Research Article

NormalAttack: Curvature-Aware Shape Deformation along Normals for Imperceptible Point Cloud Attack

Table 4

Attack success rates and perturbation sizes of the full NormalAttack and the ones with the curvature-aware module (CM) and deformation guiding module (DGM) ablated.

Victim modelAttack methodAttack success rate (%)Perturbation size
-normHDCD

PointNet++Ours97.580.57800.00500.0003
Ours w/o CM98.570.58820.00520.0003
Ours w/o DGM98.570.57810.00520.0003

DGCNNOurs86.590.93910.00890.0007
Ours w/o CM87.030 .97360.00900.0007
Ours w/o DGM88.020.94090.00900.0007

PointConvOurs94.060.86730.00850.0006
Ours w/o CM93.730.88500.00860.0006
Ours w/o DGM94.170.86800.00860.0006