinputmemorynovel
verification ladder T0 review T1 audit T2 compute T3 formal
0 comments
read the original abstract

3D Gaussian splatting (3DGS), known for its groundbreaking performance and efficiency, has become a dominant 3D representation and brought progress to many 3D vision tasks. However, in this work, we reveal a significant security vulnerability that has been largely overlooked in 3DGS: the computation cost of training 3DGS could be maliciously tampered by poisoning the input data. By developing an attack named Poison-splat, we reveal a novel attack surface where the adversary can poison the input images to drastically increase the computation memory and time needed for 3DGS training, pushing the algorithm towards its worst computation complexity. In extreme cases, the attack can even consume all allocable memory, leading to a Denial-of-Service (DoS) that disrupts servers, resulting in practical damages to real-world 3DGS service vendors. Such a computation cost attack is achieved by addressing a bi-level optimization problem through three tailored strategies: attack objective approximation, proxy model rendering, and optional constrained optimization. These strategies not only ensure the effectiveness of our attack but also make it difficult to defend with simple defensive measures. We hope the revelation of this novel attack surface can spark attention to this crucial yet overlooked vulnerability of 3DGS systems. Our code is available at https://github.com/jiahaolu97/poison-splat .

Discussion (0). Continue with ORCID to comment.

Forward citations

Cited by 3 Pith papers

Reviewed papers in the Pith corpus that reference this work. Sorted by Pith novelty score. Full citation record

  1. Safety in Embodied AI: A Survey of Risks, Attacks, and Defenses

    cs.CR 2026-03 unverdicted novelty 6.0 of 10

    The survey organizes over 400 papers on embodied AI safety into a multi-level taxonomy and flags overlooked issues such as fragile multimodal fusion and unstable planning under jailbreaks.

  2. DefenseSplat: Enhancing the Robustness of 3D Gaussian Splatting via Frequency-Aware Filtering

    cs.CV 2026-02 conditional novelty 6.0 of 10

    Zeroing high-frequency wavelet subbands of training views before 3D Gaussian Splatting suppresses Poison-Splat adversarial artifacts, yielding more robust training and rendering across Mip-NeRF 360, Tanks-and-Temples,...

  3. 3D Gaussian Splat Vulnerabilities

    cs.CR 2025-05 conditional novelty 5.0 of 10

    3DGS scenes can be poisoned or directly perturbed to embed view-dependent adversarial content that misleads YOLOv8 and Faster R-CNN object detectors.

Pith tools