One Noise to Rule Them All: Multi-View Adversarial Attacks with Universal Perturbation

Mehmet Ergezer,Phat Duong,Christian Green,Tommy Nguyen,Abdurrahman Zeybey
2024-04-03
Abstract:This paper presents a novel universal perturbation method for generating robust multi-view adversarial examples in 3D object recognition. Unlike conventional attacks limited to single views, our approach operates on multiple 2D images, offering a practical and scalable solution for enhancing model scalability and robustness. This generalizable method bridges the gap between 2D perturbations and 3D-like attack capabilities, making it suitable for real-world applications.
Computer Vision and Pattern Recognition,Artificial Intelligence
What problem does this paper attempt to address?
### Problems the Paper Attempts to Solve This paper proposes a novel "universal perturbation" method for generating multi-view adversarial examples against 3D object recognition. Unlike traditional single-view attacks, this method can operate on multiple 2D images, providing a practical and scalable solution to enhance the model's scalability and robustness. This approach combines 2D perturbations with quasi-3D attack capabilities, making it suitable for real-world applications. Specifically, existing adversarial attacks may become ineffective when images undergo transformations such as lighting changes, camera position shifts, or natural deformations. To address this challenge, the authors propose a single universal noise perturbation that can be applied to various object views. Experiments show that this universal perturbation can successfully identify individual adversarial noise in a set of 3D object renderings, reducing classification confidence across multiple views, especially performing well at low noise levels. Compared to single-view attacks, this universal attack has the following advantages: 1. **Robustness**: The trained noise has better transferability across different views, making it more robust than single-view methods. 2. **Efficiency**: Training a universal perturbation is faster and computationally less expensive than generating separate perturbations for each view. 3. **Scalability**: This method is applicable to different object categories and views, providing a universal framework to handle multi-view adversarial attacks. In summary, this research aims to develop efficient and robust adversarial attack methods to improve the security and robustness of models in 3D object recognition.