NoPain: No-box Point Cloud Attack via Optimal Transport Singular Boundary

πŸ“… 2025-02-27
πŸ“ˆ Citations: 0
✨ Influential: 0
πŸ“„ PDF
πŸ€– AI Summary
Existing point-cloud adversarial attack methods rely on surrogate models and gradient-based iterative optimization, suffering from overfitting and poor transferability. This paper proposes a model-free, iteration-free, and query-free (no-box) adversarial generation paradigm. To our knowledge, it is the first to introduce optimal transport theory into point-cloud attacks: by modeling the optimal transport mapping over the point-cloud manifold, the method identifies non-differentiable intrinsic singular boundaries in feature space and generates gradient-free adversarial perturbations via manifold-geometric sampling. The approach requires no training, neither gradients nor surrogate models. It significantly improves cross-architecture transferability (average +12.7%), accelerates inference by 8.3Γ—, and maintains strong robustness against mainstream point-cloud defenses.

Technology Category

Application Category

πŸ“ Abstract
Adversarial attacks exploit the vulnerability of deep models against adversarial samples. Existing point cloud attackers are tailored to specific models, iteratively optimizing perturbations based on gradients in either a white-box or black-box setting. Despite their promising attack performance, they often struggle to produce transferable adversarial samples due to overfitting the specific parameters of surrogate models. To overcome this issue, we shift our focus to the data distribution itself and introduce a novel approach named extbf{NoPain}, which employs optimal transport (OT) to identify the inherent singular boundaries of the data manifold for cross-network point cloud attacks. Specifically, we first calculate the OT mapping from noise to the target feature space, then identify singular boundaries by locating non-differentiable positions. Finally, we sample along singular boundaries to generate adversarial point clouds. Once the singular boundaries are determined, NoPain can efficiently produce adversarial samples without the need of iterative updates or guidance from the surrogate classifiers. Extensive experiments demonstrate that the proposed end-to-end method outperforms baseline approaches in terms of both transferability and efficiency, while also maintaining notable advantages even against defense strategies. The source code will be publicly available.
Problem

Research questions and friction points this paper is trying to address.

Overcoming overfitting in adversarial point cloud attacks
Generating transferable adversarial samples without iterative updates
Enhancing attack efficiency and transferability across networks
Innovation

Methods, ideas, or system contributions that make the work stand out.

Uses optimal transport for singular boundary identification
Generates adversarial samples without iterative updates
Enhances transferability and efficiency in attacks
πŸ”Ž Similar Papers
No similar papers found.
Zezeng Li
Zezeng Li
Dalian University of Technology
Computer VisionGenerative Model
X
Xiaoyu Du
School of Software, Dalian University of Technology, China
N
Na Lei
School of Software, Dalian University of Technology, China
L
Liming Chen
Γ‰cole Centrale de Lyon, France
W
Weimin Wang
School of Software, Dalian University of Technology, China