On Multiview Robustness of 3D Adversarial Attacks

On Multiview Robustness of 3D Adversarial Attacks
复制标题

DOI:
10.1145/3311790.3396652
复制
发表时间:
2020-07
期刊:
Practice and Experience in Advanced Research Computing
影响因子:
--
通讯作者:
Philip Yao;Andrew So;Tingting Chen;Hao Ji
Philip Yao;Andrew So;Tingting Chen;Hao Ji
中科院分区:
其他
文献类型:
--
作者:
Philip Yao;Andrew So;Tingting Chen;Hao Ji

文献摘要

相似文献

目前,深度神经网络已广泛应用于计算机视觉的许多应用中,包括医疗诊断和自动驾驶汽车。然而,深度神经网络受到对抗性示例的威胁,通常在这些示例中,图像像素被扰动,人类无法察觉,但足以欺骗深度网络。与2D图像对抗示例相比,3D对抗模型在攻击过程中的侵入性更小,因此更真实。已经有许多关于生成3D对抗性示例的研究工作。在本文中,我们研究了3D对抗性攻击的鲁棒性时,受害者的相机被放置在不同的观点。特别是,我们找到了一种创建3D对抗性示例的方法,可以从任何整数球坐标的所有视点实现100%的攻击成功率。我们的方法很简单,因为我们只扰动纹理空间。我们使用来自多个未校准图像的3D重建来创建具有逼真纹理的3D模型。在可微分渲染器的帮助下,我们然后应用基于梯度的优化来基于一组渲染图像计算纹理扰动,即,训练数据集。我们大量的实验表明,即使只包括所有可能的渲染图像的1%在训练中,我们仍然可以达到99.9%的攻击成功率与训练的纹理扰动。此外,我们的全面实验表明,我们的3D对抗性攻击的多视图鲁棒性在各种最先进的深度神经网络模型中具有很高的可移植性。
Nowadays deep neural networks have been applied widely in many applications of computer vision including medical diagnosis and self-driving cars. However, deep neural networks are threatened by adversarial examples usually in which image pixels were perturbed unnoticeable to humans but enough to fool the deep networks. Compared to 2D image adversarial examples, 3D adversarial models are less invasive in the process of attacks, and thus more realistic. There have been many research works on generating 3D adversarial examples. In this paper, we study the robustness of 3D adversarial attacks when the victim camera is placed at different viewpoints. In particular, we find a method to create 3D adversarial examples that can achieve 100% attack success rate from all viewpoints with any integer spherical coordinates. Our method is simple as we only perturb the texture space. We create 3D models with realistic textures using 3D reconstruction from multiple uncalibrated images. With the help of a differentiable renderer, we then apply gradient based optimization to compute texture perturbations based on a set of rendered images, i.e., training dataset. Our extensive experiments show that even only including 1% of all possible rendered images in training, we can still achieve 99.9% attack success rate with the trained texture perturbations. Furthermore, our thorough experiments show high transferability of the multiview robustness of our 3D adversraial attacks across various state-of-the-art deep neural network models.