This work introduces SpecEOT, a source-agnostic and graph-spectral expectation-over-transformation attack that achieves strong transferability on ModelNet40 and ShapeNet and evaluates the stochastic method over repeated seeds, extend the ablation to two source architectures, and analyze the interaction between band count and randomization strength.
Abstract
Point cloud perception is important in autonomous driving, robotics, and other security-critical 3D systems, yet learned point cloud classifiers remain vulnerable to transferable adversarial perturbations. A central difficulty in transfer-based black-box attacks is surrogate overfitting: an update that is highly effective on an accessible source model may not generalize to an unknown target architecture. We introduce SpecEOT, a source-agnostic and graph-spectral expectation-over-transformation attack. A fixed graph Fourier transform (GFT) basis is constructed from each clean point cloud. At every optimization iteration, each non-identity view independently samples a frequency band and a perturbation sign from uniform distributions; the resulting view gradients are averaged with equal weights and used to update the adversarial point cloud through projected Adam ascent. We evaluate the stochastic method over repeated seeds, extend the ablation to two source architectures, and analyze the interaction between band count and randomization strength while reporting computational cost and assessing robustness to Gaussian jitter and point dropout. SpecEOT achieves strong transferability on ModelNet40 and ShapeNet.
Adversarial attacks on 3D point clouds offer different difficulties and benefits compared to the 2D image-based ones. In this work, we aim to promote the robustness of adversarial attack methods and therefore propose approaches that target subsets of critical points in point cloud with a focus on local structural rather than global topology. This approach differs from ported 2D image attack strategies, as we consider the specific properties of 3D data including irregularity, recursiveness and geometric complexity.
By disturbing point locals' part from the cloud, we want to generate more effective attacks that reveal weaknesses of 3D classifiers. The approach increases the effectiveness of adversarial attacks and takes into account differences in the structures used for representation of 3D data, which requires dedicated methods to successfully manipulate its sensitivity.
We also study the robustness of 3D point cloud classifiers against such targeted attacks. We analyze the vulnerabilities of classifiers when facing adversarial attacks under various attack strategies and verify strategies to make them more robust
Ahmed Hasan khanjar· Journal of the College of B...· 0 citations
FDT-PC (Frequency Domain Transformation with Perceptual Constraints), a novel method that enhances adversarial transferability across different model architectures, is proposed, which achieves superior black-box attack performance on both CNNs and Vision Transformers, outperforming existing state-of-the-art input transformation methods.
Bo Li, Li Tang, Xin Jin et al.· ACM Transactions on Multimed...· 0 citations
Season, a spectrum-aware orthogonal gradient refinement framework for L-infinity transfer attacks against black-box target models on ImageNet, using a white-box surrogate to improve transfer success rate.
Detecting localized morphological anomalies in three-dimensional point clouds is difficult because geometric deviations are entangled with rigid pose variation, residual registration error, sampling noise, and normal inter-subject variability. This challenge is particularly relevant in translational neuroimaging, where abnormal shape changes may be subtle and abnormal annotations are scarce. We propose an unsupervised framework that formulates 3D anomaly detection as a two-stage factorization problem, termed AdvFlow3D-AD. First, Fast Global Registration, followed by multi-scale Iterative Closest Point refinement, establishes a common geometric reference frame and reduces rigid-body nuisance variation. Second, an adversarially regularized normalizing flow models the residual distribution of aligned normal coordinates, enabling localized anomaly scores based on distance from the learned normal latent support. Percentile calibration on normal data then defines interpretable point-level and object-level operating points without requiring abnormal samples during training. We evaluate AdvFlow3D-AD on the Real3D-AD and Anomaly ShapeNet3D datasets, achieving a point-level area under the receiver operating characteristic curve (AUROC) of 0.747 on Real3D-AD and an object-level AUROC of 0.816 on Anomaly ShapeNet3D. We further present an exploratory neurodevelopmental brain-shape case study involving pediatric perinatal-asphyxia cases. The resulting anomaly maps showed qualitative spatial correspondence with anatomically plausible hippocampal and cerebellar regions under neuroradiological review. These results suggest that separating geometric nuisance variation from residual morphology can support interpretable anomaly localization when abnormal labels are limited.
A. Jiménez-García, Jonnatan Arias-Garcia, H. García et al.· Machine Learning and Knowled...· 0 citations
Deep learning has boosted remote sensing (RS) scene classification, but adversarial examples can still cause high-confidence misclassification with imperceptible perturbations. Adversarial purification (AP) offers a practical test-time defense without retraining the classifier. However, most existing methods are confined to pixel-space restoration, which may leave residual adversarial effects that persist and amplify through feature extraction, ultimately biasing the prediction. To address these issues, a dual-domain AP (DDAP) framework is proposed to mitigate adversarial effects at both the pixel and feature levels in a unified pipeline. In the pixel domain, a pixel-domain frequency-aware diffusion purification (PFDP) module performs diffusion-based restoration through a frequency-aware dual-stream U-Net (FD-UNet). By integrating adaptive spectral filtering with multidomain consistency constraints, PFDP reduces adversarial-perturbation-dominated high-frequency responses while preserving structural details and semantic information in RS imagery. In the feature domain, an adversarial vulnerable channel dropout (AVCD) strategy models unshifted shallow-feature statistics with a Gaussian mixture model (GMM) and adaptively assigns channelwise dropout probabilities based on a samplewise shift score and channel vulnerability, thereby suppressing residual adversarial influence before downstream classification. Extensive experiments on UC Merced (UCM) and aerial image dataset (AID) across multiple backbones and attack types demonstrate that DDAP consistently improves robustness while maintaining a favorable clean–robust balance compared with representative baselines.
Yuru Su, Shaohui Mei, Mingyang Ma et al.· IEEE Transactions on Geoscie...· 0 citations
Empirical support is provided for the utility of structure-aware perturbation refinement in improving black-box adversarial transferability across heterogeneous visual architectures.
Qi-Rui Lu, Liansong Zong, Fu-Ran Liu et al.· Neural Networks· 0 citations
We use cookies to run the site and, with your consent, for analytics and to show ads.
See our Cookie Policy.