<p>3D vision recognition offers a significantly more robust tool for achieving machine cognition compared to traditional 2D vision techniques. However, similar to the vulnerabilities present in 2D vision, many 3D vision recognition applications, including point cloud classification models, are susceptible to degradation when confronted with imperceptible outliers. Outliers have a considerable impact on the performance and accuracy of models, compromising their overall effectiveness. Existing 3D point cloud attack and defense strategies neglect outliers and overlook the crucial impact of 3D printability in real-world scenarios. Neglecting this aspect hinders the consideration of potential manipulation or alteration of 3D objects in the physical realm, posing significant implications for the security and robustness of 3D vision systems. This manuscript presents a novel and effective targeted attack framework called synthesizing geometry and geodesic attack (SGGAA). It offers an alternative adversarial training algorithm that bridges the gap between the digital and physical domains. SGGAA introduces a novel generalized distance metric, facilitating the design of powerful and simple techniques for generating adversarial samples and improving the training process. It focuses on the regularizer loss object in synthesizing attack modes for mesh and point cloud spaces, utilizing Hausdorff distance, geometry distance, and geodesic distance losses. Comprehensive evaluations, including hyperparameter tuning, qualitative analysis, and quantitative experiments, were conducted to assess SGGAA’s performance. The results demonstrated its superiority, with high attack success rates, excellent geometric similarity scores, and outperformance of state-of-the-art attack strategies across various 3D defense techniques.</p>

错误:搜索内容不能为空,请输入英文关键词
错误:关键词超出字数限制,请精简
高级检索

SGGAA: a robust adversarial generation based on synthesizing point cloud and mesh space

  • Ruihan Hu,
  • Rui Yang

摘要

3D vision recognition offers a significantly more robust tool for achieving machine cognition compared to traditional 2D vision techniques. However, similar to the vulnerabilities present in 2D vision, many 3D vision recognition applications, including point cloud classification models, are susceptible to degradation when confronted with imperceptible outliers. Outliers have a considerable impact on the performance and accuracy of models, compromising their overall effectiveness. Existing 3D point cloud attack and defense strategies neglect outliers and overlook the crucial impact of 3D printability in real-world scenarios. Neglecting this aspect hinders the consideration of potential manipulation or alteration of 3D objects in the physical realm, posing significant implications for the security and robustness of 3D vision systems. This manuscript presents a novel and effective targeted attack framework called synthesizing geometry and geodesic attack (SGGAA). It offers an alternative adversarial training algorithm that bridges the gap between the digital and physical domains. SGGAA introduces a novel generalized distance metric, facilitating the design of powerful and simple techniques for generating adversarial samples and improving the training process. It focuses on the regularizer loss object in synthesizing attack modes for mesh and point cloud spaces, utilizing Hausdorff distance, geometry distance, and geodesic distance losses. Comprehensive evaluations, including hyperparameter tuning, qualitative analysis, and quantitative experiments, were conducted to assess SGGAA’s performance. The results demonstrated its superiority, with high attack success rates, excellent geometric similarity scores, and outperformance of state-of-the-art attack strategies across various 3D defense techniques.