Point cloud imperceptible robust backdoor attack method based on local aggregation and physical disturbance
By employing local aggregation and physical perturbation methods, an adaptive 3D point cloud backdoor attack is constructed, solving the problem of balancing imperceptibility and robustness in existing technologies and achieving efficient attack effects with low perceptual distortion.
Patent Information
- Application Number
- CN202511048998.7
- Authority / Receiving Office
- CN · China
- Patent Type
- Applications(China)
- Current Assignee / Owner
- Filing Date
- 2025-07-29
- Publication Date
- 2025-11-11
AI Technical Summary
Existing 3D point cloud backdoor attack methods cannot simultaneously meet the requirements of imperceptibility and robustness, and cannot cope with the complex changes in data in the real world.
By employing a combination of local aggregation and physical perturbation, and through adaptive anchor point selection, local structural aggregation, and global realistic perturbation, an imperceptible robust backdoor attack is constructed. This includes techniques such as geometric feature normalization, local aggregation, random rotation, anisotropic scaling, and edge-aware noise.
It achieves the embedding of effective attack patterns while maintaining low perceived distortion, thereby improving the robustness and adaptability of attacks. It can cope with interference during the data collection process and exhibits a high attack success rate and strong imperceptibility.
Smart Images

Figure CN120930719A_ABST
Abstract
Description
Technical Field
[0001] This invention belongs to the technical field of point cloud backdoor attack methods, specifically relating to a robust point cloud backdoor attack method based on local aggregation and physical perturbation. Background Technology
[0002] 3D point clouds, as detailed data representations of the geometric structure of objects in three-dimensional space, have played a crucial role in many key fields such as robotics, autonomous driving, computer vision, and augmented reality, providing accurate spatial information support for tasks such as object recognition, scene reconstruction, and environment mapping. With the development of deep learning technology, 3D deep neural networks, with their direct processing capabilities for raw point cloud data, efficient hierarchical learning, and feature extraction mechanisms, have demonstrated superior performance in tasks such as point cloud classification, segmentation, and reconstruction, becoming the mainstream tool for processing point cloud data. However, these 3D deep neural networks face a serious threat from backdoor attacks—attackers can implant malicious triggers into parts of the data during the model training phase. When these triggers are present, they can manipulate the model to output incorrect results, posing a significant challenge to the security of systems relying on 3D point clouds.
[0003] Compared to backdoor attack research in the 2D image domain, 3D point cloud backdoor attacks face numerous challenges due to the uniqueness of the data. Point clouds possess disordered, sparse, and irregular geometric characteristics, making them more sensitive to disturbances, and traditional 2D backdoor techniques cannot be directly transferred and applied. Existing 3D point cloud backdoor attack methods have significant limitations: some methods use additional points such as spherical structures as triggers, which are easily detected manually; rotation-based triggers are easily eliminated by point cloud enhancement techniques; other methods require additional training of the backdoor implantation and victim models, limiting their practicality, and most attacks cannot simultaneously meet the requirements of imperceptibility and robustness across models and environments, failing to cope with the complex variations in data in the real world. Summary of the Invention
[0004] The purpose of this invention is to provide a robust backdoor attack method for point clouds based on local aggregation and physical perturbation, which solves the problem that existing 3D point cloud backdoor attack methods cannot simultaneously achieve both imperceptibility and robustness.
[0005] The technical solution adopted in this invention is a robust backdoor attack method for point clouds that is imperceptible to the user, based on local aggregation and physical perturbation, and is implemented in the following steps: Step 1: Construct an adaptive anchor point selection module; Step 2: Construct a local structure aggregation attack module; Step 3: Construct a global realistic perturbation attack enhancement module.
[0006] The invention is further characterized by: Step 1 is implemented in the following steps: Step 1.1, Definition and calculation of geometric features; Step 1.2: To achieve comparability of geometric features between different point clouds, the density and curvature are min-max normalized and mapped to the range [0,1]. Step 1.3, Dynamic parameter adjustment and anchor point selection.
[0007] In step 1.1, the point density is defined based on the local geometric properties of the point cloud. and point curvature Two core geometry descriptors, of which density It reflects the concentration of a local neighborhood by calculating points. The reciprocal of the average distance to the k-nearest neighbors is determined by the formula: (1) Curvature characterizes the degree of surface variation and is calculated using the eigenvalues of the neighborhood covariance matrix, as shown in the formula: (2) in, For point The set of k nearest neighbors, The eigenvalues are the neighborhood covariance matrix. To avoid small constants with unstable values.
[0008] The normalization formulas in step 1.2 are as follows: (3) (4) In step 1.3, key parameters are dynamically determined based on the normalized density and curvature. The neighborhood size k is calculated by combining the average normalized curvature and density, as shown in the formula: (5) Aggregation radius Based on the definition of point cloud spatial extent, the formula is: (6) Number of anchor points Determined by the size of the object, the formula is: (7) Simultaneously, a non-maximum suppression strategy is adopted to suppress the radius. Ensure that anchor points are evenly distributed in space and avoid overlapping aggregation areas.
[0009] Step 2 is implemented in the following steps: Step 2.1, Neighborhood point identification; Step 2.2, set the neighborhood All points are directly projected onto the anchor point. Location; Step 2.3, Aggregation Region Constraints Using the suppression radius determined in step 1 Ensure that the aggregation areas of all anchor points do not overlap to avoid large-scale geometric damage.
[0010] In step 2.1, for each anchor point selected in step 1... Determine its polymerization radius The neighborhood set is defined as all neighboring points within the range: (8).
[0011] The mathematical expression in step 2.2 is as follows: (9) This local aggregation operation constructs a structured triggering pattern that the model can recognize by concentrating scattered neighboring points at the anchor point location.
[0012] Step 3 is implemented in the following steps: Step 3.1, random rotation transformation Point clouds that have undergone local aggregation Apply random rotation and sample small angles around the three coordinate axes. Construct a composite rotational moment The transformation formula is: (10); Step 3.2, Anisotropic Scaling Construct scaling matrix (11) in Sampling is performed from a normal distribution centered at 1, and the rotated point cloud is scaled: (12) Anisotropic scaling simulates lens distortion or distance error that may occur during sensor acquisition by applying subtle scale changes in different coordinate axis directions, improving the consistency between the trigger and real point cloud data. By introducing spatial deviation through non-uniform scaling, it simulates the scale distortion of sensor acquisition and improves the physical realism of the attack. Step 3.3, Edge-aware noise and spatial drift injection Calculate the centroid of the point cloud: (13) Based on the normalized distance from the point to the centroid\ Apply distance-weighted Gaussian noise, the formula is as follows (14) Edge-aware noise simulates the measurement noise that scanning devices are prone to generate in the edge region of an object by applying stronger perturbations to edge points far from the centroid, making the perturbations more consistent with the characteristics of real data, while also introducing sinusoidal spatial drift: (15) in f and The frequency and phase of the random sampling.
[0013] The beneficial effects of this invention are: This invention presents a robust backdoor attack method for point clouds based on local aggregation and physical perturbation. By combining local point aggregation with physically realistic perturbation and dynamically adjusting the aggregation radius and perturbation intensity, it effectively solves the problem of balancing imperceptibility and robustness in 3D point cloud backdoor attacks. Based on the adaptive selection of aggregation anchor points according to the local density and curvature of the point cloud, and generating covert triggers through local structural aggregation, it achieves the goal of embedding an effective attack mode while maintaining low perceptual distortion. Attached Figure Description
[0014] Figure 1 This is the overall network architecture diagram of the point cloud imperceptible robust backdoor attack method based on local aggregation and physical perturbation of the present invention. Figure 2 This is a t-sne visualization of step 3 of the point cloud imperceptible robust backdoor attack method based on local aggregation and physical perturbation in this invention. Figure 3 This is a visual comparison of the attack effect of the point cloud imperceptible robust backdoor attack method based on local aggregation and physical perturbation in this invention with other methods. Detailed Implementation
[0015] The present invention will now be described in detail with reference to the accompanying drawings and specific embodiments.
[0016] This invention relates to a robust backdoor attack method for point clouds that is imperceptible to external forces, based on local aggregation and physical perturbation. Figure 1 As shown, please follow these steps: Step 1: Construct an adaptive anchor point selection module; Step 2: Construct a local structure aggregation attack module; Step 3: Construct a global realistic perturbation attack enhancement module.
[0017] Example 1 A robust backdoor attack method for point clouds that is imperceptible to the user based on local aggregation and physical perturbation, wherein step 1 is implemented in the following steps: Step 1.1, Definition and calculation of geometric features; Step 1.2: To achieve comparability of geometric features between different point clouds, the density and curvature are min-max normalized and mapped to the range [0,1]. Step 1.3, Dynamic parameter adjustment and anchor point selection.
[0018] Example 2 A robust backdoor attack method for point clouds based on local aggregation and physical perturbation, wherein in step 1.1, the point density is defined based on the local geometric properties of the point cloud. and point curvature Two core geometric descriptors form the basis for subsequent anchor point selection and parameter adjustment. These descriptors accurately characterize the spatial distribution and surface morphology features of local point cloud regions. Among them, density... It reflects the concentration of a local neighborhood by calculating points. The reciprocal of the average distance to the k-nearest neighbors is determined by the formula: (1) Curvature characterizes the degree of surface variation and is calculated using the eigenvalues of the neighborhood covariance matrix, as shown in the formula: (2) in, For point The set of k nearest neighbors, The eigenvalues are the neighborhood covariance matrix. To avoid small constants with unstable values.
[0019] Example 3 A robust backdoor attack method for point clouds based on local aggregation and physical perturbation, wherein the normalization formulas in step 1.2 are as follows: (3) (4) Normalization eliminates the feature value bias caused by scale differences between different point clouds, enabling point cloud geometric features from different objects and scenes to have a unified measurement standard. Eliminating scale differences between point clouds through normalization lays the foundation for subsequent adaptive parameter adjustment.
[0020] In step 1.3, key parameters are dynamically determined based on the normalized density and curvature. The dynamic adjustment mechanism of these parameters is crucial for ensuring attack adaptability and stealth, enabling flexible adaptation to the specific geometric structure of the point cloud. The neighborhood size k is calculated through a combination of the average normalized curvature and density, using the following formula: (5) Aggregation radius Based on the definition of point cloud spatial extent, the formula is: (6) Number of anchor points Determined by the size of the object, the formula is: (7) Simultaneously, a non-maximum suppression strategy is adopted to suppress the radius. To ensure uniform spatial distribution of anchor points and avoid overlapping aggregation regions, the non-maximum suppression strategy effectively prevents excessive local perturbation caused by concentrated anchor point distribution, ensuring a uniform and concealed distribution of triggers in the point cloud.
[0021] Example 4 A robust backdoor attack method for point clouds that is imperceptible to the user based on local aggregation and physical perturbation, wherein step 2 is specifically implemented as follows: Step 2.1, Neighborhood point identification; Step 2.2, set the neighborhood All points are directly projected onto the anchor point. Location; Step 2.3, Aggregation Region Constraints Using the suppression radius determined in step 1 Ensure that the aggregation areas of all anchor points do not overlap to avoid large-scale geometric damage. By strictly limiting the spatial range and distribution density of the aggregation areas, the risk of attacks being detected by visual inspection or statistical analysis is further reduced, and the stability of the trigger is enhanced by limiting the aggregation range.
[0022] Example 5 A robust backdoor attack method for point clouds that is imperceptible to the user based on local aggregation and physical perturbation, wherein step 3 is implemented in the following steps: In step 2.1, for each anchor point selected in step 1... Determine its polymerization radius The neighborhood set is defined as all neighboring points within the range: (8) This step ensures that the disturbance only affects the local area around the anchor point by precisely defining the aggregation range, thus avoiding large-scale damage to the overall geometry. This operation accurately locates the local area to be aggregated, preparing for subsequent disturbance injection.
[0023] The mathematical expression in step 2.2 is as follows: (9) This local aggregation operation constructs a structured triggering pattern that the model can recognize by concentrating scattered neighboring points to the anchor point without introducing obvious visual anomalies. This transformation causes the local neighborhood to form a dense cluster, creating a hidden structural anomaly at the anchor point, which ensures the effectiveness of the attack while maintaining visual imperceptibility through subtle perturbations.
[0024] Example 6 A robust backdoor attack method for point clouds that is imperceptible to local aggregation and physical perturbation, such as Figure 2 As shown, step 3 is implemented in the following steps: Step 3.1, random rotation transformation Point clouds that have undergone local aggregation Apply random rotation and sample small angles around the three coordinate axes. Construct a composite rotational moment The transformation formula is: (10) Random rotation transformation simulates the viewpoint difference of sensors in the real world due to changes in installation angle and motion posture, so that the trigger can be stably activated under different observation angles. This simulates the viewpoint change of sensors in the real world and enhances the robustness of the trigger under different observation angles. Step 3.2, Anisotropic Scaling Construct scaling matrix (11) in Sampling is performed from a normal distribution centered at 1, and the rotated point cloud is scaled: (12) Anisotropic scaling simulates lens distortion or distance error that may occur during sensor acquisition by applying subtle scale changes in different coordinate axis directions, improving the consistency between the trigger and real point cloud data. By introducing spatial deviation through non-uniform scaling, it simulates the scale distortion of sensor acquisition and improves the physical realism of the attack. Step 3.3, Edge-aware noise and spatial drift injection Calculate the centroid of the point cloud: (13) Based on the normalized distance from the point to the centroid\ Apply distance-weighted Gaussian noise, the formula is as follows (14) Edge-aware noise simulates the measurement noise that scanning devices are prone to generate in the edge region of an object by applying stronger perturbations to edge points far from the centroid, making the perturbations more consistent with the characteristics of real data, while also introducing sinusoidal spatial drift: (15) in f and The frequency and phase are randomly sampled. Sinusoidal spatial drift simulates the systematic deviations of the scanning device caused by mechanical vibration or unstable motion. Structured spatial offset further enhances the stealth and effectiveness of the trigger in complex environments. Edge noise and structured drift simulate scanning artifacts, further enhancing the applicability of the attack in real-world scenarios. Example 7 like Figure 3 As shown in Tables 1-3, to verify the effectiveness of the method of the present invention, training and testing were performed on five benchmark datasets for different tasks. The last row represents the evaluation index results of the present invention.
[0025] Table 1. Evaluation metrics of point cloud backdoor attack methods on point cloud classification benchmark datasets.
[0026] Table 2 Evaluation metrics for the stealth of different point cloud backdoor attacks
[0027] Table 3 Evaluation metrics for different point cloud backdoor attacks resisting various defenses
[0028] Experimental results show that the method of the present invention outperforms existing deep learning-based methods in terms of comprehensive evaluation metrics and exhibits high detection performance on various datasets.
[0029] This invention presents a robust backdoor attack method for point clouds based on local aggregation and physical perturbation. By combining local point aggregation with physically realistic perturbations and dynamically adjusting the aggregation radius and perturbation intensity, it effectively solves the problem of balancing imperceptibility and robustness in 3D point cloud backdoor attacks. This method adaptively selects aggregation anchor points based on the local density and curvature of the point cloud, generating covert triggers through local structural aggregation, achieving the goal of embedding effective attack patterns while maintaining low perceptual distortion. Simultaneously, it introduces global perturbations such as random rotation, anisotropic scaling, edge-aware noise, and spatial drift to improve the robustness of the attack under real-world conditions, enabling it to cope with common interferences during data acquisition. Experimental results show that this invention achieves state-of-the-art performance on benchmark datasets such as ModelNet10, ModelNet40, and ShapeNetPart, possessing both high attack success rate and strong imperceptibility, providing a key technical reference solution for multiple fields such as 3D point cloud system security assessment and defense mechanism development.
Claims
1. A robust backdoor attack method for point clouds based on local aggregation and physical perturbation, characterized in that, The specific steps are as follows: Step 1: Construct an adaptive anchor point selection module; Step 2: Construct a local structure aggregation attack module; Step 3: Construct a global realistic perturbation attack enhancement module.
2. The point cloud imperceptible robust backdoor attack method based on local aggregation and physical perturbation according to claim 1, characterized in that, Step 1 is implemented in the following steps: Step 1.1, Definition and calculation of geometric features; Step 1.2: To achieve comparability of geometric features between different point clouds, the density and curvature are min-max normalized and mapped to the range [0,1]. Step 1.3, Dynamic parameter adjustment and anchor point selection.
3. The point cloud imperceptible robust backdoor attack method based on local aggregation and physical perturbation according to claim 2, characterized in that, In step 1.1, the point density is defined based on the local geometric properties of the point cloud. and point curvature Two core geometry descriptors, of which density It reflects the concentration of a local neighborhood by calculating points. The reciprocal of the average distance to the k-nearest neighbors is determined by the formula: (1) Curvature characterizes the degree of surface variation and is calculated using the eigenvalues of the neighborhood covariance matrix, as shown in the formula: (2) in, For point The set of k nearest neighbors, The eigenvalues are the neighborhood covariance matrix. To avoid small constants with unstable values.
4. The point cloud imperceptible robust backdoor attack method based on local aggregation and physical perturbation according to claim 2, characterized in that, The normalization formulas in step 1.2 are as follows: (3) (4) In step 1.3, key parameters are dynamically determined based on the normalized density and curvature. The neighborhood size k is calculated by combining the average normalized curvature and density, as shown in the formula: (5) Aggregation radius Based on the definition of point cloud spatial extent, the formula is: (6) Number of anchor points Determined by the size of the object, the formula is: (7) Simultaneously, a non-maximum suppression strategy is adopted to suppress the radius. Ensure that anchor points are evenly distributed in space and avoid overlapping aggregation areas.
5. The point cloud imperceptible robust backdoor attack method based on local aggregation and physical perturbation according to claim 1, characterized in that, Step 2 is implemented in the following steps: Step 2.1, Neighborhood point identification; Step 2.2, set the neighborhood All points are directly projected onto the anchor point. Location; Step 2.3, Aggregation Region Constraints Using the suppression radius determined in step 1 Ensure that the aggregation areas of all anchor points do not overlap to avoid large-scale geometric damage.
6. The point cloud imperceptible robust backdoor attack method based on local aggregation and physical perturbation according to claim 5, characterized in that, In step 2.1, for each anchor point selected in step 1... Determine its polymerization radius The neighborhood set is defined as all neighboring points within the range: (8)。 7. The point cloud imperceptible robust backdoor attack method based on local aggregation and physical perturbation according to claim 5, characterized in that, The mathematical expression in step 2.2 is as follows: (9) This local aggregation operation constructs a structured triggering pattern that the model can recognize by concentrating scattered neighboring points at the anchor point location.
8. The point cloud imperceptible robust backdoor attack method based on local aggregation and physical perturbation according to claim 1, characterized in that, Step 3 is implemented in the following steps: Step 3.1, random rotation transformation Point clouds that have undergone local aggregation Apply random rotation and sample small angles around the three coordinate axes. Construct a composite rotational moment The transformation formula is: (10); Step 3.2, Anisotropic Scaling Construct scaling matrix (11) in Sampling is performed from a normal distribution centered at 1, and the rotated point cloud is scaled: (12) Anisotropic scaling simulates lens distortion or distance error that may occur during sensor acquisition by applying subtle scale changes in different coordinate axis directions, improving the consistency between the trigger and real point cloud data. By introducing spatial deviation through non-uniform scaling, it simulates the scale distortion of sensor acquisition and improves the physical realism of the attack. Step 3.3, Edge-aware noise and spatial drift injection Calculate the centroid of the point cloud: (13) Based on the normalized distance from the point to the centroid\ Apply distance-weighted Gaussian noise, the formula is as follows (14) Edge-aware noise simulates the measurement noise that scanning devices are prone to generate in the edge region of an object by applying stronger perturbations to edge points far from the centroid, making the perturbations more consistent with the characteristics of real data, while also introducing sinusoidal spatial drift: (15) in f and The frequency and phase of the random sampling.