22/11/2021

On Adversarial Robustness of 3D Point Cloud Classification under Adaptive Attacks

Jiachen Sun, Karl Koenig, Yulong Cao, Qi Alfred Chen, Zhuoqing Morley Mao

Keywords: point cloud classification, adversarial training, adaptive attack

Abstract: 3D point clouds are playing pivotal roles in many safety-critical applications like autonomous driving, where adversarially robust 3D deep learning models are desired. In this study, we conduct the first security analysis of state-of-the-art (SOTA) defenses against 3D adversarial attacks and design adaptive evaluations on them. Our 100% adaptive attack success rates demonstrate that SOTA countermeasures are still fragile. We further present an in-depth study showing how adversarial training (AT) performs in point cloud classification and identify that the required symmetric function (pooling operation) is paramount to 3D models' robustness. Through systematic analysis, we unveil that the default-used fixed pooling (e.g., MAX pooling) generally weakens AT's effectiveness. Interestingly, we also discover that sorting-based parametric pooling significantly improves the models' robustness. Based on the above insights, we propose DeepSym, a deep symmetric pooling operation, to architecturally advance the robustness of PointNet to 47.0% under AT without sacrificing nominal accuracy, outperforming the original design and a strong baseline by +28.5% (~ 2.6x) and +6.5%, respectively.

 0
 0
 0
 0
This is an embedded video. Talk and the respective paper are published at BMVC 2021 virtual conference. If you are one of the authors of the paper and want to manage your upload, see the question "My papertalk has been externally embedded..." in the FAQ section.

Comments

Post Comment
no comments yet
code of conduct: tbd Characters remaining: 140

Similar Papers