On Adversarial Robustness of Point Cloud Semantic Segmentation

On Adversarial Robustness of Point Cloud Semantic Segmentation
复制标题

DOI:
10.1109/dsn58367.2023.00056
复制
发表时间:
2021-12
期刊:
2023 53rd Annual IEEE/IFIP International Conference on Dependable Systems and Networks (DSN)
影响因子:
--
通讯作者:
Jiacen Xu;Zhe Zhou;Boyuan Feng;Yufei Ding;Zhou Li
Jiacen Xu;Zhe Zhou;Boyuan Feng;Yufei Ding;Zhou Li
中科院分区:
其他
文献类型:
--
作者:
Jiacen Xu;Zhe Zhou;Boyuan Feng;Yufei Ding;Zhou Li

文献摘要

相似文献

最近的研究工作三维点云语义分割(PCSS)取得了优异的性能,采用神经网络。然而,这些复杂模型的鲁棒性还没有得到系统的分析。鉴于PCSS已应用于许多安全关键型应用,如自动驾驶,填补这一知识空白非常重要,特别是这些模型在对抗性样本下如何受到影响。因此,我们提出了PCSS鲁棒性的比较研究。首先,我们正式定义攻击者的目标下的性能下降和对象隐藏。然后,我们根据是否约束范数来开发新的攻击。我们在两个数据集和三个PCSS模型上评估了不同的攻击选项。我们发现所有的模型都是脆弱的,攻击点颜色是更有效的。通过这项研究,我们呼吁研究界注意开发新的方法来强化PCSS模型。
Recent research efforts on 3D point cloud semantic segmentation (PCSS) have achieved outstanding performance by adopting neural networks. However, the robustness of these complex models have not been systematically analyzed. Given that PCSS has been applied in many safety-critical applications like autonomous driving, it is important to fill this knowledge gap, especially, how these models are affected under adversarial samples. As such, we present a comparative study of PCSS robustness. First, we formally define the attacker's objective under performance degradation and object hiding. Then, we develop new attack by whether to bound the norm. We evaluate different attack options on two datasets and three PCSS models. We found all the models are vulnerable and attacking point color is more effective. With this study, we call the attention of the research community to develop new approaches to harden PCSS models.