Imperceptible and Robust Backdoor Attack in 3D Point Cloud

后门 计算机科学 点云 转化(遗传学) 人工智能 构造(python库) 旋转(数学) 云计算 算法 计算机安全 程序设计语言 生物化学 基因 操作系统 化学
作者
Kuofeng Gao,Jiawang Bai,Baoyuan Wu,Mengxi Ya,Shu‐Tao Xia
出处
期刊:IEEE Transactions on Information Forensics and Security [Institute of Electrical and Electronics Engineers]
卷期号:19: 1267-1282 被引量:28
标识
DOI:10.1109/tifs.2023.3333687
摘要

With the thriving of deep learning in processing point cloud data, recent works show that backdoor attacks pose a severe security threat to 3D vision applications. The attacker injects the backdoor into the 3D model by poisoning a few training samples with trigger, such that the backdoored model performs well on clean samples but behaves maliciously when the trigger pattern appears. Existing attacks often insert some additional points into the point cloud as the trigger, or utilize a linear transformation (e.g., rotation) to construct the poisoned point cloud. However, the effects of these poisoned samples are likely to be weakened or even eliminated by some commonly used pre-processing techniques for 3D point cloud, e.g., outlier removal or rotation augmentation. In this paper, we propose a novel imperceptible and robust backdoor attack (IRBA) to tackle this challenge. We utilize a nonlinear and local transformation, called weighted local transformation (WLT), to construct poisoned samples with unique transformations. As there are several hyper-parameters and randomness in WLT, it is difficult to produce two similar transformations. Consequently, poisoned samples with unique transformations are likely to be resistant to aforementioned pre-processing techniques. Besides, the distortion caused by a fixed WLT is both controllable and smooth, resulting in the generated poisoned samples that are imperceptible to human inspection. Extensive experiments on three benchmark datasets and four models show that IRBA achieves $80\%+$ attack success rate (ASR) in most cases even with pre-processing techniques, which is significantly higher than previous state-of-the-art attacks. Our code is available at https://github.com/KuofengGao/IRBA .
最长约 10秒,即可获得该文献文件

科研通智能强力驱动
Strongly Powered by AbleSci AI
科研通是完全免费的文献互助平台,具备全网最快的应助速度,最高的求助完成率。 对每一个文献求助,科研通都将尽心尽力,给求助人一个满意的交代。
实时播报
今后应助shizumi采纳,获得30
刚刚
背后艳完成签到 ,获得积分10
刚刚
SIC完成签到,获得积分10
刚刚
梦里潇湘发布了新的文献求助10
刚刚
背后艳完成签到 ,获得积分10
刚刚
背后艳完成签到 ,获得积分10
刚刚
DPBHX发布了新的文献求助10
1秒前
情怀应助1c采纳,获得10
1秒前
Raven发布了新的文献求助10
2秒前
打打应助阳光明媚采纳,获得10
2秒前
完美世界应助随便填填采纳,获得10
2秒前
bubu完成签到,获得积分10
3秒前
苏七本柒发布了新的文献求助10
4秒前
孤独雨梅发布了新的文献求助10
4秒前
nono1031完成签到,获得积分10
4秒前
月悦完成签到,获得积分10
4秒前
充电宝应助AiHaraNeko采纳,获得10
5秒前
5秒前
sansronds完成签到,获得积分10
6秒前
6秒前
7秒前
我是老大应助唐盼烟采纳,获得10
7秒前
八雲家の式神完成签到,获得积分10
7秒前
7秒前
7秒前
8秒前
8秒前
NexusExplorer应助Zever采纳,获得200
8秒前
8秒前
8秒前
9秒前
ding应助qi采纳,获得10
9秒前
充电宝应助凡凡没烦恼采纳,获得10
9秒前
Dotson完成签到 ,获得积分10
9秒前
小赵发布了新的文献求助10
10秒前
龚旺旺应助Raven采纳,获得30
10秒前
龚旺旺应助Raven采纳,获得30
10秒前
酷波er应助SiDi采纳,获得10
10秒前
miaojiakun发布了新的文献求助30
11秒前
领导范儿应助app采纳,获得10
11秒前
高分求助中
(应助此贴封号)【重要!!请各用户(尤其是新用户)详细阅读】【科研通的精品贴汇总】 10000
The Organometallic Chemistry of the Transition Metals 800
Chemistry and Physics of Carbon Volume 18 800
The Organometallic Chemistry of the Transition Metals 800
Leading Academic-Practice Partnerships in Nursing and Healthcare: A Paradigm for Change 800
The formation of Australian attitudes towards China, 1918-1941 640
Signals, Systems, and Signal Processing 610
热门求助领域 (近24小时)
化学 材料科学 医学 生物 纳米技术 工程类 有机化学 化学工程 生物化学 计算机科学 物理 内科学 复合材料 催化作用 物理化学 光电子学 电极 细胞生物学 基因 无机化学
热门帖子
关注 科研通微信公众号,转发送积分 6438535
求助须知:如何正确求助?哪些是违规求助? 8252623
关于积分的说明 17561862
捐赠科研通 5496842
什么是DOI,文献DOI怎么找? 2898983
邀请新用户注册赠送积分活动 1875671
关于科研通互助平台的介绍 1716475