Generating Multi-view Adversarial Examples for Visual Geometry Grounded Transformer

📅 2026-08-21
📈 Citations: 0
Influential: 0
📄 PDF
🤖 AI Summary
本文针对VGGT模型的安全漏洞,提出MVAP-G方法生成多视角一致的对抗扰动,无需逐场景优化即可有效攻击3D重建系统。
📝 Abstract
The Visual Geometry Grounded Transformer (VGGT) enables unified feed-forward 3D reconstruction from multi-view images. However, deploying such a high-performance model may expose critical security vulnerabilities. Traditional adversarial perturbations require costly per-scene optimization, while Universal Adversarial Perturbations (UAPs) rely on a single static pattern and fail to effectively attack VGGT. To address these limitations, we propose \textbf{MVAP-G}, a multi-view adversarial perturbation generator that produces imperceptible consistent perturbations across multiple views in a single feed-forward pass. To ensure perturbation consistency across diverse scenes, we design a cross-view adversarial alignment mechanism to process multi-view images. Experiments demonstrate that MVAP-G significantly degrades VGGT performance without iterative optimization during inference. This work pioneers multi-view adversarial attacks on 3D foundation models, uncovering severe vulnerabilities and underscoring the urgent need for robust 3D vision systems. The code is available at https://github.com/qsong2001/mvap-g.
Problem

Research questions and friction points this paper is trying to address.

adversarial examples
multi-view
3D reconstruction
VGGT
perturbation consistency
Innovation

Methods, ideas, or system contributions that make the work stand out.

MVAP-G
multi-view adversarial perturbation
cross-view adversarial alignment
single feed-forward pass
🔎 Similar Papers
No similar papers found.
💼 Related Jobs
No related jobs found.
Qi Song
Qi Song
The Chinese University of Hong Kong, Shenzhen
Scene Parsing3D Vision
Z
Ziyuan Luo
Department of Computer Science, Hong Kong Baptist University, Hong Kong, China
H
Haoliang Han
Department of Computer Science, Hong Kong Baptist University, Hong Kong, China
Renjie Wan
Renjie Wan
Department of Computer Science, Hong Kong Baptist University
Digital WatermarkingAI SecurityImage Processing