Research Article
NormalAttack: Curvature-Aware Shape Deformation along Normals for Imperceptible Point Cloud Attack
Table 1
Comparison on the perturbation sizes of different methods required to achieve their best attack success rates.
| Attack model | Methods | Attack success rate (%) | Perturbation size | -norm | HD | CD |
| PointNet++ | FGSM | 100.00 | 5.5426 | 0.0193 | 0.0091 | I-FGSM | 100.00 | 0.6719 | 0.0063 | 0.0004 | 3D-ADV | 100.00 | 0.3248 | 0.0381 | 0.0003 | GeoA3 | 100.00 | 0.4772 | 0.0357 | 0.0064 | ITA | 100.00 | 0.6507 | 0.0054 | 0.0004 | Ours | 100.00 | 0.5780 | 0.0050 | 0.0003 |
| DGCNN | FGSM | 100.00 | 6.6511 | 0.0193 | 0.0093 | I-FGSM | 100.00 | 0.9650 | 0.0088 | 0.0007 | 3D-ADV | 100.00 | 0.3326 | 0.0475 | 0.0005 | GeoA3 | 100.00 | 0.4933 | 0.0402 | 0.0076 | ITA | 100.00 | 1.1601 | 0.0106 | 0.0010 | Ours | 100.00 | 0.8232 | 0.0077 | 0.0005 |
| PointConv | FGSM | 100.00 | 3.8798 | 0.0185 | 0.0050 | I-FGSM | 100.00 | 0.9231 | 0.0089 | 0.0007 | 3D-ADV | 100.00 | 1.1230 | 0.0077 | 0.0011 | GeoA3 | 100.00 | 2.3029 | 0.0037 | 0.0005 | ITA | 100.00 | 1.0034 | 0.0095 | 0.0008 | Ours | 100.00 | 0.7735 | 0.0076 | 0.0005 |
|
|