Transferable Adversarial Attacks on 3-D Point Cloud Semantic Segmentation via Diffusion Models in Autonomous Driving
Yizhou Wang, Libing Wu, Zhuangzhuang Zhang, Lijuan Huo, Jiaqi Feng, Jing Wang, Jiong Jin
Wuhan University Huazhong University of Science and Technology Swinburne University of Technology
阅读操作
确认中在文库中上传 PDF 后可生成中文音频讲解。
摘要与影响
With the rapid advancement of LiDAR-based 3D semantic segmentation, it has provided effective support for comprehensive perception in autonomous driving. However, the vulnerabilities of existing segmentation models have not been fully explored, posing potential risks to the security of autonomous systems. Existing adversarial attacks on point cloud segmentation primarily focus on applying global perturbations to point coordinates, inevitably introducing noticeable outliers and resulting in suboptimal attack performance. Inspired by the remarkable performance of diffusion models in LiDAR scene completion tasks, we propose a novel adversarial attack framework using diffusion models targeting 3D semantic segmentation. First, we model forward and reverse diffusion processes for input point cloud scenes, then introduce targeted perturbations during the reverse diffusion sampling stage. Specifically, we initialize Gaussian noise and add it to partial input point clouds, followed by stepwise denoising for point cloud reconstruction. During each denoising step, we identify the most discrimination-sensitive critical points and apply adversarial gradients exclusively to these selected points for guiding updates. Furthermore, we design a triple-loss function to supervise adversarial point cloud generation, achieving a balance between attack performance and perturbation magnitude. Finally, we conduct comprehensive experiments on two autonomous driving datasets, SemanticKITTI and nuScenes. The experimental results indicate that our method delivers significant attack performance against six mainstream semantic segmentation models, with average relative mIoU drops reaching 61.14% and 51.55% respectively. Moreover, the proposed method successfully transfers to point cloud classification and part segmentation tasks, demonstrating superior attack performance and transferability.
逐年被引趋势
暂无年度引用数据
关键指标
同类平均 = 1
同领域 · 同年份 · 同类型
Google Scholar 与 OpenAlex 的被引统计范围不同,数值存在差异属正常。
AI 辅助阅读
依据:摘要
可就本文提问;依据不足时会说明。
学术脉络
学科主题
计算机 / AIAdversarial Robustness in Machine Learning
Autonomous Vehicle Technology and Safety · Advanced Neural Network Applications
参考文献 63
此处列出前 3 条