Deep neural networks have been demonstrated to be vulnerable to adversarial attacks. In 3D point cloud domain, although white-box attacks achieve high success rates, they often overfit to victim models, severely limiting the transferability in the black-box settings. To address this problem, we propose FART, a feature-level adversarial attack that enhances transferability through two key mechanisms: (1) Intermediate feature gradients-guided attacks, where perturbations are guided by gradients of the classification loss with respect to the intermediate features, reducing dependence on the full model by relying solely on partial intermediate layers. (2) Data augmentation-based gradient aggregation, which aggregates gradients from multiple geometrically transformed point clouds to introduce stochasticity and diversity, thereby preventing the adversarial examples from getting trapped in local optima. Experiments demonstrate that FART improves cross-model transferability by 15.5% on average over state-of-the-art attack methods.

错误:搜索内容不能为空,请输入英文关键词
错误:关键词超出字数限制,请精简
高级检索

FART-Attack: A Feature-Level Active Region Targeting Framework for Transferable Black-Box Adversarial Attacks on 3D Point Clouds

  • Xiongguan Qiu,
  • Jianhui Huo,
  • Zhaoyang Yu,
  • Weilong Peng

摘要

Deep neural networks have been demonstrated to be vulnerable to adversarial attacks. In 3D point cloud domain, although white-box attacks achieve high success rates, they often overfit to victim models, severely limiting the transferability in the black-box settings. To address this problem, we propose FART, a feature-level adversarial attack that enhances transferability through two key mechanisms: (1) Intermediate feature gradients-guided attacks, where perturbations are guided by gradients of the classification loss with respect to the intermediate features, reducing dependence on the full model by relying solely on partial intermediate layers. (2) Data augmentation-based gradient aggregation, which aggregates gradients from multiple geometrically transformed point clouds to introduce stochasticity and diversity, thereby preventing the adversarial examples from getting trapped in local optima. Experiments demonstrate that FART improves cross-model transferability by 15.5% on average over state-of-the-art attack methods.