Stealthy and Robust Backdoor Attack against 3D Point Clouds through Additional Point Features

Fuente: arXiv
Saved in:
Bibliographic Details
Main Authors: Ning, Xiaoyang, Xie, Qing, Xu, Jinyu, Jiang, Wenbo, Li, Jiachen, Ma, Yanchun
Format: Preprint
Published: 2024
Subjects:
Online Access:
Tags: Add Tag
No Tags, Be the first to tag this record!
_version_ 1866915063423565824
author Ning, Xiaoyang
Xie, Qing
Xu, Jinyu
Jiang, Wenbo
Li, Jiachen
Ma, Yanchun
author_facet Ning, Xiaoyang
Xie, Qing
Xu, Jinyu
Jiang, Wenbo
Li, Jiachen
Ma, Yanchun
contents Recently, 3D backdoor attacks have posed a substantial threat to 3D Deep Neural Networks (3D DNNs) designed for 3D point clouds, which are extensively deployed in various security-critical applications. Although the existing 3D backdoor attacks achieved high attack performance, they remain vulnerable to preprocessing-based defenses (e.g., outlier removal and rotation augmentation) and are prone to detection by human inspection. In pursuit of a more challenging-to-defend and stealthy 3D backdoor attack, this paper introduces the Stealthy and Robust Backdoor Attack (SRBA), which ensures robustness and stealthiness through intentional design considerations. The key insight of our attack involves applying a uniform shift to the additional point features of point clouds (e.g., reflection intensity) widely utilized as part of inputs for 3D DNNs as the trigger. Without altering the geometric information of the point clouds, our attack ensures visual consistency between poisoned and benign samples, and demonstrate robustness against preprocessing-based defenses. In addition, to automate our attack, we employ Bayesian Optimization (BO) to identify the suitable trigger. Extensive experiments suggest that SRBA achieves an attack success rate (ASR) exceeding 94% in all cases, and significantly outperforms previous SOTA methods when multiple preprocessing operations are applied during training.
format Preprint
id arxiv_https___arxiv_org_abs_2412_07511
institution arXiv
publishDate 2024
record_format arxiv
spellingShingle Stealthy and Robust Backdoor Attack against 3D Point Clouds through Additional Point Features
Ning, Xiaoyang
Xie, Qing
Xu, Jinyu
Jiang, Wenbo
Li, Jiachen
Ma, Yanchun
Computer Vision and Pattern Recognition
Recently, 3D backdoor attacks have posed a substantial threat to 3D Deep Neural Networks (3D DNNs) designed for 3D point clouds, which are extensively deployed in various security-critical applications. Although the existing 3D backdoor attacks achieved high attack performance, they remain vulnerable to preprocessing-based defenses (e.g., outlier removal and rotation augmentation) and are prone to detection by human inspection. In pursuit of a more challenging-to-defend and stealthy 3D backdoor attack, this paper introduces the Stealthy and Robust Backdoor Attack (SRBA), which ensures robustness and stealthiness through intentional design considerations. The key insight of our attack involves applying a uniform shift to the additional point features of point clouds (e.g., reflection intensity) widely utilized as part of inputs for 3D DNNs as the trigger. Without altering the geometric information of the point clouds, our attack ensures visual consistency between poisoned and benign samples, and demonstrate robustness against preprocessing-based defenses. In addition, to automate our attack, we employ Bayesian Optimization (BO) to identify the suitable trigger. Extensive experiments suggest that SRBA achieves an attack success rate (ASR) exceeding 94% in all cases, and significantly outperforms previous SOTA methods when multiple preprocessing operations are applied during training.
title Stealthy and Robust Backdoor Attack against 3D Point Clouds through Additional Point Features
topic Computer Vision and Pattern Recognition
url https://arxiv.org/abs/2412.07511