🤖 AI Summary
This study addresses the entanglement of benign and malicious latent distributions and information crosstalk caused by generative models in backdoor attacks against 3D point cloud autoencoders. To overcome these issues, we propose the "information black hole" principle, which leverages Gaussian constraints to decouple latent representations and prevent the leakage of source geometric information. Furthermore, we introduce a novel adaptive Gaussian matching algorithm to mitigate reconstruction collapse. Extensive experiments on the ModelNet and ShapeNetPart datasets demonstrate that our approach significantly outperforms standard trigger baselines. This work reveals fundamental differences in the backdoor mechanisms of generative models and establishes a new paradigm for efficient and controllable backdoor attacks targeting point cloud reconstruction tasks.
📝 Abstract
Point cloud autoencoders are fundamental components for 3D world representation and support many safety-critical downstream applications. Existing studies have extensively investigated backdoor attacks on point cloud classification, whereas backdoor attacks against point cloud autoencoders remain largely unexplored. However, their backdoor behaviors differ substantially due to the intrinsic structural gap between discriminative and generative models. Specifically, a classifier is a discriminative model that separately fits the marginal distributions of benign and malicious data. In contrast, the generative nature of an autoencoder entangles the two within a unified latent distribution, leading to information crosstalk and reduced attack controllability. In this setting, residual source geometric information in malicious data may leak into the clean inference branch, causing the reconstruction to collapse toward the source data. We then propose the Information Blackhole principle, which introduces Gaussian distribution constraints to disentangle latent representations and block interfering information. Building on this principle, we further propose Adaptive Gaussian Matching (AGM), which explicitly regularizes the latent distribution of poisoned samples. By suppressing the propagation of source geometric information from poisoned features to the attacker-specified reconstruction target, AGM improves attack controllability. Extensive quantitative and qualitative experiments on ModelNet and ShapeNetPart demonstrate that the proposed framework improves the attack performance of several standard triggers and reveals the unique operating mechanisms of backdoor attacks against point cloud autoencoders.