JOURNAL ARTICLE

A Backdoor Attack against 3D Point Cloud Classifiers

Zhen XiangDavid J. MillerSiheng ChenXi LiGeorge Kesidis

Year: 2021 Journal:   2021 IEEE/CVF International Conference on Computer Vision (ICCV) Pages: 7577-7587

Abstract

Vulnerability of 3D point cloud (PC) classifiers has become a grave concern due to the popularity of 3D sensors in safety-critical applications. Existing adversarial attacks against 3D PC classifiers are all test-time evasion (TTE) attacks that aim to induce test-time misclassifications using knowledge of the classifier. But since the victim classifier is usually not accessible to the attacker, the threat is largely diminished in practice, as PC TTEs typically have poor transferability. Here, we propose the first backdoor attack (BA) against PC classifiers. Originally proposed for images, BAs poison the victim classifier's training set so that the classifier learns to decide to the attacker's target class whenever the attacker's backdoor pattern is present in a given input sample. Significantly, BAs do not require knowledge of the victim classifier. Different from image BAs, we propose to insert a cluster of points into a PC as a robust backdoor pattern customized for 3D PCs. Such clusters are also consistent with a physical attack (i.e., with a captured object in a scene). We optimize the cluster's location using an independently trained surrogate classifier and choose the cluster's local geometry to evade possible PC preprocessing and PC anomaly detectors (ADs). Experimentally, our BA achieves a uniformly high success rate (> 87%) and shows evasiveness against state-of-the-art PC ADs.

Keywords:
Backdoor Classifier (UML) Computer science Flagging Artificial intelligence Preprocessor Intrusion detection system Machine learning Pattern recognition (psychology) Computer security Geography

Metrics

5
Cited By
0.49
FWCI (Field Weighted Citation Impact)
62
Refs
0.66
Citation Normalized Percentile
Is in top 1%
Is in top 10%

Citation History

Topics

Adversarial Robustness in Machine Learning
Physical Sciences →  Computer Science →  Artificial Intelligence
Forensic Fingerprint Detection Methods
Social Sciences →  Social Sciences →  Safety Research
Integrated Circuits and Semiconductor Failure Analysis
Physical Sciences →  Engineering →  Electrical and Electronic Engineering

Related Documents

JOURNAL ARTICLE

Detecting Backdoor Attacks against Point Cloud Classifiers

Zhen XiangDavid J. MillerSiheng ChenXi LiGeorge Kesidis

Journal:   ICASSP 2022 - 2022 IEEE International Conference on Acoustics, Speech and Signal Processing (ICASSP) Year: 2022 Pages: 3159-3163
JOURNAL ARTICLE

Invisible Backdoor Attack against 3D Point Cloud Classifier in Graph Spectral Domain

Linkun FanFazhi HeTongzhen SiWei TangBing Li

Journal:   Proceedings of the AAAI Conference on Artificial Intelligence Year: 2024 Vol: 38 (19)Pages: 21072-21080
JOURNAL ARTICLE

Imperceptible and Robust Backdoor Attack in 3D Point Cloud

Kuofeng GaoJiawang BaiBaoyuan WuMengxi YaShu‐Tao Xia

Journal:   IEEE Transactions on Information Forensics and Security Year: 2023 Vol: 19 Pages: 1267-1282
JOURNAL ARTICLE

Exploring adversarial attacks against malware classifiers in the backdoor poisoning attack

Gopaldinne Sanjeev ReddySripada Manasa Lakshmi

Journal:   IOP Conference Series Materials Science and Engineering Year: 2021 Vol: 1022 (1)Pages: 012037-012037
© 2026 ScienceGate Book Chapters — All rights reserved.