Confrontation sample generation method for point cloud target detection

By adding perturbations to voxel features and using sparse attack methods to generate an adversarial point cloud, the problem of inability to effectively attack voxel-based point cloud target detectors in the prior art is solved, which improves the attack effect and reduces perturbation redundancy, and enhances robustness.

CN120495619APending Publication Date: 2025-08-15NAT INNOVATION INST OF DEFENSE TECH PLA ACAD OF MILITARY SCI
View PDF 0 Cites 1 Cited by

Patent Information

Application Number
CN202510409156.3
Authority / Receiving Office
CN · China
Patent Type
Applications(China)
Current Assignee / Owner
Filing Date
2025-04-02
Publication Date
2025-08-15

AI Technical Summary

Technical Problem

The existing adversarial attack methods are mainly designed for point-based detection methods, and cannot effectively attack voxel-based point cloud target detectors. The existing methods make indiscriminate modifications on the point cloud, resulting in low perturbation redundancy and hiddenness.

Method used

By adding perturbations to voxel features, calculating gradient information and determining the amount of perturbations, generating an adversarial point cloud, and using sparse attack methods to locate high-attack efficiency areas for perturbation, the adversarial attack based on voxel-based point cloud target detection is realized.

Benefits of technology

Improves the effectiveness of counterattacks, reduces redundant perturbations, and enhances the robustness and security of voxel-based point cloud target detection.

✦ Generated by Eureka AI based on patent content.

Smart Images

  • Figure CN120495619A_ABST
    Figure CN120495619A_ABST
Patent Text Reader

Abstract

The invention discloses an adversarial sample generation method for point cloud target detection. The method comprises the following steps: acquiring a voxel-based point cloud target detector; obtaining a point cloud and a target detection truth value label corresponding to the point cloud; extracting voxel features of the point cloud; taking the voxel features as input of a point cloud target detector to obtain a target detection prediction result output by the point cloud target detector, calculating gradient information of the point cloud target detector about the voxel features according to the target detection prediction result and a target detection truth value label, determining a disturbance quantity according to the gradient information, and adding the disturbance quantity to the voxel features to obtain a target detection result; obtaining the updated voxel features; judging whether a preset condition is met or not, if so, performing the next step, and if not, performing loop iteration on the previous step until the preset condition is met; and reconstructing a point cloud according to geometric features and position features in the updated voxel features, and taking the reconstructed point cloud as a confrontation point cloud. According to the invention, attack countermeasure for point cloud target detection based on voxels can be realized, and the attack effect is improved.
Need to check novelty before this filing date? Find Prior Art

Description

Technical Field

[0001] The present invention relates to the field of computer vision technology, and in particular to a method for generating adversarial samples for point cloud target detection. Background Art

[0002] Artificial intelligence technologies, represented by deep learning, are profoundly changing how we produce and live, and have been successfully applied in fields such as computer vision, natural language processing, and speech recognition. However, researchers have discovered that deep neural networks are vulnerable to attacks, leading to erroneous judgments. This has cast a shadow over the application of deep learning in security-sensitive areas. To develop more robust and reliable deep learning systems, it is necessary to explore the various factors that contribute to deep learning security risks.

[0003] Currently, the primary security risk in deep learning comes from adversarial examples. Adversarial examples are samples that contain specially designed noise added to clean examples. These examples can cause a trained deep neural network to make incorrect inferences, and the human eye is nearly indistinguishable from clean examples. Consequently, the issue of adversarial examples in deep learning has attracted widespread attention.

[0004] In intelligent visual perception systems, 3D radar point cloud detection is crucial for accurately identifying and understanding objects in various fields, including autonomous driving and robotics. However, processing the sparsity and disorder of LiDAR point cloud data poses a challenge. To address this issue, deep learning-based methods have been developed, including point-based methods, voxel-based methods, and projection-based methods. Among them, voxel-based detection methods have been widely studied due to their superior real-time performance and have been applied in industrial-grade systems such as Apollo and Autoware. However, due to the existence of adversarial examples, which can subtly change the input data, resulting in prediction errors and the system's inability to recognize critical objects, understanding the potential vulnerabilities of point cloud detection algorithms to adversarial attacks is crucial to improving the security and robustness of these algorithms.

[0005] In recent years, various adversarial attacks have been proposed for LiDAR-based 3D point cloud detection. These attacks can be divided into two categories: one is point-level attacks, which modify the original input point cloud by designing a customized adversarial loss function, causing the target object to disappear from the object detector or degrade real-time performance. The other is object insertion attacks, which optimize 3D mesh objects and insert them into the point cloud scene through a renderer, causing the target object to disappear from the object detector or generate false targets.

[0006] However, existing adversarial attacks are primarily designed for point-based detection methods and are not applicable to voxel-based detection methods. Existing attacks rely on gradient information, but voxel-based point cloud object detectors disrupt the propagation of gradient information during preprocessing, hindering research on attacks against voxel-based point cloud object detectors. Furthermore, voxel-based point cloud object detectors typically use accelerated implementations such as C++ to convert unstructured point cloud data into structured three-dimensional voxel grids, resulting in a non-differentiable voxelization process. Existing attack methods primarily generate adversarial point clouds based on point-based point cloud object detectors, or attack in a black-box setting, such as directly employing transfer attacks or genetic algorithm attacks. These attacks achieve limited effectiveness due to the inability to effectively obtain gradient information from the network. Furthermore, existing attack methods indiscriminately modify the point cloud across the entire scene, resulting in unnecessary perturbations and low stealth. Summary of the Invention

[0007] In order to solve some or all of the technical problems existing in the above-mentioned prior art, the present invention provides an adversarial sample generation method for point cloud target detection.

[0008] The technical solutions of the present invention are as follows:

[0009] A method for generating adversarial samples for point cloud object detection is provided, the method comprising:

[0010] Step 1: Obtain a voxel-based point cloud object detector;

[0011] Step 2: Obtain the initial point cloud and its corresponding target detection true value label;

[0012] Step 3, extract voxel features of the initial point cloud;

[0013] Step 4: Use the voxel feature as the input of the voxel-based point cloud object detector to obtain the target detection prediction result output by the point cloud object detector. Based on the target detection prediction result and the target detection true value label, calculate the gradient information of the point cloud object detector with respect to the voxel feature, determine the perturbation amount based on the gradient information, add the perturbation amount to the voxel feature, and obtain the updated voxel feature.

[0014] Step 5: Determine whether the preset condition is met. If so, proceed to step 6. If not, iterate step 5 until the preset condition is met.

[0015] Step 6: reconstruct the point cloud based on the geometric features and position features in the currently updated voxel features, and use the reconstructed point cloud as the adversarial point cloud.

[0016] In some optional embodiments, calculating the gradient information of the point cloud object detector about the voxel feature based on the object detection prediction result and the object detection true value label includes:

[0017] Calculate the preset loss function based on the target detection prediction results and the target detection true value label;

[0018] The gradient of the loss function with respect to the position feature in the voxel feature is calculated and used as the gradient information of the point cloud target detector with respect to the voxel feature.

[0019] In some optional embodiments, the gradient information of the point cloud object detector with respect to the voxel feature is expressed as:

[0020]

[0021] Among them, g represents the gradient information of the point cloud target detector about the voxel feature, θ represents the parameter of the point cloud target detector, v represents the position feature in the voxel feature, c represents the color feature in the voxel feature, n represents the geometric feature in the voxel feature, y gt represents the target detection truth label corresponding to the point cloud, L(·) represents the loss function, Perform gradient calculation on the position feature v.

[0022] In some optional implementations, the disturbance amount is determined by the following formula:

[0023]

[0024] Among them, δ represents the disturbance amount and ∈ represents the disturbance coefficient.

[0025] In some optional implementations, adding the perturbation amount to the voxel feature to obtain the updated voxel feature includes:

[0026] Add the perturbation amount to the position feature in the voxel feature to obtain the updated position feature;

[0027] The point cloud is reconstructed according to the geometric features in the voxel features and the updated position features, the voxel features are extracted from the reconstructed point cloud, and the extracted voxel features are used as the updated voxel features.

[0028] In some optional implementations, adding the perturbation amount to the voxel feature to obtain the updated voxel feature includes:

[0029] Add the perturbation amount to the position feature in the voxel feature to obtain the updated position feature;

[0030] The updated position features are used to replace the position features in the voxel features extracted from the initial point cloud, and the replaced voxel features are used as the updated voxel features.

[0031] In some optional implementations, after determining the perturbation amount based on the gradient information, the perturbation amount is adjusted in the following manner, and the adjusted perturbation amount is added to the voxel feature to obtain an updated voxel feature:

[0032] Construct a mask matrix corresponding to the voxelized grid based on the target detection box predicted by the point cloud target detector;

[0033] Evaluate the attack effectiveness of each point based on its gradient in the voxelized grid;

[0034] According to the mask matrix and attack effectiveness, the gradient with the highest attack effectiveness is selected;

[0035] Based on the selected gradient, a sparse mask matrix is constructed;

[0036] Adjust the perturbation amount according to the sparse mask matrix.

[0037] In some optional implementations, the mask matrix is constructed as follows:

[0038]

[0039] in, Represents the mask matrix M corresponding to the voxelized grid B The mask value corresponding to the point with coordinates (x, y, z) in v x,y,z Represents a point with coordinates (x,y,z) in a voxelized grid.

[0040] In some optional implementations, the gradient with the highest attack effectiveness is expressed as:

[0041] G τ =sort(g·M B ,e·M B ,τ);

[0042] The sparse mask matrix is constructed in the following way:

[0043]

[0044] Among them, G τ represents the gradient of the highest attack efficiency selected, sort represents the sorting function, e represents the attack efficiency of the point, g represents the gradient of the point, M B represents the mask matrix, τ represents a hyperparameter, Represents the sparse mask matrix M S The mask value corresponding to the point with coordinates (x, y, z), g x,y,z Represents the gradient of a point with coordinates (x,y,z).

[0045] In some optional implementations, the disturbance amount is adjusted in the following manner:

[0046] δ=δ·M S ;

[0047] Where δ represents the disturbance.

[0048] The main advantages of the technical solution of the present invention are as follows:

[0049] The adversarial sample generation method for point cloud target detection of the present invention generates an adversarial point cloud by adding perturbations to voxel features instead of adding perturbations to the original point cloud, which can make the voxelization process differentiable, realize adversarial attacks on voxel-based point cloud target detection, and improve the effect of the adversarial attack; at the same time, by locating point cloud areas with high attack efficiency and only perturbing the point cloud areas with high attack efficiency, it is possible to reduce redundant disturbances while ensuring the effect of the adversarial attack. BRIEF DESCRIPTION OF THE DRAWINGS

[0050] The drawings described herein are used to provide a further understanding of the embodiments of the present invention and constitute a part of the present invention. The exemplary embodiments of the present invention and their descriptions are used to explain the present invention and do not constitute an improper limitation of the present invention. In the drawings:

[0051] Figure 1 A flowchart of a method for generating adversarial samples for point cloud object detection provided by an embodiment of the present invention;

[0052] Figure 2 Schematic diagram of the principle of the adversarial sample generation method for point cloud target detection provided by an embodiment of the present invention. DETAILED DESCRIPTION

[0053] To make the objectives, technical solutions, and advantages of the present invention more clear, the technical solutions of the present invention will be clearly and completely described below in conjunction with specific embodiments of the present invention and corresponding drawings. Obviously, the described embodiments are only part of the embodiments of the present invention, not all of the embodiments. Based on the embodiments of the present invention, all other embodiments obtained by ordinary technicians in this field without making creative efforts are within the scope of protection of the present invention.

[0054] The technical solutions provided by the embodiments of the present invention are described in detail below with reference to the accompanying drawings.

[0055] refer to Figure 1-2 , an embodiment of the present invention provides a method for generating adversarial samples for point cloud target detection, the method comprising the following steps:

[0056] Step 1: Obtain a voxel-based point cloud object detector;

[0057] In the embodiment of the present invention, since the method is used for a voxel-based point cloud target detector, a voxel-based point cloud target detector is pre-selected from the currently available voxel-based point cloud target detectors.

[0058] Step 2: Obtain the initial point cloud and its corresponding target detection true value label;

[0059] In an embodiment of the present invention, an initial point cloud is obtained according to actual needs, and a target detection true value label corresponding to the initial point cloud is obtained. The initial point cloud is a clean sample used to generate an adversarial sample.

[0060] In an embodiment of the present invention, the object detection ground truth labels corresponding to the initial point cloud can be obtained through manual annotation, semi-automatic annotation, or automatic annotation. If the obtained initial point cloud already has a corresponding object detection ground truth label, the object detection ground truth label is directly used.

[0061] Step 3, extract voxel features of the initial point cloud;

[0062] In an embodiment of the present invention, the voxel features of the point cloud include position features, color features and geometric features, and the voxel features are specifically expressed as: [v, c, n]; where v represents the position feature, c represents the color feature, and n represents the geometric feature.

[0063] Furthermore, in an embodiment of the present invention, the position feature includes the coordinates of the points within the voxel, the color feature includes the average color of the points within the voxel, and the geometric feature includes the average normal direction of the points within the voxel.

[0064] In the embodiment of the present invention, the voxel features of the point cloud are extracted using an existing conventional feature extraction method, which will not be described in detail here.

[0065] Step 4: Use the voxel feature as the input of the voxel-based point cloud object detector to obtain the target detection prediction result output by the point cloud object detector. Based on the target detection prediction result and the target detection true value label, calculate the gradient information of the point cloud object detector with respect to the voxel feature, determine the perturbation amount based on the gradient information, add the perturbation amount to the voxel feature, and obtain the updated voxel feature.

[0066] In an embodiment of the present invention, the voxel features of the point cloud are input into a voxel-based point cloud object detector to obtain an object detection prediction result output by the voxel-based point cloud object detector.

[0067] Furthermore, in an embodiment of the present invention, the gradient information of the point cloud object detector about the voxel feature is calculated based on the object detection prediction result and the object detection true value label, including the following steps:

[0068] Step 401: Calculate a preset loss function based on the target detection prediction result and the target detection true value label;

[0069] In an embodiment of the present invention, the loss function is specifically set according to actual needs, and a conventional loss function can be selected, such as the original loss function used for the target detection network, or a customized loss function, such as the IOU adversarial loss function.

[0070] In step 402 , the gradient of the loss function with respect to the position feature in the voxel feature is calculated, and the gradient is used as the gradient information of the point cloud object detector with respect to the voxel feature.

[0071] In an embodiment of the present invention, based on the above settings, the gradient information of the point cloud object detector regarding the voxel feature can be expressed as:

[0072]

[0073] Among them, g represents the gradient information of the point cloud target detector about the voxel feature, θ represents the parameter of the point cloud target detector, v represents the position feature in the voxel feature, c represents the color feature in the voxel feature, n represents the geometric feature in the voxel feature, y gt represents the target detection truth label corresponding to the point cloud, L(·) represents the loss function, Perform gradient calculation on the position feature v.

[0074] Furthermore, in an optional implementation of the embodiment of the present invention, the disturbance amount is determined by the following formula:

[0075]

[0076] Among them, δ represents the disturbance amount, ∈ represents the disturbance coefficient, and the disturbance coefficient is used to control the intensity of the disturbance. The disturbance coefficient is a small positive number, and the specific value is set according to actual needs.

[0077] Furthermore, in an embodiment of the present invention, a heavy voxelization method or a lightweight method is adopted to add the perturbation amount to the voxel feature to obtain an updated voxel feature.

[0078] In an embodiment of the present invention, when a revoxelization method is used, a perturbation amount is added to a voxel feature to obtain an updated voxel feature, including the following steps:

[0079] Step 411, adding the perturbation amount to the position feature in the voxel feature to obtain an updated position feature;

[0080] Step 412 : reconstructing a point cloud based on the geometric features in the voxel features and the updated position features, extracting the voxel features from the reconstructed point cloud, and using the extracted voxel features as updated voxel features.

[0081] In the embodiment of the present invention, voxel features include position features, color features, and geometric features.

[0082] In the embodiment of the present invention, the point cloud is reconstructed according to the voxel features using an existing conventional reconstruction method, which will not be described in detail here.

[0083] In an embodiment of the present invention, when a lightweight approach is adopted, the perturbation amount is added to the voxel feature to obtain the updated voxel feature, including the following steps:

[0084] Step 421, adding the perturbation amount to the position feature in the voxel feature to obtain an updated position feature;

[0085] In step 422 , the updated position feature is used to replace the position feature in the voxel feature extracted from the initial point cloud, and the replaced voxel feature is used as the updated voxel feature.

[0086] In an embodiment of the present invention, by adding perturbations to voxel features instead of adding perturbations to the original point cloud, the voxelization process can be made differentiable, thereby realizing adversarial attacks on voxel-based point cloud target detection and improving the effectiveness of adversarial attacks.

[0087] Step 5: Determine whether the preset condition is met. If so, proceed to step 6. If not, iterate step 5 until the preset condition is met.

[0088] In the embodiment of the present invention, when the preset conditions are met, the next step, i.e., step 6, is performed. If the preset conditions are not met, the process returns to step 5 for a loop iteration to iteratively update the voxel features. In each loop iteration of step 5, the voxel features obtained from the previous update are used as input to the voxel-based point cloud object detector.

[0089] In the embodiment of the present invention, the preset condition is specifically set according to actual needs. For example, the preset condition is set to the number of loop iterations reaching a set number of iterations.

[0090] Step 6: reconstruct the point cloud based on the geometric features and position features in the currently updated voxel features, and use the reconstructed point cloud as the adversarial point cloud.

[0091] In the embodiment of the present invention, the point cloud is reconstructed according to the voxel features using an existing conventional reconstruction method, which will not be described in detail here.

[0092] Refer to Table 1, which shows the pseudo code of the adversarial sample generation method based on the re-voxelization method provided by an embodiment of the present invention.

[0093] Table 1 Adversarial sample generation method based on revoxelization

[0094]

[0095] Refer to Table 2, which provides pseudo code for the lightweight adversarial sample generation method provided by an embodiment of the present invention.

[0096] Table 2. Adversarial sample generation methods based on lightweight methods

[0097]

[0098] In Table 1-2 above, [v0, c0, n0] represents the voxel features of the initial point cloud, v0 represents the position features in the voxel features of the initial point cloud, c0 represents the color features in the voxel features of the initial point cloud, n0 represents the geometric features in the voxel features of the initial point cloud, h(·) represents the conversion function from point cloud to voxel features, g i represents the gradient information obtained in the i-th iteration, v i represents the position feature obtained in the i-th iteration, c i represents the color feature obtained in the i-th iteration, n i represents the geometric features obtained in the i-th iteration, δ i represents the perturbation amount at the i+1th iteration, L(·) represents the loss function, Represents the position feature v i Perform gradient solution, h ′ (·) represents the conversion function from voxel features to point cloud.

[0099] The adversarial sample generation method for point cloud target detection provided by an embodiment of the present invention generates an adversarial point cloud by adding perturbations to voxel features instead of adding perturbations to the original point cloud. This can make the voxelization process differentiable, realize adversarial attacks on voxel-based point cloud target detection, and improve the effectiveness of adversarial attacks.

[0100] Furthermore, considering that global perturbations applied to all points may produce redundant perturbations with smaller attack effects, in an embodiment of the present invention, an attention-based sparse attack method is introduced to locate point cloud areas with high attack efficiency. By only perturbing point cloud areas with high attack efficiency, it is possible to reduce redundant perturbations while ensuring the anti-attack effect.

[0101] In an embodiment of the present invention, the amount of disturbance added to the voxel feature is adjusted to locate the point cloud area with high attack efficiency, and the point cloud area with high attack efficiency is disturbed.

[0102] Furthermore, in an embodiment of the present invention, after determining the perturbation amount according to the gradient information, the perturbation amount is adjusted in the following manner, and the adjusted perturbation amount is added to the voxel feature to obtain an updated voxel feature:

[0103] Step 431 , constructing a mask matrix corresponding to the voxelized grid according to the object detection box predicted by the point cloud object detector;

[0104] In an embodiment of the present invention, for each point in the voxelized grid composed of the acquired voxel features, it is checked whether it is located in any target detection frame. If the point is located in at least one target detection frame, the corresponding position in the mask matrix is assigned a value of 1. If the point is not in any target detection frame, the corresponding position in the mask matrix is assigned a value of 0, thereby constructing a mask matrix corresponding to the voxelized grid.

[0105] Specifically, the mask matrix corresponding to the constructed voxelized grid is expressed as:

[0106]

[0107] in, Represents the mask matrix M corresponding to the voxelized grid B The mask value corresponding to the point with coordinates (x, y, z) in v x,y,z Represents a point with coordinates (x,y,z) in a voxelized grid.

[0108] Step 432 , evaluating the attack effectiveness of each point based on the gradient of each point in the voxelized grid;

[0109] In the embodiment of the present invention, the attack effectiveness of a calculation point is evaluated based on the gradient of the point. The attack effectiveness is specifically expressed as:

[0110]

[0111] Among them, e represents the attack effectiveness, g x 、g y and g z Represents the gradient g of the point x,y,z The gradient components along the x-axis, y-axis, and z-axis, and |·| represents the L1 norm.

[0112] Step 433: Select the gradient with the highest attack effectiveness according to the mask matrix and the attack effectiveness;

[0113] In this embodiment of the present invention, the gradient with the highest attack effectiveness is selected in the following manner:

[0114] Determine the points within the target detection box and their corresponding gradients;

[0115] Each determined point is sorted according to the attack efficiency of the point, and the gradients corresponding to the set number of points in the front order are selected as the gradients with the highest attack efficiency.

[0116] In the embodiment of the present invention, the gradient with the highest attack effectiveness is selected as follows:

[0117] G τ =sort(g·M B ,e·M B ,τ);

[0118] Among them, G τ represents the gradient of the highest attack efficiency selected, sort represents the sorting function, e represents the attack efficiency of the point, g represents the gradient of the point, M B Represents the mask matrix, τ represents a hyperparameter, and the hyperparameter is pre-set to control the number of selected gradients.

[0119] In the above formula, by applying g·M B and e.M. B , which ensures that only points within the target detection box are considered when selecting the gradient.

[0120] Step 434, constructing a sparse mask matrix based on the selected gradient;

[0121] In an embodiment of the present invention, the constructed sparse mask matrix is expressed as:

[0122]

[0123] in, Represents the sparse mask matrix M S The mask value corresponding to the point with coordinates (x, y, z), g x,y,z Represents the gradient of a point with coordinates (x,y,z).

[0124] In an embodiment of the present invention, for each point in the voxelized grid composed of the acquired voxel features, if the point is located in the target detection frame and the gradient of the point is within the selected gradient range, the corresponding position in the sparse mask matrix is assigned a value of 1; otherwise, the corresponding position in the sparse mask matrix is assigned a value of 0, thereby obtaining a sparse mask matrix.

[0125] Step 435: Adjust the disturbance amount according to the sparse mask matrix.

[0126] In the embodiment of the present invention, the disturbance amount is adjusted using the following formula:

[0127] δ=δ·M S ;

[0128] Among them, δ represents the disturbance amount, M S Represents a sparse mask matrix.

[0129] In an embodiment of the present invention, after determining the disturbance amount based on the gradient information, the disturbance amount is adjusted using the above-mentioned method, and the adjusted disturbance amount is added to the voxel feature. This makes it possible to accurately locate the point cloud area with high attack efficiency, and only disturb the point cloud area with high attack efficiency. This can ensure the anti-attack effect while reducing redundant disturbances.

[0130] It should be noted that, in this document, relational terms such as "first" and "second" are used only to distinguish one entity or operation from another entity or operation, and do not necessarily require or imply any actual relationship or order between these entities or operations. Moreover, the terms "include", "comprise" or any other variations thereof are intended to cover non-exclusive inclusion, so that a process, method, article or device that includes a series of elements includes not only those elements, but also other elements not explicitly listed, or also includes elements inherent to such process, method, article or device. In addition, "front", "back", "left", "right", "upper" and "lower" in this document are all referenced to the placement states shown in the accompanying drawings.

[0131] Finally, it should be noted that the above embodiments are only used to illustrate the technical solutions of the present invention, rather than to limit it. Although the present invention has been described in detail with reference to the aforementioned embodiments, those skilled in the art should understand that they can still modify the technical solutions described in the aforementioned embodiments, or make equivalent replacements for some of the technical features therein. However, these modifications or replacements do not deviate the essence of the corresponding technical solutions from the spirit and scope of the technical solutions of the various embodiments of the present invention.

Claims

1. A method for generating adversarial samples for point cloud object detection, characterized in that: The method comprises: Step 1: Obtain a voxel-based point cloud object detector; Step 2: Obtain the initial point cloud and its corresponding target detection true value label; Step 3, extract voxel features of the initial point cloud; Step 4: Use the voxel feature as the input of the voxel-based point cloud object detector to obtain the target detection prediction result output by the point cloud object detector. Based on the target detection prediction result and the target detection true value label, calculate the gradient information of the point cloud object detector with respect to the voxel feature, determine the perturbation amount based on the gradient information, add the perturbation amount to the voxel feature, and obtain the updated voxel feature. Step 5: Determine whether the preset condition is met. If so, proceed to step 6. If not, iterate step 5 until the preset condition is met. Step 6: reconstruct the point cloud based on the geometric features and position features in the currently updated voxel features, and use the reconstructed point cloud as the adversarial point cloud.

2. The adversarial sample generation method for point cloud target detection according to claim 1, characterized in that: Based on the target detection prediction results and the target detection true value labels, the gradient information of the point cloud target detector about the voxel features is calculated, including: Calculate the preset loss function based on the target detection prediction results and the target detection true value label; The gradient of the loss function with respect to the position feature in the voxel feature is calculated and used as the gradient information of the point cloud target detector with respect to the voxel feature.

3. The adversarial sample generation method for point cloud target detection according to claim 2, characterized in that: The gradient information of the point cloud target detector about the voxel feature is expressed as: Among them, g represents the gradient information of the point cloud target detector about the voxel feature, θ represents the parameter of the point cloud target detector, v represents the position feature in the voxel feature, c represents the color feature in the voxel feature, n represents the geometric feature in the voxel feature, y gt represents the target detection truth label corresponding to the point cloud, L(·) represents the loss function, Perform gradient calculation on the position feature v.

4. The adversarial sample generation method for point cloud target detection according to claim 3, characterized in that: The disturbance amount is determined by the following formula: Among them, δ represents the disturbance amount and ∈ represents the disturbance coefficient.

5. The adversarial sample generation method for point cloud target detection according to claim 1, characterized in that: The perturbation amount is added to the voxel feature to obtain the updated voxel feature, including: Add the perturbation amount to the position feature in the voxel feature to obtain the updated position feature; The point cloud is reconstructed according to the geometric features in the voxel features and the updated position features, the voxel features are extracted from the reconstructed point cloud, and the extracted voxel features are used as the updated voxel features.

6. The adversarial sample generation method for point cloud target detection according to claim 1, characterized in that: The perturbation amount is added to the voxel feature to obtain the updated voxel feature, including: Add the perturbation amount to the position feature in the voxel feature to obtain the updated position feature; The updated position features are used to replace the position features in the voxel features extracted from the initial point cloud, and the replaced voxel features are used as the updated voxel features.

7. The adversarial sample generation method for point cloud object detection according to any one of claims 1 to 6, characterized in that: After determining the perturbation amount based on the gradient information, the perturbation amount is adjusted using the following method, and the adjusted perturbation amount is added to the voxel feature to obtain the updated voxel feature: Construct a mask matrix corresponding to the voxelized grid based on the target detection box predicted by the point cloud target detector; Evaluate the attack effectiveness of each point based on its gradient in the voxelized grid; According to the mask matrix and attack effectiveness, the gradient with the highest attack effectiveness is selected; Based on the selected gradient, a sparse mask matrix is constructed; Adjust the perturbation amount according to the sparse mask matrix.

8. The adversarial sample generation method for point cloud target detection according to claim 7, characterized in that: The mask matrix is constructed in the following way: in, Represents the mask matrix M corresponding to the voxelized grid B The mask value corresponding to the point with coordinates (x, y, z) in v x,y,z Represents a point with coordinates (x,y,z) in a voxelized grid.

9. The adversarial sample generation method for point cloud target detection according to claim 8, characterized in that: The gradient with the highest attack effectiveness is expressed as: G τ =sort(g·M B ,e·M B ,t); The sparse mask matrix is constructed in the following way: Among them, G τ represents the gradient of the highest attack efficiency selected, sort represents the sorting function, e represents the attack efficiency of the point, g represents the gradient of the point, M B represents the mask matrix, τ represents a hyperparameter, Represents the sparse mask matrix m S The mask value corresponding to the point with coordinates (x, y, z), g x,y,z Represents the gradient of a point with coordinates (x,y,z).

10. The adversarial sample generation method for point cloud target detection according to claim 9, characterized in that: The disturbance amount is adjusted in the following ways: δ=δ·M S ; Where δ represents the disturbance.

Citation Information

Cited By

  • A Method and Apparatus for Generating 3D Point Cloud Adversarial Examples Based on Dynamic Proxy Gradients

    CN122368685A