Eidos: Efficient, Imperceptible Adversarial 3D Point Clouds

Fuente: arXiv
Saved in:
Bibliographic Details
Main Authors: Zhang, Hanwei, Cheng, Luo, He, Qisong, Huang, Wei, Li, Renjue, Sicre, Ronan, Huang, Xiaowei, Hermanns, Holger, Zhang, Lijun
Format: Preprint
Published: 2024
Subjects:
Online Access:
Tags: Add Tag
No Tags, Be the first to tag this record!
_version_ 1866912121703366656
author Zhang, Hanwei
Cheng, Luo
He, Qisong
Huang, Wei
Li, Renjue
Sicre, Ronan
Huang, Xiaowei
Hermanns, Holger
Zhang, Lijun
author_facet Zhang, Hanwei
Cheng, Luo
He, Qisong
Huang, Wei
Li, Renjue
Sicre, Ronan
Huang, Xiaowei
Hermanns, Holger
Zhang, Lijun
contents Classification of 3D point clouds is a challenging machine learning (ML) task with important real-world applications in a spectrum from autonomous driving and robot-assisted surgery to earth observation from low orbit. As with other ML tasks, classification models are notoriously brittle in the presence of adversarial attacks. These are rooted in imperceptible changes to inputs with the effect that a seemingly well-trained model ends up misclassifying the input. This paper adds to the understanding of adversarial attacks by presenting Eidos, a framework providing Efficient Imperceptible aDversarial attacks on 3D pOint cloudS. Eidos supports a diverse set of imperceptibility metrics. It employs an iterative, two-step procedure to identify optimal adversarial examples, thereby enabling a runtime-imperceptibility trade-off. We provide empirical evidence relative to several popular 3D point cloud classification models and several established 3D attack methods, showing Eidos' superiority with respect to efficiency as well as imperceptibility.
format Preprint
id arxiv_https___arxiv_org_abs_2405_14210
institution arXiv
publishDate 2024
record_format arxiv
spellingShingle Eidos: Efficient, Imperceptible Adversarial 3D Point Clouds
Zhang, Hanwei
Cheng, Luo
He, Qisong
Huang, Wei
Li, Renjue
Sicre, Ronan
Huang, Xiaowei
Hermanns, Holger
Zhang, Lijun
Computer Vision and Pattern Recognition
Image and Video Processing
Classification of 3D point clouds is a challenging machine learning (ML) task with important real-world applications in a spectrum from autonomous driving and robot-assisted surgery to earth observation from low orbit. As with other ML tasks, classification models are notoriously brittle in the presence of adversarial attacks. These are rooted in imperceptible changes to inputs with the effect that a seemingly well-trained model ends up misclassifying the input. This paper adds to the understanding of adversarial attacks by presenting Eidos, a framework providing Efficient Imperceptible aDversarial attacks on 3D pOint cloudS. Eidos supports a diverse set of imperceptibility metrics. It employs an iterative, two-step procedure to identify optimal adversarial examples, thereby enabling a runtime-imperceptibility trade-off. We provide empirical evidence relative to several popular 3D point cloud classification models and several established 3D attack methods, showing Eidos' superiority with respect to efficiency as well as imperceptibility.
title Eidos: Efficient, Imperceptible Adversarial 3D Point Clouds
topic Computer Vision and Pattern Recognition
Image and Video Processing
url https://arxiv.org/abs/2405.14210