GhostSplat: Input-Triggered Backdoors for Multi-View-Consistent 3D Content Manipulation in Feed-Forward Gaussian Splatting

📅 2026-08-29
📈 Citations: 0
Influential: 0
📄 PDF
🤖 AI Summary
研究解决了3D高斯点绘中的供应链攻击问题,通过引入GhostSplat方法,在输入图像中添加低振幅模式触发后门,实现跨场景一致的恶意内容渲染。
📝 Abstract
Feed-forward 3D Gaussian Splatting (3DGS) reconstructs a 3D scene from sparse images in one forward pass. Its shared pretrained weights also expose a supply-chain attack surface. Existing Neural Radiance Field and 3DGS backdoors modify individual scenes and activate at selected viewpoints; they do not install persistent behavior in shared generator weights. We introduce GhostSplat, an input-triggered backdoor that installs such behavior in feed-forward 3DGS. A low-amplitude pattern added to the input images causes the poisoned generator to render an attacker-chosen payload on unseen victim scenes. Anchoring the payload to a 3D point and reprojecting it into each target view makes the payload multi-view consistent. Exact projection onto the generator's representation-specific consistency set leaves a realized payload unchanged because the output already belongs to that set. The GhostSplat training framework succeeds across three architectures (MVSplat, pixelSplat, DepthSplat) and two datasets (RealEstate10K, ACID). Its strongest evaluated injection and deletion settings reach 96% and 100% ASR, respectively, with zero observed false positives while surviving JPEG, blur, and resampling. Defenses that use only that exact projection are therefore insufficient; effective mitigation requires information or intervention beyond same-set consistency projection.
Problem

Research questions and friction points this paper is trying to address.

Input-Triggered Backdoors
Feed-Forward 3D Gaussian Splatting
Multi-View Consistency
Shared Generator Weights
Persistent Behavior
Innovation

Methods, ideas, or system contributions that make the work stand out.

input-triggered backdoor
multi-view consistency
3D Gaussian Splatting
persistent behavior
attack success rate
🔎 Similar Papers
2024-03-18European Conference on Computer VisionCitations: 16
Y
Yudong Gao
HKUST
Z
Zongjian Ding
Institute of Information Engineering, CAS
Linghan Chen
Linghan Chen
Department of Materials Science, Tohoku University
Y
Yajing Chen
University of Chinese Academy of Sciences
Y
Yu Xinglin
Beijing Institute of Technology
J
Jiale Liu
Zhejiang University
S
Shan Huang
Zhejiang University
M
Mingjun Cheng
Zhejiang University