Abstract
Deep neural networks have made tremendous progress in 3D point-cloud recognition. Recent works have shown that these 3D recognition networks are also vulnerable to adversarial samples produced from various attack methods, including optimization-based 3D Carlini-Wagner attack, gradient-based iterative fast gradient method, and skeleton-detach based point-dropping. However, after a careful analysis, these methods are either extremely slow because of the optimization/iterative scheme, or not flexible to support targeted attack of a specific category. To overcome these shortcomings, this paper proposes a novel label guided adversarial network (LG-GAN) for real-time flexible targeted point cloud attack. To the best of our knowledge, this is the first generation based 3D point cloud attack method. By feeding the original point clouds and target attack label into LG-GAN, it can learn how to deform the point clouds to mislead the recognition network into the specific label only with a single forward pass. In detail, LG-GAN first leverages one multi-branch adversarial network to extract hierarchical features of the input point clouds, then incorporates the specified label information into multiple intermediate features using the label encoder. Finally, the encoded features will be fed into the coordinate reconstruction decoder to generate the target adversarial sample. By evaluating different point-cloud recognition models (e.g., PointNet, PointNet++ and DGCNN), we demonstrate that the proposed LG-GAN can support flexible targeted attack on the fly while guaranteeing good attack performance and higher efficiency simultaneously.
| Original language | English |
|---|---|
| Title of host publication | 2020 IEEE/CVF Conference on Computer Vision and Pattern Recognition, CVPR 2020 |
| Subtitle of host publication | Proceedings |
| Publisher | IEEE |
| Pages | 10353-10362 |
| ISBN (Electronic) | 978-1-7281-7168-5 |
| ISBN (Print) | 978-1-7281-7169-2 |
| DOIs | |
| Publication status | Published - Jun 2020 |
| Event | 2020 IEEE/CVF Conference on Computer Vision and Pattern Recognition (CVPR 2020) - Virtual, Seattle, United States Duration: 13 Jun 2020 → 19 Jun 2020 http://cvpr2020.thecvf.com/ http://openaccess.thecvf.com/content_CVPR_2020/html/Guo_Zero-Reference_Deep_Curve_Estimation_for_Low-Light_Image_Enhancement_CVPR_2020_paper.html https://ieeexplore.ieee.org/xpl/conhome/9142308/proceeding http://cvpr2021.thecvf.com/ https://ieeexplore.ieee.org/xpl/conhome/1000147/all-proceedings https://openaccess.thecvf.com/CVPR2021 |
Publication series
| Name | IEEE/CVF Conference on Computer Vision and Pattern Recognition, CVPR |
|---|---|
| Publisher | Institute of Electrical and Electronics Engineers |
| ISSN (Print) | 1063-6919 |
| ISSN (Electronic) | 2575-7075 |
Conference
| Conference | 2020 IEEE/CVF Conference on Computer Vision and Pattern Recognition (CVPR 2020) |
|---|---|
| Abbreviated title | CVPR2020 |
| Place | United States |
| City | Seattle |
| Period | 13/06/20 → 19/06/20 |
| Internet address |
|
Bibliographical note
Research Unit(s) information for this publication is provided by the author(s) concerned.Fingerprint
Dive into the research topics of 'LG-GAN: Label Guided Adversarial Network for Flexible Targeted Attack of Point Cloud Based Deep Networks'. Together they form a unique fingerprint.Cite this
- APA
- Author
- BIBTEX
- Harvard
- Standard
- RIS
- Vancouver