Invisible Backdoor Attack against 3D Point Cloud Classifier in Graph Spectral Domain

Authors

  • Linkun Fan School of Computer Science, Wuhan University
  • Fazhi He School of Computer Science, Wuhan University
  • Tongzhen Si School of Information Science and Engineering, University of Ninan
  • Wei Tang School of Computer Science, Wuhan University
  • Bing Li School of Computer Science, Wuhan University Hubei Luojia Laboratory

DOI:

https://doi.org/10.1609/aaai.v38i19.30099

Keywords:

General

Abstract

3D point cloud has been wildly used in security crucial domains, such as self-driving and 3D face recognition. Backdoor attack is a serious threat that usually destroy Deep Neural Networks (DNN) in the training stage. Though a few 3D backdoor attacks are designed to achieve guaranteed attack efficiency, their deformation will alarm human inspection. To obtain invisible backdoored point cloud, this paper proposes a novel 3D backdoor attack, named IBAPC, which generates backdoor trigger in the graph spectral domain. The effectiveness is grounded by the advantage of graph spectral signal that it can induce both global structure and local points to be responsible for the caused deformation in spatial domain. In detail, a new backdoor implanting function is proposed whose aim is to transform point cloud to graph spectral signal for conducting backdoor trigger. Then, we design a backdoor training procedure which updates the parameter of backdoor implanting function and victim 3D DNN alternately. Finally, the backdoored 3D DNN and its associated backdoor implanting function is obtained by finishing the backdoor training procedure. Experiment results suggest that IBAPC achieves SOTA attack stealthiness from three aspects including objective distance measurement, subjective human evaluation, graph spectral signal residual. At the same time, it obtains competitive attack efficiency. The code is available at https://github.com/f-lk/IBAPC.

Published

2024-03-24

How to Cite

Fan, L., He, F., Si, T., Tang, W., & Li, B. (2024). Invisible Backdoor Attack against 3D Point Cloud Classifier in Graph Spectral Domain. Proceedings of the AAAI Conference on Artificial Intelligence, 38(19), 21072-21080. https://doi.org/10.1609/aaai.v38i19.30099

Issue

Section

AAAI Technical Track on Safe, Robust and Responsible AI Track