In plain words: Attacks on 3D shape classifiers either nudge individual points slightly or warp the whole shape to fool the system. Some shape-warping tricks still fool the classifier even after defenses that delete suspicious points.
Abstract · Adversarial shape perturbations on 3D point clouds
The importance of training robust neural network grows as 3D data is increasingly utilized in deep learning for vision tasks in robotics, drone control, and autonomous driving. One commonly used 3D data type is 3D point clouds, which describe shape information. We examine the problem of creating robust models from the perspective of the attacker, which is necessary in understanding how 3D neural networks can be exploited. We explore two categories of attacks: distributional attacks that involve imperceptible perturbations to the distribution of points, and shape attacks that involve deforming the shape represented by a point cloud. We explore three possible shape attacks for attacking 3D point cloud classification and show that some of them are able to be effective even against preprocessing steps, like the previously proposed point-removal defenses.
Daniel Liu, Ronald Yu, Hao Su
arXiv:1908.06062 · cs.CV, cs.CR, cs.LG, eess.IV, stat.ML · submitted Aug 16, 2019 · updated Oct 23, 2020
abstract · pdf · html · 18 pages, accepted to the 2020 ECCV workshop on Adversarial Robustness in the Real World, source code available at this https url: https://github.com/Daniel-Liu-c0deb0t/Adversarial-point-perturbations-on-3D-objects
A high-level overview of the research:
Basically neural networks are weak against adversarial attacks that change the input by a little bit to cause the prediction to be wrong. We look at these adversarial attacks in 3D space, specifically on 3D point clouds (think LiDAR and RGB-D data). In the paper, four attacks in two different categories (distributional and shape attacks) are proposed. The main benefit of distributional attacks is their imperceptibility. On the other hand, shape attacks are more easily crafted in real-life (though more perceptible) and also robust against point removal defenses that were proposed in previous work. If you want a more comprehensive (but less dense than the paper) overview, take a look at my blog post [2].
[1] https://arxiv.org/abs/1901.03006
[2] https://blog.liudaniel.com/birth-of-a-new-sub-sub-field