Provable Defense Against Clustering Attacks on 3D Point CloudsDownload PDF

22 Nov 2021, 06:35 (edited 09 Dec 2021)AAAI-22 AdvML Workshop LongPaperReaders: Everyone
  • Keywords: adversarial robustness, point cloud classification, randomized smoothing
  • Abstract: Lately, the literature on adversarial robustness spans from images to other domains such as point clouds. In this work, we consider clustering attacks on 3D point clouds and devise a provable defense mechanism to counter them. Specifically, we adopt a randomized smoothing strategy for 3D point clouds and derive a robustness certificate based on the cluster radius rather than the number of adversarial points. Our experiments on ModelNet40 and ScanObjectNN datasets using the PointNet classifier demonstrate the effectiveness of our defense mechanism against targeted and untargeted clustering attacks with a large number of adversarial points.
