REVIEW 4 cited by
ShapeAdv: Generating Shape-Aware Adversarial 3D Point Clouds
Not yet reviewed by Pith; the record is open.
This paper has not been read by Pith yet. Machine review is queued; the pith claim, tier, and objections will appear here once it completes.
SPECIMEN: schema-true, not a live event
T0 review · schema-true
One-sentence machine reading of the paper's core claim.
pith:XXXXXXXX · record.json · timestamp
read the original abstract
We introduce ShapeAdv, a novel framework to study shape-aware adversarial perturbations that reflect the underlying shape variations (e.g., geometric deformations and structural differences) in the 3D point cloud space. We develop shape-aware adversarial 3D point cloud attacks by leveraging the learned latent space of a point cloud auto-encoder where the adversarial noise is applied in the latent space. Specifically, we propose three different variants including an exemplar-based one by guiding the shape deformation with auxiliary data, such that the generated point cloud resembles the shape morphing between objects in the same category. Different from prior works, the resulting adversarial 3D point clouds reflect the shape variations in the 3D point cloud space while still being close to the original one. In addition, experimental evaluations on the ModelNet40 benchmark demonstrate that our adversaries are more difficult to defend with existing point cloud defense methods and exhibit a higher attack transferability across classifiers. Our shape-aware adversarial attacks are orthogonal to existing point cloud based attacks and shed light on the vulnerability of 3D deep neural networks.
Forward citations
Cited by 4 Pith papers
-
Cage-Based Deformation for Transferable and Undefendable Point Cloud Attack
CageAttack generates adversarial point clouds by perturbing cage vertices and propagating deformations via mean value coordinates, claiming a better trade-off between attack success, transferability, undefendability, ...
-
KNN-Defense: Defense against 3D Adversarial Point Clouds using Nearest-Neighbor Search
KNN-Defense applies nearest-neighbor search in feature space to 3D point cloud classification, improving robustness to adversarial perturbations without retraining.
-
Texture- and Shape-based Adversarial Attacks for Overhead Image Vehicle Detection
Practical texture constraints (pixelation, limited colors, masking) lower adversarial attack success on overhead vehicle detectors, but combining them with small 3D shape deformation approaches unconstrained texture a...
-
Improving the Transferability of 3D Point Cloud Attack via Spectral-aware Admix and Optimization Designs
SAAO improves transferability of 3D point cloud adversarial attacks by performing Admix-style mixing in the graph Fourier domain with learnable weights and gradient-based path selection, yielding higher transfer attac...
Discussion (0). Continue with ORCID to comment.