Point cloud confrontation attack method and system based on sparse disturbance

By setting spatial logic blocks and optimizing perturbation points within the oriented bounding box of the point cloud, the problems of perturbation sparsity and insufficient transferability in point cloud classifier attacks are solved, sparsely perturbed point cloud attacks are realized, and the attack success rate and imperceptibility are improved.

CN120655976APending Publication Date: 2025-09-16UNIV OF SCI & TECH OF CHINA
View PDF 1 Cites 0 Cited by

Patent Information

Application Number
CN202510751309.2
Authority / Receiving Office
CN · China
Patent Type
Applications(China)
Current Assignee / Owner
Filing Date
2025-06-06
Publication Date
2025-09-16

AI Technical Summary

Technical Problem

Existing point cloud classifier attack methods have difficulty achieving sparsity of perturbations, resulting in point cloud distortion and poor attack effects, and insufficient transferability between different point cloud classifiers.

Method used

By selecting certain points of the original point cloud within the oriented bounding box of the point cloud and applying an offset, setting a rectangular spatial logic block to slide within the oriented bounding box, adjusting the offset, the length and width of the spatial logic block, and the sliding step, and using the loss function to optimize the perturbation points to ensure perturbation sparsity and structural sparsity, a sparse perturbation point cloud is generated.

Benefits of technology

The perturbation sparsity is achieved, point cloud distortion is limited, the stealth of the attack is improved, the transferability between different point cloud classifiers is improved, and the perturbation budget is reduced.

✦ Generated by Eureka AI based on patent content.

Smart Images

  • Figure CN120655976A_ABST
    Figure CN120655976A_ABST
Patent Text Reader

Abstract

The invention discloses a point cloud attack resisting method and system based on sparse perturbation, and the method comprises the steps: taking a directional bounding box of an original point cloud as an effective attack space, selecting some points in the original point cloud in the directional bounding box of the original point cloud, applying offset to form disturbance points, setting a rectangular spatial logic block, and carrying out the spatial logic block; sliding in the directional bounding box, adjusting the offset, the length and width of the spatial logic block and the sliding step length, calculating a loss function value, stopping adjustment until the loss function value is minimum, taking the obtained disturbance point as an optimized disturbance point, and applying the optimized disturbance point to the original point cloud of the point cloud classifier; the method has the advantages that the sparsity of disturbance is realized, the distortion of the point cloud is limited, and non-inductive attack is realized.
Need to check novelty before this filing date? Find Prior Art

Description

Technical Field

[0001] The present invention relates to the field of counterattacks, and in particular to a point cloud counterattack method and system based on sparse perturbation. Background Art

[0002] In recent years, deep learning algorithms have made remarkable and rapid progress in solving a wide range of tasks involving complex raw data. For example, they have demonstrated outstanding performance in speech recognition, object detection, and image segmentation. However, neural networks have been shown to be vulnerable to adversarial attacks. Even slight changes in the input data can lead to significant deviations in the output, despite these minor changes being barely perceptible to human perception. Research on the vulnerability of neural networks began with the study of two-dimensional RGB images. The concept of adversarial examples was first proposed, and it was pointed out that the vulnerability of deep models to adversarial examples primarily stems from the presence of internal linear components.

[0003] At present, the mainstream attack method for point cloud classifiers is based on the transformation of two-dimensional images. However, these methods do not perform well in terms of sensitive indicators such as perturbation budget and time consumption. A point cloud attack algorithm called 3D-Adv was first proposed. For example, the Chinese patent publication number CN114973235A discloses an adversarial point cloud generation method based on adding perturbations in the geometric feature field, which adopts a 3D point cloud adversarial attack method. The point cloud is attacked by generating adversarial points or adversarial point perturbations. This perturbation is usually visually imperceptible, but it is enough to cause the deep learning model to make incorrect predictions, thereby effectively attacking the deep learning model. In fact, the earliest 3D-Adv work used adversarial point cloud samples to attack the target model (ie, the victim model), with a success rate of nearly 99% at the time. Subsequently, a data-driven adversarial point cloud sample generation method called AdvPC was proposed, and the transferability of adversarial point cloud samples was studied for the first time.

[0004] Given the irregular shape and varying cardinality of point clouds, it is challenging to effectively limit the perturbation space while ensuring the effectiveness of the attack. p Norms cannot be simply applied to 3D point clouds, and the smoothness of adversarial examples for point clouds is more difficult to guarantee than for 2D images. When attacking keypoints using previous methods, perturbations tend to cluster locally, making it difficult to achieve perturbation sparsity. Furthermore, enhancing transferability between different point cloud classifiers while maintaining a low perturbation budget remains an open problem. Summary of the Invention

[0005] The technical problem to be solved by the present invention is how to achieve the sparsity of disturbance when attacking a point cloud classifier, so as to limit the distortion of the point cloud and realize a senseless attack.

[0006] The present invention solves the above technical problems through the following technical means: a point cloud counterattack method based on sparse perturbation, comprising: regarding the directional bounding box of the original point cloud as a valid attack space, selecting some points in the original point cloud within the directional bounding box of the original point cloud and applying an offset to form a disturbance point, setting a rectangular spatial logic block, making it slide within the directional bounding box, adjusting the offset, the length and width of the spatial logic block, and the sliding step, calculating the loss function value, and stopping the adjustment until the loss function value is minimized. The obtained disturbance point is the optimized disturbance point, and the optimized disturbance point is applied to the original point cloud of the point cloud classifier.

[0007] Beneficial effect: The present invention selects some points in the original point cloud within the directional bounding box of the original point cloud and applies an offset to form disturbance points, sets a rectangular spatial logic block, makes it slide within the directional bounding box, adjusts the offset, the length and width of the spatial logic block, and the sliding step, so that fewer disturbance points are added and the disturbance is avoided from being concentrated in the local space, thereby achieving the sparsity of the disturbance, and optimizing the disturbance points using the loss function, which ensures the disturbance effect while limiting the distortion of the point cloud through structural sparsity, thereby achieving a senseless attack.

[0008] Furthermore, the spatial logical block has a length and width of l, a height of C, and a step size of S. By adjusting the step size S and the size of the spatial logical block l, different spatial sparse grouping schemes can be achieved. The spatial logical block structure ensures a certain degree of sparsity in the perturbation without affecting the overall structure of the point cloud. This approach can improve the stealth of the attack while preventing unnecessary perturbations from affecting the visualization and geometric structure of the point cloud.

[0009] Furthermore, the loss function includes structural sparsity Φ(δ), and the calculation process of structural sparsity Φ(δ) is:

[0010] The spatial logic block decomposes the adversarial point set into a set of groups where a∈[A],b∈[B],e∈[E], and The adversarial point set refers to the set of all perturbation points, [] represents the integer symbol, H represents the length of the oriented bounding box of the original point cloud, W represents the width of the oriented bounding box of the original point cloud, and P represents the height of the oriented bounding box of the original point cloud. In this way, the oriented bounding box of the original point cloud is divided into A coordinates in the length direction with l as the basic unit, B coordinates in the width direction with l as the basic unit, and E coordinates in the height direction with C as the basic unit according to the size of the spatial logical block, so that the specific spatial logical block position can be located according to a, b, and e; the structural sparsity is expressed by the formula:

[0011]

[0012] in, Indicates that the index Υ a,b,eThe set of adversarial points for positioning, ||·||2 represents the L2 norm, Υ a,b,e Represents the index of the spatial logical block with group numbers a, b, and e.

[0013] Furthermore, the loss function also includes target loss Target loss is the output of the attacked model when the adversarial point cloud sample X′ is input Take the logarithm multiplied by the target label as an addend, take the logarithm of the difference between 1 and v(X′), and then multiply it by the difference between 1 and the target label as another addend. After adding the two addends, take the inverse.

[0014] Furthermore, the loss function also includes logical structure loss Logical structure loss The calculation process is: the adversarial point concentration X i The disturbance displacement corresponding to the point is used as a subtrahend and is compared with X i The perturbation displacement of the eight nearest original points is taken as the minuend, and the square of the L2 norm is taken after subtracting the two, and the perturbation displacement of the eight nearest original points is traversed. i The perturbation displacements of the eight nearest original points are summed up, and then all points in the adversarial point set are traversed to perform the above calculations and sum to obtain the logical structure loss. To minimize spatial logical distortion in the point cloud after the attack, a logical structure loss was designed. This loss encourages adjacent points to have similar perturbations. If the perturbation of a point is too large while that of its neighbors is smaller, the loss increases. If the logical structure of the perturbation is not controlled, the attack may cause unreasonable distortion in the point cloud. For example, some points may move significantly while their neighbors barely move, resulting in an unnatural point cloud shape that is easily detected. By constraining the logical structure loss, the offset trends of adjacent points are kept consistent, ensuring that the point cloud after the attack still conforms to the topology of the original object.

[0015] Furthermore, the loss function also includes a combined loss, which is the target loss and logical structure loss Weighted addition.

[0016] Furthermore, the loss function is a weighted addition of the combination loss and the structural sparsity.

[0017] The present invention also provides a point cloud anti-attack system based on sparse perturbation, comprising:

[0018] Initialization module, used to regard the oriented bounding box of the original point cloud as a valid attack space and set the rectangular spatial logic block;

[0019] The perturbation adding module is used to select some points in the original point cloud within the oriented bounding box of the original point cloud and apply offsets to form perturbation points, so that the spatial logic block slides within the oriented bounding box;

[0020] The perturbation optimization module is used to adjust the offset, the length and width of the spatial logic block, and the sliding step size, and calculate the loss function value until the loss function value is minimized. The adjustment is stopped and the obtained perturbation point is the optimized perturbation point. The optimized perturbation point is applied to the original point cloud of the point cloud classifier.

[0021] Furthermore, the length and width of the spatial logic block are l, the height is C, and the step length is S.

[0022] Furthermore, the loss function includes structural sparsity Φ(δ), and the calculation process of structural sparsity Φ(δ) is:

[0023] The spatial logic block decomposes the adversarial point set into a set of groups where a∈[A],b∈[B],e∈[E], and The adversarial point set refers to the set of all perturbation points, [] represents the integer symbol, H represents the length of the oriented bounding box of the original point cloud, W represents the width of the oriented bounding box of the original point cloud, and P represents the height of the oriented bounding box of the original point cloud. In this way, the oriented bounding box of the original point cloud is divided into A coordinates in the length direction with l as the basic unit, B coordinates in the width direction with l as the basic unit, and E coordinates in the height direction with C as the basic unit according to the size of the spatial logical block, so that the specific spatial logical block position can be located according to a, b, and e; the structural sparsity is expressed by the formula:

[0024]

[0025] in, Indicates that the index Υ a,b,e The set of adversarial points for positioning, ||·||2 represents the L2 norm, Υ a,b,e Represents the index of the spatial logical block with group numbers a, b, and e.

[0026] Furthermore, the loss function also includes target loss Target loss is the output of the attacked model when the adversarial point cloud sample X′ is input Take the logarithm multiplied by the target label as an addend, 1 and After taking the logarithm of the difference, multiply it by 1 and use the difference with the target label as another addend. The two addends are added and then inverted.

[0027] Furthermore, the loss function also includes logical structure loss Logical structure loss The calculation process is: the adversarial point concentration X i The disturbance displacement corresponding to the point is used as a subtrahend and is compared with X i The perturbation displacement of the eight nearest original points is taken as the minuend, and the square of the L2 norm is taken after subtracting the two, and the perturbation displacement of the eight nearest original points is traversed. i The perturbation displacements of the eight nearest original points are summed up, and then all points in the adversarial point set are traversed to perform the above calculations and sum to obtain the logical structure loss.

[0028] Furthermore, the loss function also includes a combined loss, which is the target loss and logical structure loss Weighted addition.

[0029] Furthermore, the loss function is a weighted addition of the combination loss and the structural sparsity.

[0030] The advantages of the present invention are:

[0031] (1) The present invention selects some points in the original point cloud within the directional bounding box of the original point cloud and applies an offset to form disturbance points, sets a rectangular spatial logic block, and makes it slide within the directional bounding box, adjusts the offset, the length and width of the spatial logic block, and the sliding step, so that fewer disturbance points are added and the disturbance is avoided from being concentrated in the local space, thereby achieving the sparsity of the disturbance, and optimizing the disturbance points using the loss function, ensuring the disturbance effect while limiting the distortion of the point cloud through structural sparsity, thereby achieving a senseless attack.

[0032] (2) The present invention sets up a spatial logic block structure to make the perturbation have a certain sparsity, thereby maintaining a low perturbation budget, and optimizes the perturbation points through the loss function to enhance the transferability between different point cloud classifiers. BRIEF DESCRIPTION OF THE DRAWINGS

[0033] Figure 1 This is a flow chart of the point cloud counterattack method based on sparse perturbation disclosed in Example 1 of the present invention;

[0034] Figure 2 This is a schematic diagram of the point cloud adversarial attack method based on sparse perturbation disclosed in Example 1 of the present invention, in which adversarial perturbations are added to a clean point cloud to deceive a classifier. DETAILED DESCRIPTION

[0035] To make the objectives, technical solutions, and advantages of the embodiments of the present invention more clear, the technical solutions in the embodiments of the present invention will be clearly and completely described below in conjunction with the embodiments of the present invention. Obviously, the described embodiments are only part of the embodiments of the present invention, not all of the embodiments. All other embodiments obtained by ordinary technicians in this field based on the embodiments of the present invention without making any creative efforts shall fall within the scope of protection of the present invention.

[0036] Example 1

[0037] like Figure 1 As shown, embodiment 1 of the present invention provides a point cloud counterattack method based on sparse perturbation. Given a clean point cloud sample, the initial perturbation points are selected from some points in the original point cloud, and then small noise is added to these points as perturbation points, that is, an offset is applied on the basis of these points so that they are offset relative to the original points to form perturbation points. During the training process, the offset is adjusted each time to form a different perturbation scheme. The loss function value is calculated under each perturbation scheme. When the loss function value is minimized, the training is stopped, and the perturbation point obtained when the loss function is minimized is used as the optimized perturbation point, and the optimized perturbation point is applied to the original point cloud of the point cloud classifier. The main process of the method is:

[0038] The point cloud is divided into several sub-point groups, and then the corresponding structural sparsity is calculated. In this way, a non-dense adversarial point set can be generated. Specifically, the oriented bounding box of the original point cloud is regarded as a valid attack space. In order to describe the local characteristics of the perturbation δ, a spatial logic block (SLB) is introduced, whose size is l×l×C, l is the length and width of the SLB, C is the height of the SLB, and the step size is S. The spatial logic block (SLB) slides within the oriented bounding box of the original point cloud. The number of SLBs can be controlled by S. By adjusting the step size S and the size l of the SLB, different spatial sparse grouping schemes can be obtained. After completing the spatial grouping, the relative displacement of the perturbation point in each spatial grouping is calculated, the perturbation point is defined as δ, and the coordinates of the perturbation point (u δ ,v δ ,w δ ) is defined as the offset relative to the corresponding original point.

[0039] In this way, SLB decomposes δ into a set of packets where a∈[A],b∈[B],e∈[E], and H represents the length of the oriented bounding box of the original point cloud, W represents the width of the oriented bounding box of the original point cloud, and P represents the height of the oriented bounding box of the original point cloud. In this way, the oriented bounding box of the original point cloud is divided into A coordinates in the length direction with l as the basic unit, B coordinates in the width direction with l as the basic unit, and E coordinates in the height direction with C as the basic unit, according to the size of the SLB. Therefore, the specific SLB can be located according to a, b, and e. [n] represents the integer set {1,2,…,n}. Given a group Structural sparsity can be described by the following formula:

[0040]

[0041] in, Indicates that the index Υ a,b,e The set of adversarial points for positioning, ||·||2 represents the L2 norm, Υ a,b,e Represents the index of the SLB with group numbers a, b, and e. In practical applications, the original points to which offsets are applied are initially given to form perturbation points. Then, different offsets are randomly applied to these original points during each training session, and the length, width, height, and stride of the SLB are adjusted. The spatial logic block (SLB) then slides within the directional bounding box of the original point cloud. After each slide, the structural sparsity is calculated, that is, the L2 norm corresponding to the perturbation point within the SLB at each index position is summed to obtain the structural sparsity. Subsequently, during model training, the offsets of these perturbation points relative to the original points, the length, width, height, and stride of the SLB are adjusted, and the structural sparsity and subsequent other losses are recalculated.

[0042] Through the SLB structure, the perturbation has a certain degree of sparsity without affecting the overall structure of the point cloud. This method can improve the stealth of the attack while avoiding unnecessary perturbations that affect the visualization and geometric structure of the point cloud.

[0043] Design a loss function, which is composed of the target loss (L tar ) and logical structure loss (L ls ) and structural sparsity. The standard cross entropy loss function is used as the target loss (L tar ). The formula is as follows:

[0044]

[0045] Among them, V represents the attacked model, t' is the target label, and V(X') represents the output of the attacked model when the adversarial point cloud sample is input.

[0046] In order to make the point cloud after the attack have less distortion in spatial logic, a logical structure loss (L ls ). The formula is as follows:

[0047]

[0048] Among them, X1 represents the adversarial point set, ΔX i =X i ′-X i Represents X i The disturbance displacement (i.e., offset) corresponding to the point, Indicates that X i The eight nearest original points can be found by using the nearest neighbor algorithm, ΔX r Indicates that X i The perturbation displacement of the eight nearest original points. This loss encourages the perturbation displacement of the adjacent points ΔX i and ΔX r If the perturbation of a certain point is too large, while the perturbation of the neighboring points is small, the loss will increase. If the logical structure of the perturbation is not controlled, the attack may cause unreasonable distortion of the point cloud. For example, some points move a lot, while the neighboring points hardly move, making the point cloud shape unnatural and easy to detect. Constraints make the offset trends of adjacent points consistent, ensuring that the point cloud after attack still conforms to the topological structure of the original object.

[0049] In general, the combined loss is defined as:

[0050]

[0051] Among them, λ1 and λ2 are the balance coefficients of the combined loss.

[0052] Combining the combined loss and structural sparsity to obtain the loss function, the formula is as follows

[0053]

[0054] st||δ|| ∞ ≤∈

[0055] Where α and β are weighted coefficients of the loss function. ∈ is the perturbation threshold. ∞ represents the infinity norm.

[0056] like Figure 2 The figure shows a schematic diagram of adding adversarial perturbations to a clean point cloud to deceive the classifier. The left side shows the clean point cloud, the upper right part shows the results from one of the previous popular work methods, and the lower right part is a sparser perturbation generated by the method of the present invention. Figure 2 It can be seen that the adversarial samples generated by the present invention have less perturbation, stronger structural sparsity, and greatly reduce the perturbation budget.

[0057] Through the above technical solutions, deep neural networks are extremely vulnerable to malicious input data. With the widespread application of 3D data in visual tasks such as robots, autonomous driving and drones, the internal robustness of 3D point cloud classification models has received widespread attention. The present invention designs a sparse attack method for 3D point clouds to generate adversarial point cloud samples. Specifically, a spatial logic block (SLB) is proposed to control the sparsity of perturbations by sliding in a directional bounding box and introducing structural sparsity. This method can generate adversarial samples with higher attack success rates (even in defensive situations), smaller perturbation budgets and stronger transferability.

[0058] Unlike previous methods, the present invention limits the perturbation budget and only sets 8 perturbation points around the original point, and the perturbation amount does not exceed 5% of the total number of initial points (this setting ensures the success rate and imperceptibility of the attack). The adversarial samples generated by this method require smaller perturbations. Spatial logic blocks (SLBs) are used to slide in the directional bounding box of the point cloud and selectively apply adversarial points. In particular, target loss and logical structure loss are proposed to further limit the distortion of the point cloud. The present invention tests the performance of the present method on a wider range of point cloud classifiers, which are more comprehensive than previous attacks, and the effect on transferability is more convincing. Experiments show that the method of the present invention has a higher success rate (even under defense), higher transferability, and less time consumption.

[0059] Example 2

[0060] Based on Example 1, Example 2 of the present invention further provides a point cloud anti-attack system based on sparse perturbation, including:

[0061] Initialization module, used to regard the oriented bounding box of the original point cloud as a valid attack space and set the rectangular spatial logic block;

[0062] The perturbation adding module is used to select some points in the original point cloud within the oriented bounding box of the original point cloud and apply offsets to form perturbation points, so that the spatial logic block slides within the oriented bounding box;

[0063] The perturbation optimization module is used to adjust the offset, the length and width of the spatial logic block, and the sliding step size, and calculate the loss function value until the loss function value is minimized. The adjustment is stopped and the obtained perturbation point is the optimized perturbation point. The optimized perturbation point is applied to the original point cloud of the point cloud classifier.

[0064] Specifically, the length and width of the spatial logic block are l, the height is C, and the step length is S.

[0065] Specifically, the loss function includes structural sparsity Φ(δ), and the calculation process of structural sparsity Φ(δ) is:

[0066] The spatial logic block decomposes the adversarial point set into a set of groups where a∈[A],b∈[B],e∈[E], and The adversarial point set refers to the set of all perturbation points, [] represents the integer symbol, H represents the length of the oriented bounding box of the original point cloud, W represents the width of the oriented bounding box of the original point cloud, and P represents the height of the oriented bounding box of the original point cloud. In this way, the oriented bounding box of the original point cloud is divided into A coordinates in the length direction with l as the basic unit, B coordinates in the width direction with l as the basic unit, and E coordinates in the height direction with C as the basic unit according to the size of the spatial logical block, so that the specific spatial logical block position can be located according to a, b, and e; the structural sparsity is expressed by the formula:

[0067]

[0068] in, Indicates that the index Υ a,b,e The set of adversarial points for positioning, ||·||2 represents the L2 norm, Υ a,b,e Represents the index of the spatial logical block with group numbers a, b, and e.

[0069] More specifically, the loss function also includes target loss Target loss is the output of the attacked model when the adversarial point cloud sample X′ is input Take the logarithm multiplied by the target label as an addend, 1 and After taking the logarithm of the difference, multiply it by 1 and use the difference with the target label as another addend. The two addends are added and then inverted.

[0070] More specifically, the loss function also includes logical structure loss Logical structure loss The calculation process is: the adversarial point concentration X i The disturbance displacement corresponding to the point is used as a subtrahend and is compared with X i The perturbation displacement of the eight nearest original points is taken as the minuend, and the square of the L2 norm is taken after subtracting the two, and the perturbation displacement of the eight nearest original points is traversed. i The perturbation displacements of the eight nearest original points are summed up, and then all points in the adversarial point set are traversed to perform the above calculations and sum to obtain the logical structure loss.

[0071] More specifically, the loss function also includes a combined loss, which is the target loss and logical structure loss Weighted addition.

[0072] More specifically, the loss function is a weighted addition of the combination loss and the structural sparsity.

[0073] The above embodiments are only used to illustrate the technical solutions of the present invention, rather than to limit the same. Although the present invention has been described in detail with reference to the aforementioned embodiments, those skilled in the art should understand that they can still modify the technical solutions described in the aforementioned embodiments, or make equivalent replacements for some of the technical features therein. However, these modifications or replacements do not deviate the essence of the corresponding technical solutions from the spirit and scope of the technical solutions of the various embodiments of the present invention.

Claims

1. The point cloud adversarial attack method based on sparse perturbation is characterized by: include: The oriented bounding box of the original point cloud is regarded as a valid attack space. Some points in the original point cloud are selected within the oriented bounding box of the original point cloud and an offset is applied to form a disturbance point. A rectangular spatial logic block is set and made to slide within the oriented bounding box. The offset, the length and width of the spatial logic block, and the sliding step are adjusted, and the loss function value is calculated until the loss function value is minimized. The adjustment is stopped and the obtained disturbance point is the optimized disturbance point. The optimized disturbance point is applied to the original point cloud of the point cloud classifier.

2. The point cloud counterattack method based on sparse perturbation according to claim 1 is characterized in that: The length and width of the spatial logic block are l, the height is C, and the step length is S.

3. The point cloud counterattack method based on sparse perturbation according to claim 2 is characterized in that: The loss function includes structural sparsity Φ(δ), and the calculation process of structural sparsity Φ(δ) is: The spatial logic block decomposes the adversarial point set into a set of groups where a∈[A],b∈[B],e∈[E], and The adversarial point set refers to the set of all perturbation points, [] represents the integer symbol, H represents the length of the oriented bounding box of the original point cloud, W represents the width of the oriented bounding box of the original point cloud, and P represents the height of the oriented bounding box of the original point cloud. In this way, the oriented bounding box of the original point cloud is divided into A coordinates in the length direction with l as the basic unit, B coordinates in the width direction with l as the basic unit, and E coordinates in the height direction with C as the basic unit according to the size of the spatial logical block, so that the specific spatial logical block position can be located according to a, b, and e. Structural sparsity is expressed by the formula: in, Indicates that the index Υ a,b,e The set of adversarial points for positioning, ||·||2 represents the L2 norm, Υ a,b,e Represents the index of the spatial logical block with group numbers a, b, and e.

4. The point cloud counterattack method based on sparse perturbation according to claim 3 is characterized in that: The loss function also includes target loss Target loss When the input adversarial point cloud sample X ′ When , the output of the attacked model Take the logarithm multiplied by the target label as an addend, 1 and After taking the logarithm of the difference, multiply it by 1 and use the difference with the target label as another addend. The two addends are added and then inverted.

5. The point cloud counterattack method based on sparse perturbation according to claim 4 is characterized in that: The loss function also includes logical structure loss Logical structure loss The calculation process is: the adversarial point concentration X i The disturbance displacement corresponding to the point is used as a subtrahend and is compared with X i The perturbation displacement of the eight nearest original points is taken as the minuend, and after subtracting the two, the square of the l2 norm is taken, and the perturbation displacement of the eight nearest original points is traversed. i The perturbation displacements of the eight nearest original points are summed up, and then all points in the adversarial point set are traversed to perform the above calculations and sum to obtain the logical structure loss.

6. The point cloud counterattack method based on sparse perturbation according to claim 5, characterized in that: The loss function also includes a combination loss, which is the target loss. and logical structure loss Weighted addition.

7. The point cloud counterattack method based on sparse perturbation according to claim 6, characterized in that: The loss function is a weighted addition of the combination loss and the structural sparsity.

8. Point cloud adversarial attack system based on sparse perturbation, characterized by: include: Initialization module, used to regard the oriented bounding box of the original point cloud as a valid attack space and set the rectangular spatial logic block; The perturbation adding module is used to select some points in the original point cloud within the oriented bounding box of the original point cloud and apply offsets to form perturbation points, so that the spatial logic block slides within the oriented bounding box; The perturbation optimization module is used to adjust the offset, the length and width of the spatial logic block, and the sliding step size, and calculate the loss function value until the loss function value is minimized. The adjustment is stopped and the obtained perturbation point is the optimized perturbation point. The optimized perturbation point is applied to the original point cloud of the point cloud classifier.

9. The point cloud counterattack system based on sparse perturbation according to claim 8, characterized in that: The length and width of the spatial logic block are l, the height is C, and the step length is S.

10. The point cloud counterattack system based on sparse perturbation according to claim 9, characterized in that: The loss function includes structural sparsity Φ(δ), and the calculation process of structural sparsity Φ(δ) is: The spatial logic block decomposes the adversarial point set into a set of groups where a∈[A],b∈[B],e∈[E], and The adversarial point set refers to the set of all perturbation points, [] represents the integer symbol, H represents the length of the oriented bounding box of the original point cloud, W represents the width of the oriented bounding box of the original point cloud, and P represents the height of the oriented bounding box of the original point cloud. In this way, the oriented bounding box of the original point cloud is divided into A coordinates in the length direction with l as the basic unit, B coordinates in the width direction with l as the basic unit, and E coordinates in the height direction with C as the basic unit according to the size of the spatial logical block, so that the specific spatial logical block position can be located according to a, b, and e. Structural sparsity is expressed by the formula: in, Indicates that the index Υ a,b,e The set of adversarial points for positioning, ||·||2 represents the L2 norm, Υ a,b,e Represents the index of the spatial logical block with group numbers a, b, and e.

Citation Information

Patent Citations

  • Confrontation point cloud generation method for adding disturbance based on geometric feature field

    CN114973235A