Three-dimensional transferability confrontation sample generation method for intelligent driving

By combining decomposition perturbation strategies and the least possible class method, a three-dimensional point cloud adversarial sample with high attack success rate and transferability is generated, which solves the problem of limited transferability between different network architectures in the existing technology, and is suitable for practical application scenarios such as intelligent driving.

CN120219881APending Publication Date: 2025-06-27JIMEI UNIV +1
View PDF 0 Cites 2 Cited by

Patent Information

Application Number
CN202510301540.1
Authority / Receiving Office
CN · China
Patent Type
Applications(China)
Current Assignee / Owner
Filing Date
2025-03-14
Publication Date
2025-06-27

AI Technical Summary

Technical Problem

In the prior art, the transferability of three-dimensional point cloud adversarial attacks between different network architectures is limited, and there is little consideration for actual application scenarios, which hinders the application in fields such as intelligent driving.

Method used

By integrating the decomposition perturbation strategy and the least possible class method, a more attack success rate and transferability adversarial samples are generated. The specific steps include randomly decomposing the adversarial perturbation into multiple sub-perturbations and iteratively optimized using the probability predicted by the model, constraining the direction of the sub-perturbation to improve its transferability.

Benefits of technology

High attack success rate was achieved in multiple data sets and model experiments, improving the transferability of adversarial samples, and achieving high success rate attack effect on the actual traffic scene target recognition data set.

✦ Generated by Eureka AI based on patent content.

Smart Images

  • Figure CN120219881A_ABST
    Figure CN120219881A_ABST
Patent Text Reader

Abstract

The invention relates to a three-dimensional transferability adversarial sample generation method for intelligent driving, and belongs to the field of computer vision, three-dimensional point cloud and adversarial learning. According to the method, through fusion of a decomposition disturbance strategy and a least likelihood class method, a high attack success rate is realized under a plurality of data sets and a plurality of model experiments, and the transferability of an adversarial sample is improved; according to the method, an actual scene traffic object data set based on a KITTI street scene data set is further manufactured, sufficient training and testing are carried out on the data set, the high success rate of real traffic object target recognition attacks is achieved, and considerable transferable attacks are achieved on a plurality of victim models and agent models. According to the invention, through research on the adversarial sample, the robustness and stability of the deep neural network model are improved, and the safety and reliability of the intelligent driving system are enhanced.
Need to check novelty before this filing date? Find Prior Art

Description

Technical Field

[0001] The present invention belongs to the fields of computer vision, 3D point cloud, and adversarial learning, and particularly relates to a method for generating 3D transferable adversarial samples for intelligent driving. Background Art

[0002] The generation of adversarial samples is an important research direction in the fields of deep learning and artificial intelligence, and it plays an important role in both theoretical research and practical applications. The generation of adversarial samples can help researchers and developers improve the robustness of the model in an adversarial environment, that is, the stability of the model when facing tiny perturbations. In practical applications, that is, under the condition of incomplete information, the generation of 3D point cloud adversarial samples needs to additionally consider its transferability, that is, its attack effect on different classification models. The research on transferability helps to evaluate and understand the vulnerability of deep learning models when facing adversarial attacks, and provides valuable contributions to the security protection in the practical field.

[0003] PF-Attack[1] is a new method for generating adversarial samples, aiming to generate more transferable adversarial samples. PF-Attack consists of a perturbation decomposition module and a point cloud classifier, and the goal is to find perturbations to generate imperceptible adversarial point cloud examples to deceive the classifier. The perturbation decomposition module divides the adversarial perturbation into two sub-perturbations through random perturbation decomposition, and these sub-perturbations may also be adversarial. In this way, PF-Attack can optimize both the perturbation and its sub-perturbations simultaneously, so as to generate adversarial samples that are further away from the decision boundary and improve its transferability.

[0004] GeoA 3 [2] is a geometric perception adversarial attack method proposed by Yuxin Wen et al., aiming to generate adversarial point clouds to attack the deep point set classifier. This method combines the misclassification loss of the target attack with geometric perception regularization to generate imperceptible adversarial point clouds. GeoA3 introduces a new geometric perception target, aiming to maintain the smoothness and fairness of the generated adversarial samples. At the same time, a new misclassification loss of the target attack is adopted, which supports the continuous pursuit of more malicious signals. By optimizing the point cloud coordinates through the iterative method and gradually adjusting the positions of the points, the maximization of the adversarial effect is achieved.

[0005] Adv-PC[3] is a transferable adversarial attack on 3D point clouds proposed by Hamdi A et al. By introducing a point cloud autoencoder to capture the natural distribution of the data, the attack becomes more data-dependent. Combining the network adversarial loss and the data adversarial loss, the perturbation variable is optimized so that it can still deceive the classifier after being reconstructed by the autoencoder, significantly improving the transferability of 3D point cloud adversarial samples.

[0006] MI-FGSM [4] proposes a momentum-based iterative optimization algorithm. By introducing a momentum term during the iteration process, it stabilizes the update direction and escapes from local maxima, thereby generating more transferable adversarial examples. The Momentum Iterative Fast Gradient Sign Method (MI-FGSM) can stabilize the update direction and avoid falling into local maxima by accumulating the velocity vector of the gradient direction in each iteration. At the same time, it combines the network adversarial loss and the data adversarial loss to optimize the generation of adversarial examples.

[0007] The existing technologies have the following defects:

[0008] 1) Existing point cloud perturbation attack methods based on white-box attacks have limited transferability between different network architectures. Most of the point cloud perturbation attack methods based on white-box attacks require all the network model data. Even if all the parameters of a network model are available, it is difficult to transfer the successful perturbation of a single model to different models, which makes it difficult to implement the perturbation attack algorithm in real-world scenarios.

[0009] 2) Although 3D point cloud data has wide applications in fields such as autonomous driving and robotics, most of the existing research on adversarial examples focuses on the theoretical and experimental levels, with less consideration of the adversarial attack and defense mechanisms in actual application scenarios. The available 3D point cloud object recognition datasets lack actual application scenarios, which hinders the use of adversarial example generation technology in real-world fields such as intelligent driving. Summary of the Invention

[0010] The purpose of the present invention is to solve the problem that the imperceptibility and adversarial strength of existing point cloud adversarial attacks cannot achieve a good balance, and to provide a 3D transferable adversarial example generation method for intelligent driving. This method effectively improves the transferability of adversarial perturbation attacks, and through the research on adversarial examples, it is beneficial to improve the robustness and stability of deep neural network models, and enhance the security and reliability of intelligent driving systems.

[0011] To achieve the above purpose, the technical solution of the present invention is: a 3D transferable adversarial example generation method for intelligent driving, which enhances the attack success rate and transferability of adversarial examples by integrating the decomposition perturbation strategy and the least likely class method.

[0012] In an embodiment of the present invention, a real traffic scene object recognition dataset based on the KITTI street view dataset is also constructed to achieve a high success rate of real traffic object target recognition attacks.

[0013] In an embodiment of the present invention, the decomposition perturbation strategy is to randomly decompose the adversarial perturbation of the adversarial example into multiple sub-perturbations.

[0014] In one embodiment of the present invention, the least likely class method improves the attack success rate and transferability of adversarial samples by constraining the directions of multiple sub-perturbations decomposed by the decomposition perturbation strategy.

[0015] In one embodiment of the present invention, by fusing the decomposition perturbation strategy and the least likely class method, that is: through the decomposition perturbation strategy, the adversarial perturbation of the adversarial sample is randomly decomposed into multiple sub-perturbations, the one-hot encoding of the class of the sub-perturbation is output, and the probability predicted by the model is used for iterative optimization. Calculate the Euclidean distance between the sub-perturbation label category and the least likely class of the one-hot encoding, expect the label category of the sub-perturbation to select the least likely class, optimize the distance loss from the least likely class, so that its output deviates from the normal result, thereby generating an adversarial sample that is far from the decision boundary and has better transferability.

[0016] In one embodiment of the present invention, the specific implementation manner of fusing the decomposition perturbation strategy and the least likely class method is as follows:

[0017] Step S1, set a point cloud classifier, generate an adversarial perturbation according to the point cloud data, and use the method of random decomposition to generate multiple sub-perturbations; specifically, assume that P ∈ R N*3 represents a benign three-dimensional point cloud with the true label y, and given a model f θ , there is f θ (P) = y. Assume that Δ is a successful adversarial perturbation of P, that is, f θ (P + Δ) = y' ≠ y. Each perturbation Δ is randomly decomposed into different sub-perturbations as follows:

[0018] Δ = Γ ⊙ Δ l + (1 - Γ) ⊙ Δ r

[0019] where Γ ∈ {0, 1} N*3 is a mask metric, Δ l and Δ r are the left and right perturbations respectively, and ⊙ is the element-wise multiplication;

[0020] Use the random perturbation factor method to attack, that is, given a mask matrix Γ ∈ {0, 1} N*3 , the probability that a certain element value in Γ is 1 is p, and the probability that a certain element value is 0 is 1 - p; the matrix set S composed of all possible Γ is expressed as:

[0021]

[0022] Each time of iterative optimization, randomly draw a mask matrix Γ' from the set S to decompose the perturbation;

[0023] Step S2: Use the least likely class method to constrain the direction of the sub-perturbation; perform iterative optimization using the prediction probabilities generated by the model. Let p(y∣P) denote the likelihood of the point cloud P output by the model with respect to class y, and use y LLC to represent the label of the least likely class, that is, the class that the output model distrusts the most among all possible classes y of the point cloud P; use f θ (P + Δ) to represent the class judgment of the model on the point cloud P after adding the perturbation Δ; use y LLC (P + Δ) to represent the least likely class of the point cloud P after adding the perturbation Δ, and use d(P, Δ) to represent the Euclidean distance between the class of the point cloud after adding the perturbation and its least likely class; the relevant formulas are as follows:

[0024] y LLC = argmin{p(y∣P)}

[0025] d(P, Δ) = (f θ (P + Δ) - y LLC (P + Δ)) 2

[0026] Step S3: Iteratively optimize the main perturbation and the sub-perturbations generated by decomposition to generate more transferable adversarial perturbations; use g(P) y to represent the prediction probability of the deep neural network for the y-th class of the point cloud P, and use v(P, Δ) to calculate the prediction probability g(P + Δ) of the true label class y of the point cloud P after adding the perturbation Δ y and the prediction probability max y′≠y g(P + Δ) y′ between it and the class y' with the highest probability except for the true label class y:

[0027] v(P, Δ) = (max y′≠y g(P + Δ) y′ - g(P + Δ) y ) 2

[0028] Use P' to represent the perturbed point cloud after adding the perturbation Δ to the initial point cloud P, and use the cross-entropy loss function l cls (f θ (P′), y true ) as the benchmark of the final loss function, where y true represents the true class of the point cloud P, and then add a penalty function l LLC (P′, P, Δ); the final loss function to be minimized is as follows:

[0029] l final = -l cls (f θ (P′), y true ) + τ·lLLC (P′, P, Δ)

[0030] s.t. ‖Δ‖ ∞ ≤ ∈

[0031] where τ is the penalty parameter, and ∈ is used to constrain the infinity norm of Δ;

[0032] Finally, a 3D point cloud adversarial sample for intelligent driving target recognition with better transferability is generated.

[0033] In an embodiment of the present invention, the penalty function l LLC (P′, P, Δ) uses the chamfer distance function l CD (P′, P) and the perturbation score function l llc (P, Δ), where β is a hyperparameter used to optimize the perturbation score. The chamfer distance function is used to calculate the difference between two sets of point clouds, and the perturbation score function l llc (P, Δ) consists of the Euclidean distance between the point cloud P and two sub-perturbations generated by decomposing the perturbation and v(P, Δ); the relevant formulas are as follows:

[0034] l LLC (P′, P, Δ) = l CD (P′, P) + β · l llc (P, Δ)

[0035] l llc = d(P, Γ' ⊙ Δ) + d(P, (1 - Γ') ⊙ Δ) + v(P, Δ)

[0036]

[0037] where n represents the number of points in the original point cloud P, n' represents the number of points corresponding to the perturbed point cloud P', and a and b respectively represent the abstract points of the adversarial point cloud and the original point cloud.

[0038] The present invention also provides an electronic device, which includes a processor and a memory. Among them, the memory stores a computer program. When the computer program is executed by the processor, the processor is enabled to execute the method steps as described in any of the above.

[0039] The present invention also provides a 3D transferable adversarial sample generation system for intelligent driving, including a memory, a processor, and computer program instructions stored on the memory and capable of being run by the processor. When the processor runs the computer program instructions, the method steps as described above can be implemented.

[0040] The present invention also provides a computer-readable storage medium, on which computer program instructions capable of being run by a processor are stored. When the processor runs the computer program instructions, the method steps described above can be implemented.

[0041] Compared with the prior art, the present invention has the following beneficial effects: By integrating the decomposition perturbation strategy and the least likely class method, the method of the present invention achieves a high attack success rate under multiple datasets and multiple model experiments, improving the transferability of adversarial samples; The present invention also produces a real-scene traffic object dataset based on the KITTI street scene dataset, and conducts sufficient training and testing on this dataset, achieving a high success rate in the recognition attack of real traffic objects, and achieving a considerable transferable attack on multiple victim models and proxy models. Through the research on adversarial samples, the present invention is conducive to improving the robustness and stability of deep neural network models, and enhancing the security and reliability of intelligent driving systems. BRIEF DESCRIPTION OF THE DRAWINGS

[0042] Figure 1 It is the overall framework of the adversarial sample generation method of the present invention. DETAILED DESCRIPTION OF THE INVENTION

[0043] The technical solution of the present invention will be specifically described below with reference to the drawings.

[0044] The present invention provides a three-dimensional transferable adversarial sample generation method for intelligent driving, which enhances the attack success rate and transferability of adversarial samples by integrating the decomposition perturbation strategy and the least likely class method.

[0045] The following is the specific implementation process of the present invention.

[0046] A three-dimensional transferable adversarial sample generation method for intelligent driving in the present invention enhances the attack success rate and transferability of samples by combining the decomposition perturbation and the least likely class method. The adversarial perturbation of an adversarial sample can be decomposed into two sub-perturbations, which may also be adversarial perturbations. The sub-perturbations are generated by means of random perturbation, the possibility of various categories of the sub-perturbations is output using a class one-hot encoding, the sub-perturbations are constrained using the least likely class method, the Euclidean distance between the sub-perturbation label category and the least likely class of the class one-hot encoding is reduced, it is expected that the label category of the sub-perturbation selects the least likely class, the distance loss from the least likely class is optimized, so that its output deviates from the normal result, and by combining it with the loss of the main perturbation, the adversarial perturbation can be made far from the decision boundary, thereby generating a more effective adversarial perturbation, as Figure 1 shown.

[0047] The specific implementation steps of the method of the present invention are as follows:

[0048] Step 1: We first set up a point cloud classifier, generate adversarial perturbations based on the point cloud data, and generate multiple sub-perturbations using the method of random decomposition. Specifically, assume that P ∈ R N*3 represents a benign 3D point cloud with the true label y. Given a model f θ , assume that Δ is a successful adversarial perturbation of P, that is, f θ (P + Δ) = y' ≠ y. Each perturbation Δ can be randomly decomposed into different sub-perturbations as follows:

[0049] Δ = Γ ⊙ Δ l + (1 - Γ) ⊙ Δ r

[0050] where Γ ∈ {0, 1} N*3 is the mask metric, Δ l and Δ r are the left and right perturbations respectively, and ⊙ is the element-wise multiplication;

[0051] Use the random perturbation factor method to attack, that is, given a mask matrix Γ ∈ {0, 1} N*3 , the probability that an element value in Γ is 1 is p, and the probability that an element value is 0 is 1 - p. The matrix set S composed of all possible Γ can be expressed as:

[0052]

[0053] Randomly draw a mask matrix from the set S to decompose the perturbation during each iteration optimization;

[0054] Step 2: Use the least likely class method to constrain the direction of the sub-perturbation; use the predicted probability generated by the model for iterative optimization. Let p(y|P) represent the likelihood of the point cloud P output by the model with respect to the class y. Use y LLC to represent the label of the least likely class, that is, the class that the output model distrusts the most among all possible classes y of the point cloud P; use f θ (P + Δ) to represent the class judgment of the model on the point cloud P after adding the perturbation Δ; use y LLC (P + Δ) to represent the least likely class of the point cloud P after adding the perturbation Δ, and use d(P, Δ) to represent the Euclidean distance between the class of the point cloud after adding the perturbation and its least likely class; the relevant formulas are as follows:

[0055] y LLC = argmin{p(y|P)}

[0056] d(P, Δ) = (f θ (P + Δ) - y LLC (P + Δ)) 2

[0057] Step 3: Iteratively optimize the main perturbation and the sub-perturbations generated by decomposition to generate more transferable adversarial perturbations. We believe that adversarial perturbations far from the decision boundary will have better transferability in attacking different victim models. We use g(P) y to represent the predicted probability of the y-th class for the point cloud P by the deep neural network, and use v(P,Δ) to calculate the predicted probability g(P + Δ) of the true label class y after adding the perturbation Δ to the point cloud P y and the predicted probability max y′≠y g(P + Δ) y′ between it and the predicted probability of the class y' with the highest probability except for the true label class y:

[0058] v(P,Δ) = (max y′≠y g(P + Δ) y′ - g(P + Δ) y ) 2

[0059] Use P' to represent the point cloud after adding the perturbation to the initial point cloud P, and use the cross-entropy loss function l cls (fθ(P′), y true ) as the benchmark of the final loss function, where y true represents the true class of the point cloud P, and then add a penalty function l LLC (P′, P, Δ). The final loss function we try to optimize is as follows:

[0060] l final = - l cls (f θ (P′), y true ) + τ · l LLC (P′, P, Δ)

[0061] s.t. ‖Δ‖ ∞ ≤ ∈

[0062] where τ is the penalty parameter and ∈ is used to constrain the infinity norm of Δ; the chamfer distance function l LLC (P′, P, Δ) uses the chamfer distance function l CD (P′, P) and the perturbation score function l llc (P, Δ), and β is a hyperparameter used to optimize the perturbation score. The chamfer distance function is used to calculate the difference between two sets of point clouds, and the perturbation score function l llc (P, Δ) consists of the Euclidean distance between the point cloud P and the two sub-perturbations generated by decomposing the perturbation and v(P,Δ); the relevant formulas are as follows:

[0063] l LLC (P′, P, Δ) = l CD (P′, P) + β · lllc (P,Δ)

[0064] l llc = d(P,Γ'⊙Δ)+d(P,(1 - Γ')⊙Δ)+v(P,Δ)

[0065]

[0066] Where n represents the number of points in the original point cloud P, n' represents the number of points corresponding to the perturbed point cloud P', and a and b respectively represent the abstract points of the adversarial point cloud and the original point cloud.

[0067] Finally, a three - dimensional point cloud adversarial sample for intelligent driving target recognition with better transferability is generated.

[0068] Traditional point cloud adversarial attack methods are usually based on white - box attacks, which require a comprehensive understanding of the relevant parameters of the model, making it difficult to apply adversarial samples in actual scenarios.

[0069] In contrast, the present invention first uses a decomposed perturbation strategy, randomly decomposes the perturbation into multiple sub - perturbations, outputs the class one - hot encoding of the sub - perturbations, iteratively optimizes using the probability predicted by the model, calculates the Euclidean distance between the sub - perturbation label category and the least - likely class of the one - hot encoding, expects the sub - perturbation label category to select the least - likely class, so as to deviate from the normal result. Using the least - likely class to constrain the direction of the sub - perturbation during random decomposition further makes the adversarial perturbation far from the decision boundary, improving the transferability of the perturbation attack.

[0070] attack.

[0071] Although the PF - Attack method uses a random decomposition strategy and improves the attack success rate, it does not limit the direction of its decomposition. Due to the randomness of the mask matrix in random decomposition, it may perform poorly when dealing with point clouds with complex spatial relationships.

[0072] The method of the present invention overcomes these limitations in the following aspects:

[0073] 1. Use the least - likely class method to constrain the direction of the decomposed perturbation, making the direction of iterative optimization of the adversarial perturbation further away from the decision boundary and improving the transferability of the perturbation attack.

[0074] 2. Combine the decomposed perturbation strategy and the least - likely class method to further improve its attack success rate.

[0075] 3. Conduct training and testing on the object dataset in the real - world traffic scenario, verify its reliability in the real application scenario, see Table 1 and Table 2. Table 1 shows the comparison between the method of the present invention and other existing algorithms (PF - Attack[1], GeoA 3[2], Adv-PC[3], 3D-Adv[5], KNN[6]) on the ModelNet40 dataset, and Table 2 shows the comparison of the attack success rate between the method of the present invention and PF-Attack[1] on the KITTI-C dataset.

[0076] The KITTI dataset is a multi-modal benchmark dataset containing more than 20,000 detailed annotated dynamic driving scenarios, which is widely used in the fields of autonomous driving and computer vision. We use the 3Dbbox information in the KITTI dataset label file to process its 7,480 street scene point cloud data. First, we select six categories of car, van, truck, pedestrian, bicycle, and tram from the KITTI dataset categories for subsequent operations. Taking the car category as an example, according to the length, width, height, and center information of the 3Dbbox in the label file, with the center of the 3Dbbox as the coordinate origin, we convert the point cloud data from the camera coordinate to the bbox coordinate system, and then according to the length, width, and height information, discard the points that do not belong to the car object to obtain the preliminary car object point cloud. By traversing all the street scene point clouds, we obtain all the data of the car category. Repeating the operation, we obtain the preliminary classification datasets of the six categories. Then, we perform upsampling and downsampling operations on all the point cloud data to ensure that the number of points in all the point cloud data is 1,024, and at the same time, we perform normalization operations on the point cloud. We randomly select 2,000 car point clouds, and 800 for each of the other five categories, a total of 4,000 to form the KITTI-C dataset. This dataset contains 3,200 training samples and 800 test samples. Each time, we randomly select 40 point cloud data from each class, a total of 240, for generating adversarial point clouds.

[0077] Table 1 Attack success rate of the method of the present invention (DPLLC) on the ModelNet40 dataset

[0078]

[0079] Table 2 Attack success rate of the method of the present invention (DPLLC) on the KITTI-C dataset

[0080]

[0081] Generally speaking, by introducing the least likely class method, the method of the present invention is further optimized on the basis of decomposing the perturbation strategy. Compared with the prior art, the present invention provides a more transferable adversarial sample generation method.

[0082] The present invention also provides an electronic device, which includes a processor and a memory. Among them, the memory stores a computer program, and when the computer program is executed by the processor, the processor is made to execute the method steps as described in any one of the above.

[0083] The present invention also provides a three-dimensional transferable adversarial sample generation system for intelligent driving, including a memory, a processor, and computer program instructions stored on the memory and executable by the processor. When the processor runs the computer program instructions, the method steps as described above can be implemented.

[0084] The present invention also provides a computer-readable storage medium, on which computer program instructions executable by a processor are stored. When the processor runs the computer program instructions, the method steps as described in any one of the above can be implemented.

[0085] References:

[0086] [1] He B, Liu J, Li Y, et al. Generating transferable 3d adversarial pointcloud via random perturbation factorization[C] / / Proceedings of the AAAI Conference on Artificial Intelligence. 2023, 37(1): 764-772.

[0087] [2] Wen Y, Lin J, Chen K, et al. Geometry-aware generation of adversarial point clouds[J]. IEEE Transactions on Pattern Analysis and Machine Intelligence, 2020, 44(6): 2984-2999.

[0088] [3] Hamdi A, Rojas S, Thabet A, et al. Advpc: Transferable adversarial perturbations on 3d point clouds[C] / / Computer Vision–ECCV 2020: 16th European Conference, Glasgow, UK, August 23–28, 2020, Proceedings, Part XII 16. Springer International Publishing, 2020: 241-257.

[0089] [4] Dong Y, Liao F, Pang T, et al. Boosting adversarial attacks with momentum[C] / / Proceedings of the IEEE conference on computer vision and pattern recognition. 2018:9185-9193.

[0090] [5] Xiang C, Qi C R, Li B. Generating 3d adversarial point clouds[C] / / Proceedings of the IEEE / CVF conference on computer vision and pattern recognition. 2019:9136-9144.

[0091] [6] Boateng E Y, Otoo J, Abaye D A. Basic tenets of classification algorithms K-nearest-neighbor, support vector machine, random forest and neural network: A review[J]. Journal of Data Analysis and Information Processing, 2020, 8(4):341-357.

[0092] The above are the preferred embodiments of the present invention. All changes made according to the technical solution of the present invention, when the resulting functional effects do not exceed the scope of the technical solution of the present invention, shall fall within the protection scope of the present invention.

Claims

1. A method for generating three-dimensional transferable adversarial samples for intelligent driving, characterized in that: By integrating the decomposition perturbation strategy and the least likely class method, the attack success rate and transferability of adversarial samples are enhanced.

2. The method for generating three-dimensional transferable adversarial samples for intelligent driving according to claim 1, characterized in that: We also build a real-world traffic scene target recognition dataset based on the KITTI street view dataset to achieve a high success rate of real-world traffic object target recognition attack.

3. The method for generating three-dimensional transferable adversarial samples for intelligent driving according to claim 1, characterized in that: The decomposition perturbation strategy is to randomly decompose the adversarial perturbation of the adversarial sample into multiple sub-perturbations.

4. The method for generating three-dimensional transferable adversarial samples for intelligent driving according to claim 3, characterized in that: The least likely class method improves the attack success rate and transferability of adversarial samples by constraining the directions of multiple sub-perturbations decomposed by the decomposition perturbation strategy.

5. The method for generating three-dimensional transferable adversarial samples for intelligent driving according to claim 1 or 4, characterized in that: The method integrates the decomposition perturbation strategy and the least likely class method, that is, through the decomposition perturbation strategy, the adversarial perturbation of the adversarial sample is randomly decomposed into multiple sub-perturbations, the sub-perturbation class one-hot encoding is output, the probability predicted by the model is used for iterative optimization, the Euclidean distance between the sub-perturbation label category and the one-hot encoded least likely class is calculated, the label category of the expected sub-perturbation selects the least likely class, and the distance loss with the least likely class is optimized, so that its output deviates from the normal result, thereby generating an adversarial sample that is far away from the decision boundary and has more transferability.

6. The method for generating three-dimensional transferable adversarial samples for intelligent driving according to claim 5, characterized in that: The specific implementation of the fusion decomposition perturbation strategy and the least likely class method is as follows: Step S1: Set the point cloud classifier, generate adversarial perturbations based on the point cloud data, and use the random decomposition method to generate multiple sub-perturbations; specifically, assume P∈R N*3 Represents a benign 3D point cloud with true label y, given a model f θ , there is f θ (P) = y. Assume that Δ is a successful adversarial perturbation of P, i.e., f θ (P+Δ)=y'≠y, each perturbation Δ is randomly decomposed into different sub-perturbations, as follows: D=C⊙D l +(1-C)⊙D r where Γ∈{0,1} N*3 is the mask metric, Δ l and Δ r are the left and right perturbations respectively, ⊙ is the element-by-element multiplication; Use the random perturbation factor method to attack, that is, given a mask matrix Γ∈{0,1} N*3 , the probability that an element value in Γ is 1 is p, and the probability that an element value is 0 is 1-p; the matrix set S composed of all possible Γ is expressed as: S={Γ it ∣i∈{1,2,...,N},t∈{1,2,3}} In each iterative optimization, a mask matrix Γ' is randomly extracted from the set S to decompose the perturbation; Step S2: Use the least likely class method to constrain the direction of the sub-disturbance; use the predicted probability generated by the model to perform iterative optimization, and use p(y|P) to represent the possibility of the point cloud P output by the model about the category y, and use y LLC To represent the label of the least likely class, that is, the least trusted category of all possible categories y of the output model about the point cloud P; use f θ (P+Δ) represents the model's category judgment of point cloud P after adding perturbation Δ; using y LLC (P+Δ) represents the least likely class of the point cloud P after adding the perturbation Δ, and d(P,Δ) is used to represent the Euclidean distance between the point cloud category after adding the perturbation and its least likely class; the relevant formula is as follows: y LLC =argmin{p(y∣P)} d(P,Δ)=(f θ (P+Δ)-y LLC (P+D)) 2 Step S3, iteratively optimize the main perturbation and the sub-perturbations generated by decomposition to generate more transferable adversarial perturbations; use g(P) y To represent the predicted probability of the yth class of the deep neural network predicting the point cloud P, use v(P,Δ) to calculate the predicted probability g(P+Δ) of the true label class y after adding the perturbation Δ to the point cloud P. y The predicted probability max of the highest probability class y' other than the true label class y y′≠y g(P+Δ) y′ Distance between: v(P,Δ)=(max y′≠y g(P+Δ) y′ -g(P+Δ) y ) 2 Use P' to represent the perturbed point cloud after adding perturbation Δ to the initial point cloud P, and use the cross entropy loss function As the basis of the final loss function, y true Represents the true category of the point cloud P, and then adds a penalty function The final loss function that we try to minimize is as follows: s.t.‖Δ‖ ∞ ≤∈ Where τ is the penalty parameter, ∈ is used to constrain the infinite norm of Δ; Finally, more transferable 3D point cloud adversarial samples for intelligent driving target recognition are generated.

7. The method for generating three-dimensional transferable adversarial samples for intelligent driving according to claim 6, characterized in that: Penalty Function The chamfer distance function is used in and the perturbation score function β is a hyperparameter used to optimize the perturbation score. The perturbation score function It consists of three parts: the Euclidean distance between the point cloud P and the two sub-disturbances generated by the decomposed disturbance and v(P,Δ); the relevant formula is as follows: Where n represents the number of points in the original point cloud P, n' represents the number of points corresponding to the point cloud P' after perturbation, and a and b represent the abstract points of the adversarial point cloud and the original point cloud, respectively.

8. An electronic device comprising a processor and a memory, wherein: The memory stores a computer program, and when the computer program is executed by the processor, the processor executes the method steps according to any one of claims 1 to 7.

9. A three-dimensional transferable adversarial sample generation system for intelligent driving, characterized in that: The method comprises a memory, a processor, and computer program instructions stored in the memory and executable by the processor. When the processor executes the computer program instructions, the method steps as claimed in any one of claims 1 to 7 can be implemented.

10. A computer-readable storage medium storing computer program instructions that can be executed by a processor, wherein when the processor executes the computer program instructions, the method steps according to any one of claims 1 to 7 can be implemented.

Citation Information

Cited By

  • Method for generating imperceptible three-dimensional point cloud confrontation sample

    CN120893479A

  • Method for generating imperceptible three-dimensional point cloud adversarial samples

    CN120893479B