Clean tag backdoor attack method and system for 3D point cloud model

Through gradient alignment technology and decision-making boundary distance strategy optimization triggers and perturbations, the problem of the failure of the existing 3D point cloud model backdoor attack in the de novo training scenario is solved, and a backdoor attack with high success rate and concealment is achieved, which improves the security and robustness of the model.

CN120337235AActive Publication Date: 2025-07-18FUJIAN NORMAL UNIV

Patent Information

Application Number
CN202510836325.1
Authority / Receiving Office
CN · China
Patent Type
Applications(China)
Current Assignee / Owner
Filing Date
2025-06-21
Publication Date
2025-07-18
Estimated Expiration
2045-06-21

AI Technical Summary

Technical Problem

The existing backdoor attack method for 3D point cloud models fails in de novo training scenarios, and traditional backdoor attacks are easily discovered by tag detection and defense mechanisms. Clean tag backdoor attacks are effective in transfer learning scenarios but are not suitable for de novo training.

Method used

Gradient alignment technology and data selection strategy based on decision boundary distance are adopted, and the trigger insertion position and perturbation are optimized to form a poisoned data set, bypassing label detection, and backdoor attacks with high success rate are achieved.

Benefits of technology

Achieving a 98.5% attack success rate in a resumption scenario significantly improves the concealment and practicality of backdoor attacks, can bypass the tag detection defense mechanism, improves the probability of model vulnerabilities being discovered, and enhances the robustness and security of the point cloud model.

✦ Generated by Eureka AI based on patent content.

Smart Images

  • Figure CN120337235A_ABST
    Figure CN120337235A_ABST
Patent Text Reader

Abstract

The invention provides a clean label backdoor attack method and system for a 3D point cloud model. The method comprises the steps that S101, a clean data set is acquired, and model parameters are randomly initialized; s102, randomly selecting a source class data set and a target class data set, and performing optimization; s103, the disturbance is initialized; s104, adding the obtained disturbance # imgabs0 # into a target class data set, and screening the target class data set by using a data selection strategy based on a decision boundary distance to obtain a final poisoning data set; s105, mixing the poisoning data set with the clean data set to form a new data set; according to the technical scheme, the practicability and the concealment of backdoor attacks are remarkably improved, the probability that model vulnerabilities are found is increased, and an important reference is provided for evaluating and improving the robustness and the safety of the point cloud model in a real environment.
Need to check novelty before this filing date? Find Prior Art

Description

Technical Field

[0001] The present invention relates to the technical field of artificial intelligence security, in particular to a clean-label backdoor attack method and system for 3D point cloud models. Background Art

[0002] Point cloud deep learning technology has rapidly become a core manufacturing technology in fields such as advanced autonomous driving, robotics, and medical treatment, and these application scenarios are often closely related to life safety. In recent years, a number of studies have explored the feasibility of backdoor attacks on 3D point cloud models. The backdoor attack assumes that the attacker can manipulate the training data and implant predefined triggers in some samples for tampering. The main purpose of the backdoor attack is that the deep learning model implanted with the backdoor still performs normally on normal samples without triggers during the inference stage, while misclassifying the poisoned samples with triggers. Since point clouds usually undergo random sampling before being input into the model, they usually have data sparsity and irregularity. This creates an opportunity for attackers to inject backdoors. Attackers can utilize these characteristics and subtly change the point cloud data to embed hidden trigger conditions in the model. In addition, 3D point cloud models are usually highly sensitive to local geometric features, which are crucial for identifying the shape and orientation of objects. Attackers can implant backdoor triggers by making subtle modifications to specific local features. By exploiting these security vulnerabilities, backdoor attacks have become a huge threat in the field of 3D deep learning. Although existing backdoor attacks pose a significant threat to 3D point cloud models, there are still the following deficiencies in the research in this area.

[0003] Existing research on backdoor attacks on 3D point cloud models can be roughly divided into two categories: traditional backdoor attacks and clean-label backdoor attacks. In traditional backdoor attacks, poisoned point cloud data samples are usually constructed by inserting additional points with specific physical characteristics as triggers. These triggers are designed by the attacker to establish an association with the target label preset by the attacker.

[0004] However, traditional backdoor attacks usually cannot bypass label detection due to their label flipping steps. To improve the concealment of the attack, clean-label backdoor attacks on point cloud models were proposed in subsequent work. Although existing research has verified the feasibility of clean-label backdoor attacks, their experiments are limited to the transfer learning scenario, where the pre-trained model used by the victim is both fixed and known to the attacker. In the transfer learning scenario, the attacker can obtain an existing, trained model, fine-tune it based on the model parameters, and implant a backdoor for this specific set of parameters to make the backdoor effective for this particular model.

[0005] In contrast, the from-scratch training scenario means that the victim directly starts from randomly initialized model parameters without relying on any external pre-trained weights. In this setting, the attacker neither knows the specific architecture details of the model nor can obtain the initial parameter distribution and training strategy, and different parameter combinations and feature representations may be generated in each training. Research shows that when applying clean-label backdoor attack methods designed only for the transfer learning scenario to the from-scratch training scenario, these backdoors will immediately fail. This is because these attack methods assume that the attacker can design a trigger mechanism based on a known and trained model, while in the from-scratch training scenario, the parameters and learning process of the target model are completely unknown to the attacker, so it is impossible to ensure that the backdoor trigger mechanism matches a specific model. Summary of the Invention

[0006] In view of this, the purpose of the present invention is to provide a clean-label backdoor attack method and system for 3D point cloud models, which significantly improves the practicality and concealment of backdoor attacks, increases the probability of discovering model vulnerabilities, and provides an important reference for evaluating and enhancing the robustness and security of point cloud models in real environments.

[0007] To achieve the above object, the present invention adopts the following technical solutions: A clean-label backdoor attack method for 3D point cloud models, comprising the steps of:

[0008] S101: Obtain a clean data set and randomly initialize model parameters, and perform model deployment and training to obtain a proxy model;

[0009] S102: Randomly select a source class data set and a target class data set, set the shape and size parameters of the trigger, then optimize the insertion position of the trigger to obtain the optimal insertion position, and finally insert the trigger into the source class data set to form a new source class data set;

[0010] S103: Initialize the perturbation, where represents the number of perturbations, add the perturbations to the target class data set to form an initial poisoned data set , and optimize the perturbations using the gradient alignment method, and obtain the final perturbations through multiple rounds of iterative optimization ;

[0011] S104: Add the obtained perturbations to the target class data set, and then use a data selection strategy based on the decision boundary distance to screen the target class data set to obtain the final poisoned data set;

[0012] S105: Mix the poisoned dataset with the clean dataset to form a new dataset, use this new dataset to train the model to obtain a model with a backdoor, and verify its attack effectiveness. If the attack is effective, a vulnerability is discovered.

[0013] In a preferred embodiment, the S101 specifically includes:

[0014] Obtain a clean dataset. The clean dataset selects 3D point cloud datasets, including ModelNet10, ModelNet40, and ShapeNet. The number of categories contained in these three datasets is 10, 40, and 16 respectively. Subsequently, initialize the model locally. The architecture of the model selects four architectures: PointNet, PointNet++, DGCNN, and PointCNN. Then set the number of training rounds of the model to 150 rounds, and the data training batch size to 128. The optimizer of the model selects the Adam algorithm; the learning rate The initial value is 0.01, and it is reduced by 30% after every 30 rounds of training; the loss function of the model selects the cross-entropy loss function Its mathematical expression is: , is a one-hot vector, represents the output of the model; randomly sample 2048 points from each point cloud data to form training data; the mathematical expression of the model training process is:

[0015]

[0016] where is the set of model parameters, means assignment, that is, assign the content calculated by the formula in the second half to the new theta, and the model parameters will be updated and optimized in each round of training; represents the learning rate of perturbation, usually set to 0.01; represents the total number of training samples; represents the gradient of the model parameters; i represents the sample, represents the total number of categories; represents the value of the one-hot encoding of the true label of the th sample at the dimension, represents the probability that the model predicts that the th sample belongs to the

[0017] In a preferred embodiment, the S102 specifically includes:

[0018] Select the source data category and the target data category, and then randomly insert a regular spherical point cloud of 300 points as a trigger into the source data category point cloud data. Subsequently, load the proxy model trained in step S101 locally, and obtain the optimal position to insert the trigger through multiple rounds of iteration using a gradient-based position optimization method; the mathematical expression of this optimization method is:

[0019]

[0020]

[0021] where represents the insertion position obtained by solving through minimization and maximization; after minimizing the trigger insertion into the sample, the distribution distance between the trigger and each point in the original sample is minimized; maximization means that after the trigger is inserted into the sample, the probability value output by the model for this sample should be closest to the value of our attack target to the greatest extent; represents the optional spatial position of the three-dimensional continuous domain; is the Lagrange multiplier used to balance distance minimization and classification probability constraints; represents the total number of source category backdoor training samples for optimization; represents the position to the sample point cloud of the Euclidean distance; represents the logarithm of the probability that the source category data is predicted as the target category by the proxy model after the trigger is inserted at the position ; p(*) represents the probability distribution output by the model, t represents the attacker's attack target category; m(X,c) represents the new sample formed after the trigger is inserted at position c in sample X; the logarithm of the probability that the source category data is predicted as the target category by the proxy model ; represents the proxy model obtained in S101; finally, the optimal solution is obtained after multiple rounds of iterative optimization; represents the sample label; argmin represents the value of the independent variable parameter c corresponding to the minimum value of the function; (*) represents a custom function.

[0022] In a preferred embodiment, the S103 specifically includes:

[0023] Randomly initialize the perturbation , add it to the target dataset to form an initial poisoned dataset, load the proxy model , and calculate the poisoned dataset through the proxy model The difference between the source dataset and its corresponding label one-hot vector with respect to the model parameters derivative, then calculate the mean squared error value between these two derivatives, and finally use the projected gradient descent method to optimize the perturbation so that the poisoned dataset establishes a connection with the source class dataset inserted with the trigger, and the model subsequently learns the information of the trigger on the source class dataset through the poisoned dataset to implant the backdoor; during this optimization process, every 20 times the perturbation is optimized, the surrogate model will be retrained from scratch; finally, after 200 times of update and optimization, the attack success rate reaches the highest value and stabilizes; the mathematical expression for this step is:

[0024]

[0025] where MSE represents and the mean squared error value; represents the gradient with respect to the model parameters; represents the number of model parameters;

[0026]

[0027] where the poisoned dataset the difference between the output of the model and the source class one-hot vector with respect to derivative; is the set of model parameters; represents the surrogate model; represents the poisoned sample; represents the added perturbation; represents the number of poisoned samples;

[0028]

[0029] where the poisoned dataset the difference between the output of the model and the target class one-hot vector with respect to derivative; represents the number of target class samples, represents the inserted trigger.

[0030] In a preferred embodiment, the S104 specifically includes:

[0031] Load the surrogate model and calculate the poisoned dataset through the surrogate model The distance between each sample and the model decision boundary is counted and sorted, and finally the poisoning rate is calculated. Select the top ranked data samples to form the final poisoning data set ; The calculation formula for the distance from the data sample to the model decision boundary is: , used to measure the sample Output to target category one-hot vector in the model distance.

[0032] In a preferred embodiment, the step S105 specifically includes:

[0033] The mixed new dataset is published to an open source platform for download, and then the dataset is used to train and deploy the model. The model architecture parameter settings are all random. After training, a 3D point cloud model with a backdoor is obtained. After the attack, the vulnerability of the 3D point cloud model is discovered.

[0034] The present invention also provides a clean label backdoor attack system for 3D point cloud models, which runs the clean label backdoor attack method for 3D point cloud models; it includes a victim, an attacker and a data set; the attacker first obtains a clean data set, randomly selects a source class data set and a target class data set, and extracts the source class data and the target class data from the data set, then locally calculates the gradient through a proxy model to obtain the gradient of the source class data and the target class data, optimizes the perturbation using a gradient alignment technology, inserts the perturbation into the data set to form a poisoned data set, and then optimizes the poisoned data set using a data selection strategy, then merges the poisoned data set with the clean data set and publishes it on an open source platform for the victim to download and use. After the victim downloads the poisoned data set, the poisoned data set is used for model training, and finally a model with a backdoor is obtained. The attacker triggers the backdoor by inputting data with a pre-set trigger into the model, thereby achieving the purpose of the attack and ultimately detecting the vulnerability of the 3D point cloud model.

[0035] Compared with the prior art, the present invention has the following beneficial effects: Existing backdoor attacks on 3D point cloud models have the following defects. Traditional backdoor attacks are prone to being detected by existing label-based detection defense mechanisms due to their operation of flipping data labels. Although the clean-label backdoor attack solves this defect, in the scenario of training from scratch, existing clean-label backdoor attack methods often fail due to randomly initialized model parameters and can only take effect in the fine-tuning scenario. Based on the gradient alignment technique and the data selection strategy based on the decision boundary distance, the present invention proposes the first clean-label backdoor attack on 3D point cloud models in the scenario of training from scratch. Through the data selection strategy based on the decision boundary, the present invention only needs to poison 1.5% of the total dataset to achieve an attack success rate of 98.5%. Most existing attack methods set the poisoning rate to 5% to 9%, but the highest achievable attack success rate can only reach 90%. And since it is a clean-label attack, it can easily bypass label-based detection defense mechanisms and is the first effective clean-label backdoor attack on 3D point cloud models in the scenario of training from scratch. The present invention proposes a general framework for clean-label backdoor attacks on point cloud deep learning models, gives a formal definition and effectiveness analysis of its attack process, and provides a specific instantiated implementation. Experiments and theoretical analysis show that this method still has a high success rate, strong concealment, label consistency, and cross-model transfer ability under the black-box setting that does not depend on the victim model architecture and parameters. Compared with existing solutions, it significantly improves the practicability and concealment of backdoor attacks, increases the probability of discovering model vulnerabilities, and provides an important reference for evaluating and improving the robustness and security of point cloud models in real environments. BRIEF DESCRIPTION OF THE DRAWINGS

[0036] Figure 1 It is a system model diagram of a preferred embodiment of the present invention;

[0037] Figure 2 It is a flowchart of a preferred embodiment of the present invention;

[0038] Figure 3 It is a schematic diagram of an application scenario of a preferred embodiment of the present invention. DETAILED DESCRIPTION OF THE EMBODIMENTS

[0039] The present invention will be further described below in conjunction with the accompanying drawings and embodiments.

[0040] It should be noted that the following detailed description is illustrative and is intended to provide further explanation of the present application. Unless otherwise specified, all technical and scientific terms used herein have the same meaning as commonly understood by those of ordinary skill in the technical field to which the present application belongs.

[0041] It should be noted that the terms used herein are only for describing specific embodiments and are not intended to limit the exemplary embodiments according to the present application; as used herein, unless the context clearly indicates otherwise, the singular form is also intended to include the plural form. In addition, it should also be understood that when the terms "comprising" and / or "including" are used in this specification, they specify the presence of features, steps, operations, devices, components, and / or combinations thereof.

[0042] A Clean Label Backdoor Attack Method and System for 3D Point Cloud Models, refer to Figures 1-3 , aiming at the defects that most existing backdoor attacks on 3D point cloud models cannot bypass the defense mechanism based on label detection or fail in the scenario of training from scratch, the present invention proposes the first clean label backdoor attack on 3D point cloud models in the scenario of training from scratch based on gradient alignment technology and a data selection strategy based on the distance from the decision boundary. The present invention only needs to poison 1.5% of the total dataset to achieve an attack success rate of 98.5%, while most existing attack methods set the poisoning rate to 5% to 9%, but the highest achievable attack success rate can only reach 90%. And since it is a clean label attack, it can easily perturb the defense mechanism based on label detection. Please refer to Figure 1 , a clean label backdoor attack system for point cloud deep learning models mainly includes three types of entities: attackers, datasets, and victims. The attacker first obtains a clean dataset, randomly selects source classes and target classes, and extracts source class data and target class data from the dataset. Subsequently, after calculating the gradients of the source class data and target class data through a proxy model locally, the attacker optimizes the perturbation using gradient alignment technology, inserts the perturbation into the dataset to form a poisoned dataset, and then optimizes the poisoned dataset using a data selection strategy. Subsequently, the poisoned dataset is fused with the clean dataset and published on an open-source platform for the victim to download and use. After the victim downloads the poisoned dataset and uses it for model training, a backdoored model is finally obtained. The attacker triggers the backdoor by inputting data with a pre-set trigger into the model, thereby achieving the purpose of the attack. In the present invention, it is assumed that the attacker does not master the details of the model parameters, architecture, and training process used by the victim, that is, the proxy model used by the attacker to generate perturbations locally is random; once the victim's model is trained and deployed, the attacker can insert a trigger to selectively activate the backdoor during testing.

[0043] Please refer to Figure 2 , a clean label backdoor attack method for 3D point cloud models, includes the steps of:

[0044] S101. Obtain a clean dataset and randomly initialize model parameters, perform model deployment and training to obtain a proxy model;

[0045] S102. Randomly select the source class and the target class, set parameters such as the shape and size of the trigger, and then optimize the insertion position of the trigger to obtain the optimal insertion position. Finally, insert the trigger into the source class dataset to form a new source class dataset. ;

[0046] S103. Initialize the perturbation , where represents the number of perturbations. Add the perturbations to the target class dataset to form an initial poisoned dataset . Use the gradient alignment technique to optimize the perturbations, and obtain the final perturbations through multiple rounds of iterative optimization ;

[0047] S104. Add the obtained perturbations to the target class dataset, and then use the data selection strategy based on the decision boundary distance to screen this dataset to obtain the final poisoned dataset;

[0048] S105. Mix the poisoned dataset with the clean dataset to form a new dataset, use this dataset to train the model to obtain a model with a backdoor, and verify its attack effectiveness.

[0049] Further, the detailed process of the above steps is as follows:

[0050] The step S101 specifically includes:

[0051] The attacker first obtains the clean dataset. The dataset selects the current most mainstream 3D point cloud datasets, namely ModelNet10, ModelNet40, and ShapeNet. The number of categories contained in these three datasets is 10, 40, and 16 respectively. Subsequently, initialize the model locally. The architecture of the model selects four mainstream architectures: PointNet, PointNet++, DGCNN, and PointCNN. Then set the number of model training rounds to 150, and the data training batch size to 128. The optimizer of the model selects the Adam algorithm. The initial value of the learning rate is 0.01, and it is reduced by 30% after every 30 rounds of training. The loss function of the model selects the cross-entropy loss function, and its mathematical expression is: . Randomly sample 2048 points from each point cloud data to form the training data. The mathematical expression of the model training process is:

[0052]

[0053] where is the parameter set of the model, and these parameters will be updated and optimized in each round of training; Denotes the total number of training samples; Denotes the gradient of the model parameters; Denotes the total number of classes; Denotes the value of the one - hot encoding of the true label of the th sample at the dimension, Denotes the probability that the model predicts the th sample belongs to the

[0054] th class (softmax output); Finally, the attacker obtains the surrogate model after 150 rounds of training.

[0055] In step S102, the attacker first selects the source data class and the target data class, then initializes the trigger, and obtains the trigger position through algorithm optimization, specifically including:

[0056]

[0057]

[0058] Among them Denotes the insertion position obtained by minimizing and maximizing (saddle point) solution; Denotes the optional spatial position of the three - dimensional continuous domain; is the Lagrange multiplier, used to balance distance minimization and classification probability constraints; Denotes the total number of source - class backdoor training samples for optimization; Denotes the position to the sample point cloud of the Euclidean distance; Denotes the logarithm of the probability that the source - class data is predicted as the target class by the surrogate model after the trigger is inserted at position c; Denotes the surrogate model obtained in S101; Finally, the optimal solution of is obtained after multiple rounds of iterative optimization.

[0059] In step S103, the attacker optimizes the perturbation using the gradient alignment technique; specifically, it includes:

[0060] The attacker first randomly initializes the perturbation , adds it to the target class dataset to form an initial poisoned dataset , loads the surrogate model , and through the surrogate model calculates the derivative of the difference between the poisoned dataset and the source dataset and their corresponding label one-hot vectors with respect to the model parameters . Then, it calculates the mean squared error value between these two derivatives. Finally, it uses the projected gradient descent method to optimize the perturbation so that the poisoned dataset and the source class dataset inserted with the trigger are established. Subsequently, the model can learn the information of the trigger on the source class dataset through the poisoned dataset to implant the backdoor. In this optimization process, every 20 times the perturbation is optimized, the surrogate model will be retrained from scratch. The purpose of this step is to prevent the perturbation from overly relying on the learning path and parameters of a certain model during the optimization process, which is one of the keys for the present invention to take effect in the scenario of retraining from scratch. Finally, after 200 times of update and optimization, the attack success rate reaches the highest value and stabilizes. The mathematical expression of this step is:

[0061]

[0062] where MSE represents and 's mean squared error value; represents the number of model parameters.

[0063]

[0064] where the derivative of the difference between the output of the poisoned dataset on the model and the source class one-hot vector with respect to ; represents the number of poisoned samples.

[0065]

[0066] where the derivative of the difference between the output of the poisoned dataset on the model and the target class one-hot vector with respect to ; represents the number of target class samples.

[0067] In step S104, the attacker generates a poisoned dataset through a data selection strategy based on the distance to the decision boundary, which specifically includes:

[0068] The attacker first loads the surrogate model , calculates the distance from each sample in the poisoned dataset to the model decision boundary through the surrogate model, sorts the statistics, and finally selects the data samples with higher rankings according to the poisoning rate to form the final poisoned dataset . The calculation formula for the distance from a data sample to the model decision boundary is: , which is used to measure the sample the distance from the output in the model to the one-hot vector of the target class .

[0069] In step S105, the attacker mixes the poisoned dataset with the original clean dataset to form a new dataset. Subsequently, the victim uses this dataset for model training and deployment. Finally, the attacker conducts an attack effectiveness verification, which specifically includes:

[0070] The attacker publishes the mixed new dataset to an open-source platform for the victim to download. Subsequently, the victim uses this dataset for model training and deployment. The model architecture, parameters, etc. used by the victim are all random. After training, a model with a backdoor is obtained. During the victim's training process, the five most mainstream defense methods against point cloud backdoor attacks are added to detect the backdoor, but the final results show that these methods cannot effectively resist the attack method proposed in the present invention, especially the defense method based on label detection. After the victim publishes the trained model online, the attacker inputs point cloud data with a trigger, such as point cloud data of a pedestrian holding a ball, into the model. After the model recognizes the trigger, the backdoor is activated and misclassified as a car. At the same time, when inputting clean point cloud data without a trigger, the model performs normally, so it will not arouse the victim's alertness, improving the concealment of the attack.

[0071] From the above description, it can be seen that the present invention adopts a gradient alignment technology and a data selection strategy based on the distance to the decision boundary, and proposes the first clean-label backdoor attack scheme for 3D point cloud models in the scenario of training from scratch. The present invention gives a formal definition and effectiveness analysis of its attack process, and provides a specific instantiation implementation. Experiments and theoretical analysis show that this method still has a high success rate, strong concealment, label consistency, and cross-model migration ability under the black-box setting that does not depend on the victim model architecture and parameters. Compared with existing schemes, it significantly improves the practicability and concealment of backdoor attacks, providing an important reference for evaluating and enhancing the robustness and security of point cloud models in real environments.

[0072] This solution aims to systematically reveal the potential vulnerabilities of existing 3D point cloud models, provide a new quantifiable and reproducible testing method for model security assessment, and build a unified attack evaluation framework, providing a testing method for performance comparison and effect verification between different subsequent defense mechanisms. The ultimate goal is to promote the improvement of defense mechanisms by means of the proposed attack methods, accelerate the improvement of 3D point cloud models, and thus build a more robust and trustworthy visual perception system.

[0073] The above are only the embodiments of the present invention, and do not limit the patent scope of the present invention accordingly. All equivalent transformations made by using the content of the specification and drawings of the present invention, or directly or indirectly applied in related technical fields, are equally included in the patent protection scope of the present invention.

Claims

1. A clean-label backdoor attack method for 3D point cloud models, characterized in that Including the steps: S101: Obtain a clean data set and randomly initialize the model parameters, perform model deployment and training to obtain a surrogate model; S102: Randomly select a source class data set and a target class data set, set the shape and size parameters of the trigger, then optimize the insertion position of the trigger to obtain the optimal insertion position, and finally insert the trigger into the source class data set to form a new source class data set; S103: Initialize perturbations, where represents the number of perturbations, and add the perturbations to the target class dataset to form an initial poisoned dataset , use the gradient alignment method to optimize the perturbations, and obtain the final perturbations through multiple rounds of iterative optimization ; S104: Add the obtained perturbation to the target class dataset, and then use the data selection strategy based on the decision boundary distance to screen the target class dataset to obtain the final poisoned dataset; S105: Mix the poisoned data set with the clean data set to form a new data set, use this new data set to train the model to obtain a model with a backdoor, and verify the effectiveness of the attack. If the attack is verified to be effective, a vulnerability is discovered.

2. The clean-label backdoor attack method for 3D point cloud models according to claim 1, wherein The specific content of S101 includes: Obtain a clean dataset. The clean dataset selects 3D point cloud datasets, namely ModelNet10, ModelNet40, and ShapeNet. The number of categories contained in these three datasets is 10, 40, and 16 respectively. Subsequently, initialize the model locally. The architecture of the model selects four architectures: PointNet, PointNet++, DGCNN, and PointCNN. Then set the number of training rounds of the model to 150 rounds, and the data training batch size to 128. The optimizer of the model selects the Adam algorithm; the learning rate The initial value is 0.01, and it is reduced by 30% after every 30 rounds of training; the loss function of the model selects the cross-entropy loss function , and its mathematical expression is: , is a one-hot vector, represents the output of the model; randomly sample 2048 points from each point cloud data to form training data; the mathematical expression of the model training process is: Among them is the parameter set of the model, indicating that the assignment assigns the content obtained by calculating the formula in the second half to the new theta, and the parameters of the model will be updated and optimized in each round of training; represents the learning rate of the perturbation, represents the total number of training samples; represents the gradient of the model parameters; i represents the sample, represents the total number of classes; represents the value of the one-hot encoding of the true label of the th sample at the th dimension, represents the predicted probability that the model assigns the th sample to the th class; Finally, the attacker obtains the proxy model after 150 rounds of training.

3. The clean-label backdoor attack method for 3D point cloud models according to claim 1, characterized in that The specific content of S102 includes: Select the source data class and the target data class, and then randomly insert a regular spherical point cloud with a size of 300 points as a trigger into the source data class point cloud data. Then, locally load the surrogate model trained in step S101, and perform multiple rounds of iteration through a gradient-based position optimization method to obtain the optimal position to insert the trigger; the mathematical expression of this optimization method is: wherein represents the insertion position obtained by minimizing and maximizing; after the minimization trigger is inserted into the sample, the distribution distance between the trigger and each point in the original sample is minimized; maximization means that after the trigger is inserted into the sample, the probability value output by the model for this sample should be closest to the value of our attack target to the greatest extent; represents the optional spatial position of the three-dimensional continuous domain; is the Lagrange multiplier, which is used to balance the distance minimization and the classification probability constraint; represents the total number of source-class backdoor training samples for optimization; represents the position to the sample point cloud of the Euclidean distance; represents the logarithm of the probability that the source-class data is predicted as the target class by the surrogate model after the trigger is inserted at the insertion position ; p(*) represents the probability distribution output by the model, t represents the attacker's attack target class; m(X, c) represents the new sample formed after the trigger is inserted at the c position of the X sample; the logarithm of the probability that the source-class data is predicted as the target class by the surrogate model ; represents the surrogate model obtained in S101; finally, the optimal solution is obtained after multiple rounds of iterative optimization; represents the sample label; argmin represents the value of the independent variable parameter c when the function takes the minimum value; f(*) represents a custom function.

4. The clean-label backdoor attack method for 3D point cloud models according to claim 1, wherein The specific content of S103 includes: Randomly initialize the perturbation , add it to the target class dataset to form the initial poisoned dataset, and load the surrogate model , through the surrogate model calculate the derivative of the difference between the poisoned dataset and the source dataset and its corresponding label one-hot vector with respect to the model parameters , then calculate the mean square error value between these two derivatives, and finally use the projected gradient descent method to optimize the perturbation so that the poisoned dataset and the source class dataset inserted with the trigger are established, and the model subsequently learns the information of the trigger on the source class dataset through the poisoned dataset to implant the backdoor; in this optimization process, the surrogate model will be retrained from scratch every 20 times the perturbation is optimized; finally, after updating and optimizing 200 times, the attack success rate reaches the highest value and tends to be stable; the mathematical expression for this step is: where MSE represents and is the mean squared error value; represents the gradient with respect to the model parameters; represents the number of model parameters; Among them Poisoned dataset The difference between the upper output of the model and the source class one-hot vector with respect to The derivative of; Is the parameter set of the model; Represents the surrogate model; Represents the poisoned sample; Represents the added perturbation; Represents the number of poisoned samples; Among them Poisoned dataset The difference between the upper output of the model and the target class one-hot vector with respect to Derivative; Indicates the number of target class samples, Indicates the inserted trigger.

5. The clean-label backdoor attack method for 3D point cloud models according to claim 1, wherein The specific content of S104 includes: Load the proxy model and calculate the poisoned dataset through the proxy model the distance of each sample to the model decision boundary, sort the statistics, and finally select the data samples with the top rankings according to the poisoning rate to form the final poisoned dataset ; the calculation formula for the distance of the data sample to the model decision boundary is: which is used to measure the sample the distance from the output in the model to the target class one-hot vector ​ 6. The clean-label backdoor attack method for 3D point cloud models according to claim 1, wherein The specific content of S105 includes: Publish the mixed new data set to an open-source platform for downloading. Then, use this data set for model training and deployment. The model architecture parameters are all set randomly. After training, a 3D point cloud model with a backdoor is obtained. After being attacked, the vulnerability of the 3D point cloud model is discovered.

7. A clean-label backdoor attack system for 3D point cloud models, characterized in that, Run the clean-label backdoor attack method for 3D point cloud models described in any one of claims 1-6 above; Including a victim, an attacker, and a data set; the attacker first obtains a clean data set, randomly selects a source class data set and a target class data set, and extracts the source class data and the target class data from the data set. Then, after calculating the gradients of the source class data and the target class data through the surrogate model locally, after optimizing the perturbation using the gradient alignment technique, insert the perturbation into the data set to form a poisoned data set, and then optimize the poisoned data set using the data selection strategy. Subsequently, fuse the poisoned data set with the clean data set and publish it to an open-source platform for the victim to download and use. After the victim downloads the poisoned data set, use this poisoned data set for model training. Finally, a model with a backdoor is obtained. The attacker triggers the backdoor by inputting data with a pre-set trigger into the model, thereby achieving the purpose of the attack, and finally detecting the vulnerability of the 3D point cloud model.

Citation Information

Patent Citations

  • Semantic self-adaptive point cloud backdoor attack method

    CN117272296A

  • Multi-mode invisible backdoor attack method and system based on countermeasure disturbance and medium

    CN118350436A

  • Defense method facing machine learning system poisoning attack

    CN118747825A

  • Clean tag backdoor attack method based on face variable features

    CN119360458A

  • Post-Training Detection and Identification of Human-Imperceptible Backdoor-Poisoning Attacks

    US20200387608A1

Cited By

  • Backdoor attack detection method based on artificial intelligence

    CN121151096A