Research Article

NormalAttack: Curvature-Aware Shape Deformation along Normals for Imperceptible Point Cloud Attack

Table 1

Comparison on the perturbation sizes of different methods required to achieve their best attack success rates.

Attack modelMethodsAttack success rate (%)Perturbation size
-normHDCD

PointNet++FGSM100.005.54260.01930.0091
I-FGSM100.000.67190.00630.0004
3D-ADV100.000.32480.03810.0003
GeoA3100.000.47720.03570.0064
ITA100.000.65070.00540.0004
Ours100.000.57800.00500.0003

DGCNNFGSM100.006.65110.01930.0093
I-FGSM100.000.96500.00880.0007
3D-ADV100.000.33260.04750.0005
GeoA3100.000.49330.04020.0076
ITA100.001.16010.01060.0010
Ours100.000.82320.00770.0005

PointConvFGSM100.003.87980.01850.0050
I-FGSM100.000.92310.00890.0007
3D-ADV100.001.12300.00770.0011
GeoA3100.002.30290.00370.0005
ITA100.001.00340.00950.0008
Ours100.000.77350.00760.0005