iBA: Backdoor Attack on 3D Point Cloud via Reconstructing Itself

被引:0
|
作者
Bian, Yuhao [1 ]
Tian, Shengjing [2 ]
Liu, Xiuping [1 ]
机构
[1] Dalian Univ Technol, Sch Math Sci, Dalian 116024, Liaoning, Peoples R China
[2] China Univ Min & Technol, Sch Econ & Management, Xuzhou 221116, Jiangsu, Peoples R China
关键词
Point cloud compression; Three-dimensional displays; Image reconstruction; Solid modeling; Smoothing methods; Manuals; Training; Backdoor attack; 3D point cloud; shape classification;
D O I
10.1109/TIFS.2024.3452630
中图分类号
TP301 [理论、方法];
学科分类号
081202 ;
摘要
The widespread deployment of deep neural networks (DNNs) for 3D point cloud processing contrasts sharply with their vulnerability to security breaches, particularly backdoor attacks. Studying these attacks is crucial for raising security awareness and mitigating potential risks. However, the irregularity of 3D data and the heterogeneity of 3D DNNs pose unique challenges. Existing methods frequently fail against basic point cloud preprocessing or require intricate manual design. Exploring simple, imperceptible, effective, and difficult-to-defend triggers in 3D point clouds remains challenging. To address this issue, we propose iBA, a novel solution utilizing a folding-based auto-encoder (AE). By leveraging united reconstruction losses, iBA enhances both effectiveness and imperceptibility. Its data-driven nature eliminates the need for complex manual design, while the AE core imparts significant nonlinearity and sample specificity to the trigger, rendering traditional preprocessing techniques ineffective. Additionally, a trigger smoothing module based on spherical harmonic transformation (SHT) allows for controllable intensity. We also discuss potential countermeasures and the possibility of physical deployment for iBA as an extensive reference. Both quantitative and qualitative results demonstrate the effectiveness of our method, achieving state-of-the-art attack success rates (ASR) across a variety of victim models, even with defensive measures in place. iBA's imperceptibility is validated with multiple metrics as well.
引用
收藏
页码:7994 / 8008
页数:15
相关论文
共 50 条
  • [1] Imperceptible and Robust Backdoor Attack in 3D Point Cloud
    Gao, Kuofeng
    Bai, Jiawang
    Wu, Baoyuan
    Ya, Mengxi
    Xia, Shu-Tao
    [J]. IEEE TRANSACTIONS ON INFORMATION FORENSICS AND SECURITY, 2024, 19 : 1267 - 1282
  • [2] A Backdoor Attack against 3D Point Cloud Classifiers
    Xiang, Zhen
    Miller, David J.
    Chen, Siheng
    Li, Xi
    Kesidis, George
    [J]. 2021 IEEE/CVF INTERNATIONAL CONFERENCE ON COMPUTER VISION (ICCV 2021), 2021, : 7577 - 7587
  • [3] PointCRT: Detecting Backdoor in 3D Point Cloud via Corruption Robustness
    Hu, Shengshan
    Liu, Wei
    Li, Minghui
    Zhang, Yechao
    Liu, Xiaogeng
    Wang, Xianlong
    Zhang, Leo Yu
    Hou, Junhui
    [J]. PROCEEDINGS OF THE 31ST ACM INTERNATIONAL CONFERENCE ON MULTIMEDIA, MM 2023, 2023, : 666 - 675
  • [4] PointBA: Towards Backdoor Attacks in 3D Point Cloud
    Li, Xinke
    Chen, Zhirui
    Zhao, Yue
    Tong, Zekun
    Zhao, Yabang
    Lim, Andrew
    Zhou, Joey Tianyi
    [J]. 2021 IEEE/CVF INTERNATIONAL CONFERENCE ON COMPUTER VISION (ICCV 2021), 2021, : 16472 - 16481
  • [5] Work-in-Progress: A Physically Realizable Backdoor Attack on 3D Point Cloud Deep Learning
    Bian, Chen
    Jiang, Wei
    Zhan, Jinyu
    Song, Ziwei
    Wen, Xiangyu
    Lei, Hong
    [J]. 2021 INTERNATIONAL CONFERENCE ON HARDWARE/SOFTWARE CODESIGN AND SYSTEM SYNTHESIS (CODES+ISSS 2021), 2021, : 27 - 28
  • [6] Backdoor Attack on 3D Grey Image Segmentation
    Xu, Honghui
    Cai, Zhipeng
    Xiong, Zuobin
    Li, Wei
    [J]. 23RD IEEE INTERNATIONAL CONFERENCE ON DATA MINING, ICDM 2023, 2023, : 708 - 717
  • [7] Imperceptible Transfer Attack and Defense on 3D Point Cloud Classification
    Liu, Daizong
    Hu, Wei
    [J]. IEEE TRANSACTIONS ON PATTERN ANALYSIS AND MACHINE INTELLIGENCE, 2023, 45 (04) : 4727 - 4746
  • [8] Transferable Adversarial Attack on 3D Object Tracking in Point Cloud
    Liu, Xiaoqiong
    Lin, Yuewei
    Yang, Qing
    Fan, Heng
    [J]. MULTIMEDIA MODELING, MMM 2023, PT II, 2023, 13834 : 446 - 458
  • [9] SAMPLING OF 3D POINT CLOUD VIA GERSHGORIN DISC ALIGNMENT
    Dinesh, Chinthaka
    Cheung, Gene
    Wang, Fen
    Bajic, Ivan, V
    [J]. 2020 IEEE INTERNATIONAL CONFERENCE ON IMAGE PROCESSING (ICIP), 2020, : 2736 - 2740
  • [10] Explicitly Perceiving and Preserving the Local Geometric Structures for 3D Point Cloud Attack
    Liu, Daizong
    Hu, Wei
    [J]. THIRTY-EIGHTH AAAI CONFERENCE ON ARTIFICIAL INTELLIGENCE, VOL 38 NO 4, 2024, : 3576 - 3584