Generating Transferable 3D Adversarial Point Clouds Based on Multi-Scale Features

Mengyao Xu, Fulan Qian, Yanping Zhang, Hai Chen, Yan Cui, Sha Xin Wei · 2024

Recent studies have shown that deep neural networks are vulnerable to adversarial attacks. In the task of 3D point cloud classification, transfer-based adversarial attack methods have attracted much attention. However, the adversarial point clouds generated by existing methods are usually overly dependent on the network structure of the surrogate model, resulting in poor transferability. Additionally, they generally adopt the strategy of directly deforming and optimizing the point cloud data, which limits their transferability. To address the above problems, we propose a novel 3D point cloud adversarial attack method based on multi-scale features of data, named MSFA. The method employs an autoencoder designed to extract multi-scale features from the point clouds and reconstruct them effectively. Furthermore, it efficiently identifies positive and negative features within the point cloud data by calculating the Shapley value and employs a feature loss to attack the features of the point cloud. This makes the adversarial point clouds not overly dependent on the network structure of the surrogate model and more concerned with their own features, thus enhancing the transferability. Extensive experiments are conducted on the well-recognized benchmark dataset, demonstrating the effectiveness of the proposed MSFA method in generating highly transferable adversarial point clouds.

Read the paper · More papers on PaperTik