arXivDaily arXiv每日学术速递 周一至周五更新
arXiv周末暂无论文更新,休息一下吧,周末愉快~~
arXiv 2608.29184cs.CR

GhostSplat:前馈高斯溅射中用于多视图一致3D内容操纵的输入触发后门

GhostSplat: Input-Triggered Backdoors for Multi-View-Consistent 3D Content Manipulation in Feed-Forward Gaussian Splatting

Yudong Gao, Zongjian Ding, Linghan Chen, Yajing Chen, Yu Xinglin, Jiale Liu, Shan Huang, Mingjun Cheng

首次发表
浏览论文内容

中文总结 AI 辅助

GhostSplat是针对前馈3D高斯溅射的输入触发后门,可植入共享生成器权重实现多视图一致的3D内容操纵,在多架构数据集上攻击成功率高且抗常见图像变换,现有防御措施无法有效应对。

中文摘要 AI 辅助

前馈3D高斯溅射(3DGS)可通过一次前向传播从稀疏图像重建3D场景,其共享的预训练权重也暴露了供应链攻击面。现有神经辐射场和3DGS后门会修改单个场景并在选定视点激活,无法在共享生成器权重中植入持久行为。本文提出GhostSplat,一种可在前馈3DGS中植入此类行为的输入触发后门:向输入图像添加低振幅图案,会使中毒的生成器在未见过的受害者场景上渲染攻击者选定的有效载荷;将有效载荷锚定到3D点并重新投影到每个目标视图,可使有效载荷具备多视图一致性;精确投影到生成器特定表示的一致性集合后,实现的有效载荷保持不变,因为输出已属于该集合。GhostSplat训练框架在三种架构(MVSplat、pixelSplat、DepthSplat)和两个数据集(RealEstate10K、ACID)上均有效,评估中最强的注入和删除设置分别达到96%和100%的攻击成功率(ASR),且未观察到误报,同时能抵御JPEG、模糊和重采样攻击。因此,仅使用精确投影的防御措施不足,有效缓解需要超出同集合一致性投影的信息或干预手段。

英文摘要

Feed-forward 3D Gaussian Splatting (3DGS) reconstructs a 3D scene from sparse images in one forward pass. Its shared pretrained weights also expose a supply-chain attack surface. Existing Neural Radiance Field and 3DGS backdoors modify individual scenes and activate at selected viewpoints; they do not install persistent behavior in shared generator weights. We introduce GhostSplat, an input-triggered backdoor that installs such behavior in feed-forward 3DGS. A low-amplitude pattern added to the input images causes the poisoned generator to render an attacker-chosen payload on unseen victim scenes. Anchoring the payload to a 3D point and reprojecting it into each target view makes the payload multi-view consistent. Exact projection onto the generator's representation-specific consistency set leaves a realized payload unchanged because the output already belongs to that set. The GhostSplat training framework succeeds across three architectures (MVSplat, pixelSplat, DepthSplat) and two datasets (RealEstate10K, ACID). Its strongest evaluated injection and deletion settings reach 96% and 100% ASR, respectively, with zero observed false positives while surviving JPEG, blur, and resampling. Defenses that use only that exact projection are therefore insufficient; effective mitigation requires information or intervention beyond same-set consistency projection.

补充信息

↑