Less Is More: Sparse and Cooperative Perturbation for Point Cloud Attacks

Fuente: arXiv
Enregistré dans:
Détails bibliographiques
Auteurs principaux: Tang, Keke, Hao, Tianyu, Wang, Xiaofei, Peng, Weilong, Zhang, Denghui, Zhu, Peican, Tian, Zhihong
Format: Preprint
Publié: 2025
Sujets:
Accès en ligne:
Tags: Ajouter un tag
Pas de tags, Soyez le premier à ajouter un tag!
_version_ 1866909962954866688
author Tang, Keke
Hao, Tianyu
Wang, Xiaofei
Peng, Weilong
Zhang, Denghui
Zhu, Peican
Tian, Zhihong
author_facet Tang, Keke
Hao, Tianyu
Wang, Xiaofei
Peng, Weilong
Zhang, Denghui
Zhu, Peican
Tian, Zhihong
contents Most adversarial attacks on point clouds perturb a large number of points, causing widespread geometric changes and limiting applicability in real-world scenarios. While recent works explore sparse attacks by modifying only a few points, such approaches often struggle to maintain effectiveness due to the limited influence of individual perturbations. In this paper, we propose SCP, a sparse and cooperative perturbation framework that selects and leverages a compact subset of points whose joint perturbations produce amplified adversarial effects. Specifically, SCP identifies the subset where the misclassification loss is locally convex with respect to their joint perturbations, determined by checking the positivedefiniteness of the corresponding Hessian block. The selected subset is then optimized to generate high-impact adversarial examples with minimal modifications. Extensive experiments show that SCP achieves 100% attack success rates, surpassing state-of-the-art sparse attacks, and delivers superior imperceptibility to dense attacks with far fewer modifications.
format Preprint
id arxiv_https___arxiv_org_abs_2512_13119
institution arXiv
publishDate 2025
record_format arxiv
spellingShingle Less Is More: Sparse and Cooperative Perturbation for Point Cloud Attacks
Tang, Keke
Hao, Tianyu
Wang, Xiaofei
Peng, Weilong
Zhang, Denghui
Zhu, Peican
Tian, Zhihong
Cryptography and Security
Most adversarial attacks on point clouds perturb a large number of points, causing widespread geometric changes and limiting applicability in real-world scenarios. While recent works explore sparse attacks by modifying only a few points, such approaches often struggle to maintain effectiveness due to the limited influence of individual perturbations. In this paper, we propose SCP, a sparse and cooperative perturbation framework that selects and leverages a compact subset of points whose joint perturbations produce amplified adversarial effects. Specifically, SCP identifies the subset where the misclassification loss is locally convex with respect to their joint perturbations, determined by checking the positivedefiniteness of the corresponding Hessian block. The selected subset is then optimized to generate high-impact adversarial examples with minimal modifications. Extensive experiments show that SCP achieves 100% attack success rates, surpassing state-of-the-art sparse attacks, and delivers superior imperceptibility to dense attacks with far fewer modifications.
title Less Is More: Sparse and Cooperative Perturbation for Point Cloud Attacks
topic Cryptography and Security
url https://arxiv.org/abs/2512.13119