6DAttack: Backdoor Attacks in the 6DoF Pose Estimation

Fuente: arXiv
Enregistré dans:
Détails bibliographiques
Auteurs principaux: Guo, Jihui, Zhang, Zongmin, Sun, Zhen, Yang, Yuhao, Wu, Jinlin, Zhang, Fu, He, Xinlei
Format: Preprint
Publié: 2025
Sujets:
Accès en ligne:
Tags: Ajouter un tag
Pas de tags, Soyez le premier à ajouter un tag!
_version_ 1866914213993119744
author Guo, Jihui
Zhang, Zongmin
Sun, Zhen
Yang, Yuhao
Wu, Jinlin
Zhang, Fu
He, Xinlei
author_facet Guo, Jihui
Zhang, Zongmin
Sun, Zhen
Yang, Yuhao
Wu, Jinlin
Zhang, Fu
He, Xinlei
contents Deep learning advances have enabled accurate six-degree-of-freedom (6DoF) object pose estimation, widely used in robotics, AR/VR, and autonomous systems. However, backdoor attacks pose significant security risks. While most research focuses on 2D vision, 6DoF pose estimation remains largely unexplored. Unlike traditional backdoors that only change classes, 6DoF attacks must control continuous parameters like translation and rotation, rendering 2D methods inapplicable. We propose 6DAttack, a framework using 3D object triggers to induce controlled erroneous poses while maintaining normal behavior. Evaluations on PVNet, DenseFusion, and PoseDiffusion across LINEMOD, YCB-Video, and CO3D show high attack success rates (ASRs) without compromising clean performance. Backdoored models achieve up to 100% clean ADD accuracy and 100% ASR, with triggered samples reaching 97.70% ADD-P. Furthermore, a representative defense remains ineffective. Our findings reveal a serious, underexplored threat to 6DoF pose estimation.
format Preprint
id arxiv_https___arxiv_org_abs_2512_19058
institution arXiv
publishDate 2025
record_format arxiv
spellingShingle 6DAttack: Backdoor Attacks in the 6DoF Pose Estimation
Guo, Jihui
Zhang, Zongmin
Sun, Zhen
Yang, Yuhao
Wu, Jinlin
Zhang, Fu
He, Xinlei
Computer Vision and Pattern Recognition
Deep learning advances have enabled accurate six-degree-of-freedom (6DoF) object pose estimation, widely used in robotics, AR/VR, and autonomous systems. However, backdoor attacks pose significant security risks. While most research focuses on 2D vision, 6DoF pose estimation remains largely unexplored. Unlike traditional backdoors that only change classes, 6DoF attacks must control continuous parameters like translation and rotation, rendering 2D methods inapplicable. We propose 6DAttack, a framework using 3D object triggers to induce controlled erroneous poses while maintaining normal behavior. Evaluations on PVNet, DenseFusion, and PoseDiffusion across LINEMOD, YCB-Video, and CO3D show high attack success rates (ASRs) without compromising clean performance. Backdoored models achieve up to 100% clean ADD accuracy and 100% ASR, with triggered samples reaching 97.70% ADD-P. Furthermore, a representative defense remains ineffective. Our findings reveal a serious, underexplored threat to 6DoF pose estimation.
title 6DAttack: Backdoor Attacks in the 6DoF Pose Estimation
topic Computer Vision and Pattern Recognition
url https://arxiv.org/abs/2512.19058