Revisiting Adversarial Robustness in Large-Scale 3-D Vision–Language Models
Abstract
Pre-trained 3D vision-language models have demonstrated strong semantic generalization and robustness to distribution shifts. However, the implications of semantic robustness for geometric stability remain unclear. This study revisits the adversarial robustness of 3D vision-language models when confronted with adversarial point clouds. Focusing on zero-shot classification, this study demonstrates that these models exhibit heightened sensitivity to small coordinate perturbations. The behavior of adversarial perturbations is further analyzed under widely used point-cloud preprocessing mechanisms, revealing that naive filtering or reconstruction mainly suppresses irregular perturbations produced by vanilla gradient-based attacks and provides limited protection against stronger attack methods. To this end, a refined adversarial objective is introduced with two complementary priors that encourage adversarial point clouds to remain smooth and geometrically plausible: a statistical prior that regularizes the sampling distribution, and a geometric prior that promotes consistency with a plausible object-surface manifold. These findings highlight the need for a more rigorous security evaluation of 3D vision-language models.