PointBA: Towards Backdoor Attacks in 3D Point Cloud

📅 2021-03-30
🏛️ IEEE International Conference on Computer Vision
📈 Citations: 50
✨ Influential: 12
📄 PDF
🤖 AI Summary
This work presents the first systematic study of backdoor attacks against 3D point cloud models, revealing their superior stealth and threat compared to adversarial attacks. To address this, we propose PointBA—a unified backdoor attack framework supporting both poison-label (PointPBA) and clean-label (PointCBA) paradigms—leveraging spatial transformation vulnerabilities and feature disentanglement for highly stealthy, optimization-friendly backdoor embedding. PointBA is the first dual-paradigm backdoor framework tailored for point clouds and the first to introduce backdoor attacks into 3D deep learning. Extensive experiments demonstrate that PointPBA achieves >95% attack success rate across multiple datasets and models, while PointCBA attains ~50% success with significantly enhanced stealth. This work establishes a benchmark attack methodology for robustness evaluation of 3D models and delivers critical security insights for the emerging field of 3D machine learning.
📝 Abstract
3D deep learning has been increasingly more popular for a variety of tasks including many safety-critical applications. However, recently several works raise the security issues of 3D deep models. Although most of them consider adversarial attacks, we identify that backdoor attack is indeed a more serious threat to 3D deep learning systems but remains unexplored. We present the backdoor attacks in 3D point cloud with a unified framework that exploits the unique properties of 3D data and networks. In particular, we design two attack approaches on point cloud: the poison-label backdoor attack (PointPBA) and the clean- label backdoor attack (PointCBA). The first one is straight-forward and effective in practice, while the latter is more sophisticated assuming there are certain data inspections. The attack algorithms are mainly motivated and developed by 1) the recent discovery of 3D adversarial samples suggesting the vulnerability of deep models under spatial transformation; 2) the proposed feature disentanglement technique that manipulates the feature of the data through optimization methods and its potential to embed a new task. Extensive experiments show the efficacy of the PointPBA with over 95% success rate across various 3D datasets and models, and the more stealthy PointCBA with around 50% success rate. Our proposed backdoor attack in 3D point cloud is expected to perform as a baseline for improving the robustness of 3D deep models.
Problem

Research questions and friction points this paper is trying to address.

Exploring backdoor attacks in 3D point cloud deep learning systems
Designing poison-label and clean-label backdoor attacks for 3D data
Assessing attack success rates on various 3D datasets and models
Innovation

Methods, ideas, or system contributions that make the work stand out.

Unified framework for 3D point cloud backdoor attacks
Poison-label and clean-label attack approaches
Feature disentanglement technique for embedding tasks
🔎 Similar Papers
No similar papers found.
💼 Related Jobs
No related jobs found.
National University of Singapore | Southwest Jiaotong University | Institute of High Performance Computing
X
Xinke Li
National University of Singapore
Zhirui Chen
Zhirui Chen
National University of Singapore
Reinforcement LearningLarge Language Model3D Computer Vision
Y
Yue Zhao
National University of Singapore
Zekun Tong
Zekun Tong
National University of Singapore
Y
Yabang Zhao
National University of Singapore
A
A. Lim
Southwest Jiaotong University
Joey Tianyi Zhou
Joey Tianyi Zhou
A*STAR and NUS
Efficient AIRobust & Safe AI