iBA: Backdoor Attack on 3D Point Cloud via Reconstructing Itself

被引:0
|
作者
Bian, Yuhao [1 ]
Tian, Shengjing [2 ]
Liu, Xiuping [1 ]
机构
[1] Dalian Univ Technol, Sch Math Sci, Dalian 116024, Liaoning, Peoples R China
[2] China Univ Min & Technol, Sch Econ & Management, Xuzhou 221116, Jiangsu, Peoples R China
关键词
Point cloud compression; Three-dimensional displays; Image reconstruction; Solid modeling; Smoothing methods; Manuals; Training; Backdoor attack; 3D point cloud; shape classification;
D O I
10.1109/TIFS.2024.3452630
中图分类号
TP301 [理论、方法];
学科分类号
081202 ;
摘要
The widespread deployment of deep neural networks (DNNs) for 3D point cloud processing contrasts sharply with their vulnerability to security breaches, particularly backdoor attacks. Studying these attacks is crucial for raising security awareness and mitigating potential risks. However, the irregularity of 3D data and the heterogeneity of 3D DNNs pose unique challenges. Existing methods frequently fail against basic point cloud preprocessing or require intricate manual design. Exploring simple, imperceptible, effective, and difficult-to-defend triggers in 3D point clouds remains challenging. To address this issue, we propose iBA, a novel solution utilizing a folding-based auto-encoder (AE). By leveraging united reconstruction losses, iBA enhances both effectiveness and imperceptibility. Its data-driven nature eliminates the need for complex manual design, while the AE core imparts significant nonlinearity and sample specificity to the trigger, rendering traditional preprocessing techniques ineffective. Additionally, a trigger smoothing module based on spherical harmonic transformation (SHT) allows for controllable intensity. We also discuss potential countermeasures and the possibility of physical deployment for iBA as an extensive reference. Both quantitative and qualitative results demonstrate the effectiveness of our method, achieving state-of-the-art attack success rates (ASR) across a variety of victim models, even with defensive measures in place. iBA's imperceptibility is validated with multiple metrics as well.
引用
收藏
页码:7994 / 8008
页数:15
相关论文
共 50 条
  • [41] D-DPCC: Deep Dynamic Point Cloud Compression via 3D Motion Prediction
    Fan, Tingyu
    Gao, Linyao
    Xu, Yiling
    Li, Zhu
    Wang, Dong
    [J]. arXiv, 2022,
  • [42] 3D Building Scene Reconstruction Based on 3D LiDAR Point Cloud
    Yang, Shih-Chi
    Fan, Yu-Cheng
    [J]. 2017 IEEE INTERNATIONAL CONFERENCE ON CONSUMER ELECTRONICS - TAIWAN (ICCE-TW), 2017,
  • [43] Deformation Tracking in 3D Point Clouds Via Statistical Sampling of Direct Cloud-to-Cloud Distances
    Bahman Jafari
    Ali Khaloo
    David Lattanzi
    [J]. Journal of Nondestructive Evaluation, 2017, 36
  • [44] Deformation Tracking in 3D Point Clouds Via Statistical Sampling of Direct Cloud-to-Cloud Distances
    Jafari, Bahman
    Khaloo, Ali
    Lattanzi, David
    [J]. JOURNAL OF NONDESTRUCTIVE EVALUATION, 2017, 36 (04)
  • [45] 3D Point Cloud Denoising and Normal Estimation for 3D Surface Reconstruction
    Liu, Chang
    Yuan, Ding
    Zhao, Hongwei
    [J]. 2015 IEEE INTERNATIONAL CONFERENCE ON ROBOTICS AND BIOMIMETICS (ROBIO), 2015, : 820 - 825
  • [46] Generating 3D Model of Furniture from 3D Point Cloud of Room
    Osakama, Shunta
    Manabe, Yoshitsugu
    Yata, Noriko
    [J]. INTERNATIONAL WORKSHOP ON ADVANCED IMAGING TECHNOLOGY (IWAIT) 2020, 2020, 11515
  • [47] CHATGPT FOR POINT CLOUD 3D OBJECT PROCESSING
    Balado, J.
    Nguyen, G.
    [J]. GEOSPATIAL WEEK 2023, VOL. 10-1, 2023, : 107 - 114
  • [48] A review of algorithms for filtering the 3D point cloud
    Han, Xian-Feng
    Jin, Jesse S.
    Wang, Ming-Jie
    Jiang, Wei
    Gao, Lei
    Xiao, Liping
    [J]. SIGNAL PROCESSING-IMAGE COMMUNICATION, 2017, 57 : 103 - 112
  • [49] 3D IMAGE SEGMENTATION SUPPORTED BY A POINT CLOUD
    Kosa, Balazs
    Mikula, Karol
    Uba, Markjoe Olunna
    Weberling, Antonia
    Christodoulou, Neophytos
    Zernicka-Goetz, Magdalena
    [J]. DISCRETE AND CONTINUOUS DYNAMICAL SYSTEMS-SERIES S, 2021, 14 (03): : 971 - 985
  • [50] 3D adversarial attacks beyond point cloud
    Zhang, Jinlai
    Chen, Lyujie
    Liu, Binbin
    Ouyang, Bo
    Xie, Qizhi
    Zhu, Jihong
    Li, Weiming
    Meng, Yanmei
    [J]. INFORMATION SCIENCES, 2023, 633 : 491 - 503