arXivDaily arXiv每日学术速递 周一至周五更新
arXiv周末暂无论文更新,休息一下吧,周末愉快~~
arXiv 2609.33569cs.CR

信息黑洞:探索三维点云重建中的后门机制

Information Blackhole: Exploring Backdoor Mechanism in 3D Point Cloud Reconstruction

Zhifei Yang, Xiuping Liu, Kuofeng Gao, Junkai Qiu, Meng Liu, Yuhao Bian

首次发表
浏览论文内容

中文总结 AI 辅助

针对点云自编码器后门攻击研究空白,提出信息黑洞原理与自适应高斯匹配方法,通过解耦潜在表示抑制源信息泄漏,提升攻击可控性,并在ModelNet和ShapeNetPart上验证了有效性。

中文摘要 AI 辅助

点云自编码器是三维世界表示的基础组件,支撑着许多安全关键的下游应用。现有研究已广泛探讨了点云分类中的后门攻击,但针对点云自编码器的后门攻击在很大程度上仍未得到探索。然而,由于判别模型与生成模型之间存在内在的结构差异,它们的后门行为截然不同。具体而言,分类器是一种判别模型,分别拟合良性和恶意数据的边缘分布。相比之下,自编码器的生成特性将两者纠缠在统一的潜在分布中,导致信息串扰并降低攻击可控性。在此背景下,恶意数据中残留的源几何信息可能泄漏到干净的推理分支,导致重建结果向源数据坍缩。为此,我们提出信息黑洞原理,引入高斯分布约束以解耦潜在表示并阻断干扰信息。基于该原理,我们进一步提出自适应高斯匹配(AGM),显式正则化中毒样本的潜在分布。通过抑制源几何信息从中毒特征向攻击者指定的重建目标传播,AGM提高了攻击可控性。在ModelNet和ShapeNetPart上的大量定量和定性实验表明,所提出的框架提升了几种标准触发器的攻击性能,并揭示了针对点云自编码器的后门攻击的独特运作机制。

英文摘要

Point cloud autoencoders are fundamental components for 3D world representation and support many safety-critical downstream applications. Existing studies have extensively investigated backdoor attacks on point cloud classification, whereas backdoor attacks against point cloud autoencoders remain largely unexplored. However, their backdoor behaviors differ substantially due to the intrinsic structural gap between discriminative and generative models. Specifically, a classifier is a discriminative model that separately fits the marginal distributions of benign and malicious data. In contrast, the generative nature of an autoencoder entangles the two within a unified latent distribution, leading to information crosstalk and reduced attack controllability. In this setting, residual source geometric information in malicious data may leak into the clean inference branch, causing the reconstruction to collapse toward the source data. We then propose the Information Blackhole principle, which introduces Gaussian distribution constraints to disentangle latent representations and block interfering information. Building on this principle, we further propose Adaptive Gaussian Matching (AGM), which explicitly regularizes the latent distribution of poisoned samples. By suppressing the propagation of source geometric information from poisoned features to the attacker-specified reconstruction target, AGM improves attack controllability. Extensive quantitative and qualitative experiments on ModelNet and ShapeNetPart demonstrate that the proposed framework improves the attack performance of several standard triggers and reveals the unique operating mechanisms of backdoor attacks against point cloud autoencoders.

发表机构

  • Dalian University of Technology(大连理工大学)
  • Tsinghua Shenzhen International Graduate School, Tsinghua University(清华大学深圳国际研究生院)
  • Shandong University(山东大学)

机构由 AI 辅助整理,请以论文原文为准。

↑