Crafting Transferable Adversarial Examples Against 3D Object Detection

Haiyan Long, Chen Hai, Mengyao Xu, Chonghao Zhang, Fulan Qian · IET Computer Vision · 2025

ABSTRACT 3D object detection is one of the current popular hotspots by perceiving the surrounding environment through LiDAR and camera sensors to recognise the category and location of objects in the scene. Deep neural networks (DNNs) have been found to be vulnerable to adversarial examples. Although some approaches have begun to investigate the robustness of 3D object detection models, they are currently generating adversarial examples in a white‐box setting and there is a lack of research into generating transferable adversarial examples in a black‐box setting. In this paper, a non‐end‐to‐end attack algorithm was proposed for LiDAR pipelines that crafts transferable adversarial examples against 3D object detection. Specifically, the method generates adversarial examples by restraining features with high contribution to downstream tasks and amplifying features with low contribution to downstream tasks in the feature space. Extensive experiments validate that the method produces more transferable adversarial point clouds, for example, the method generates adversarial point clouds in the nuScenes dataset that are about 10 and 7 better than the state‐of‐the‐art method on mAP and NDS, respectively.

Read the paper · More papers on PaperTik