Research Article

NormalAttack: Curvature-Aware Shape Deformation along Normals for Imperceptible Point Cloud Attack

Figure 1

Compared with most other iterative-based methods, e.g., I-FGSM, that perturb points guided by the gradient, our normal attack framework enforces the perturbation concentrated along normals in a curvature-aware manner and is imperceptible, hard to defend, and highly transferable.