Stealthy and Robust Backdoor Attack against 3D Point Clouds through Additional Point Features

  • 2024-12-10 13:48:11
  • Xiaoyang Ning, Qing Xie, Jinyu Xu, Wenbo Jiang, Jiachen Li, Yanchun Ma
  • 0

Abstract

Recently, 3D backdoor attacks have posed a substantial threat to 3D DeepNeural Networks (3D DNNs) designed for 3D point clouds, which are extensivelydeployed in various security-critical applications. Although the existing 3Dbackdoor attacks achieved high attack performance, they remain vulnerable topreprocessing-based defenses (e.g., outlier removal and rotation augmentation)and are prone to detection by human inspection. In pursuit of a morechallenging-to-defend and stealthy 3D backdoor attack, this paper introducesthe Stealthy and Robust Backdoor Attack (SRBA), which ensures robustness andstealthiness through intentional design considerations. The key insight of ourattack involves applying a uniform shift to the additional point features ofpoint clouds (e.g., reflection intensity) widely utilized as part of inputs for3D DNNs as the trigger. Without altering the geometric information of the pointclouds, our attack ensures visual consistency between poisoned and benignsamples, and demonstrate robustness against preprocessing-based defenses. Inaddition, to automate our attack, we employ Bayesian Optimization (BO) toidentify the suitable trigger. Extensive experiments suggest that SRBA achievesan attack success rate (ASR) exceeding 94% in all cases, and significantlyoutperforms previous SOTA methods when multiple preprocessing operations areapplied during training.