IPA-NeRF: Illusory Poisoning Attack Against Neural Radiance Fields

Fuente: arXiv
Saved in:
Bibliographic Details
Main Authors: Jiang, Wenxiang, Zhang, Hanwei, Zhao, Shuo, Guo, Zhongwen, Wang, Hao
Format: Preprint
Published: 2024
Subjects:
Online Access:
Tags: Add Tag
No Tags, Be the first to tag this record!
_version_ 1866911960414552064
author Jiang, Wenxiang
Zhang, Hanwei
Zhao, Shuo
Guo, Zhongwen
Wang, Hao
author_facet Jiang, Wenxiang
Zhang, Hanwei
Zhao, Shuo
Guo, Zhongwen
Wang, Hao
contents Neural Radiance Field (NeRF) represents a significant advancement in computer vision, offering implicit neural network-based scene representation and novel view synthesis capabilities. Its applications span diverse fields including robotics, urban mapping, autonomous navigation, virtual reality/augmented reality, etc., some of which are considered high-risk AI applications. However, despite its widespread adoption, the robustness and security of NeRF remain largely unexplored. In this study, we contribute to this area by introducing the Illusory Poisoning Attack against Neural Radiance Fields (IPA-NeRF). This attack involves embedding a hidden backdoor view into NeRF, allowing it to produce predetermined outputs, i.e. illusory, when presented with the specified backdoor view while maintaining normal performance with standard inputs. Our attack is specifically designed to deceive users or downstream models at a particular position while ensuring that any abnormalities in NeRF remain undetectable from other viewpoints. Experimental results demonstrate the effectiveness of our Illusory Poisoning Attack, successfully presenting the desired illusory on the specified viewpoint without impacting other views. Notably, we achieve this attack by introducing small perturbations solely to the training set. The code can be found at https://github.com/jiang-wenxiang/IPA-NeRF.
format Preprint
id arxiv_https___arxiv_org_abs_2407_11921
institution arXiv
publishDate 2024
record_format arxiv
spellingShingle IPA-NeRF: Illusory Poisoning Attack Against Neural Radiance Fields
Jiang, Wenxiang
Zhang, Hanwei
Zhao, Shuo
Guo, Zhongwen
Wang, Hao
Computer Vision and Pattern Recognition
Cryptography and Security
Neural Radiance Field (NeRF) represents a significant advancement in computer vision, offering implicit neural network-based scene representation and novel view synthesis capabilities. Its applications span diverse fields including robotics, urban mapping, autonomous navigation, virtual reality/augmented reality, etc., some of which are considered high-risk AI applications. However, despite its widespread adoption, the robustness and security of NeRF remain largely unexplored. In this study, we contribute to this area by introducing the Illusory Poisoning Attack against Neural Radiance Fields (IPA-NeRF). This attack involves embedding a hidden backdoor view into NeRF, allowing it to produce predetermined outputs, i.e. illusory, when presented with the specified backdoor view while maintaining normal performance with standard inputs. Our attack is specifically designed to deceive users or downstream models at a particular position while ensuring that any abnormalities in NeRF remain undetectable from other viewpoints. Experimental results demonstrate the effectiveness of our Illusory Poisoning Attack, successfully presenting the desired illusory on the specified viewpoint without impacting other views. Notably, we achieve this attack by introducing small perturbations solely to the training set. The code can be found at https://github.com/jiang-wenxiang/IPA-NeRF.
title IPA-NeRF: Illusory Poisoning Attack Against Neural Radiance Fields
topic Computer Vision and Pattern Recognition
Cryptography and Security
url https://arxiv.org/abs/2407.11921