A Survey of Adversarial Perturbations on 3D Point Clouds
Hak-Bum Lee, Hakgu Kim, Kyuhong LEE · TECHART Journal of Arts and Imaging Science · 2025
Recent advancements in 3D deep learning have led to the worldwide adoption of point cloud classifiers across domains, such as autonomous driving, robotics, and medical imaging. However, these models are highly vulnerable to adversarial attacks that introduce minimal perturbations to the point positions, leading to incorrect predictions. Even small geometric changes are visually apparent and difficult to conceal. Therefore, researchers have proposed a range of adversarial perturbations on 3D point clouds to evaluate the robustness of AI models and identify potential vulnerabilities while aiming to maximize imperceptibility and maintain high attack success rate. This study provides a comprehensive survey of recent techniques, categorizing them into five methodological groups: distance-based adversarial perturbation, normal vector-based adversarial perturbation, frequency-based adversarial perturbation, mesh-aware adversarial perturbation, and saliency-guided adversarial perturbation. For each category, we analyzed the core mechanisms, strengths, and limitations of generating visually plausible adversarial examples. Furthermore, we evaluated and compared state-of-the-art methods on the ModelNet40 dataset using standard classification backbones, and assessed their robustness under three widely used input restoration defenses.