Explainability-aware one point attack for point cloud neural networks
Recent studies have shown an increased interest to investigate the reliability of point cloud networks by adversarial attacks. However, most of the existing studies aim to deceive humans, while few address the operation principles of the models themselves. In this work, we propose two adversarial methods: One Point Attack (OPA) and Critical Traversal Attack (CTA), which target the points crucial to predictions more precisely by incorporating explainability methods. Our results show that popular point cloud networks can be deceived with almost 100% success rate by shifting only one point from the input instance. We also show the interesting impact of different point attribution distributions on the adversarial robustness of point cloud networks. We discuss how our approaches facilitate the explainability study for point cloud networks. To the best of our knowledge, this is the first point-cloud-based adversarial approach concerning explainability. Our code is available at https://github.com/Explain3D/Exp-One-Point-Atk-PC.
- Published in:
Proceedings of the IEEE/CVF Winter Conference on Applications of Computer Vision (WACV) - Type:
Inproceedings - Authors:
Tan, Hanxiao; Kotthaus, Helena - Year:
2023
Citation information
Tan, Hanxiao; Kotthaus, Helena: Explainability-aware one point attack for point cloud neural networks, Proceedings of the IEEE/CVF Winter Conference on Applications of Computer Vision (WACV), 2023, https://openaccess.thecvf.com/content/WACV2023/html/Tan_Explainability-Aware_One_Point_Attack_for_Point_Cloud_Neural_Networks_WACV_2023_paper.html, Tan.Kotthaus.2023a,
@Inproceedings{Tan.Kotthaus.2023a,
author={Tan, Hanxiao; Kotthaus, Helena},
title={Explainability-aware one point attack for point cloud neural networks},
booktitle={Proceedings of the IEEE/CVF Winter Conference on Applications of Computer Vision (WACV)},
url={https://openaccess.thecvf.com/content/WACV2023/html/Tan_Explainability-Aware_One_Point_Attack_for_Point_Cloud_Neural_Networks_WACV_2023_paper.html},
year={2023},
abstract={Recent studies have shown an increased interest to investigate the reliability of point cloud networks by adversarial attacks. However, most of the existing studies aim to deceive humans, while few address the operation principles of the models themselves. In this work, we propose two adversarial methods: One Point Attack (OPA) and Critical Traversal Attack (CTA), which target the points crucial...}}