Point Clean-label Backdoor Attack for Specific Classes via Feature Entanglement
Yang Wang, Wei Li, Shengbo Chen, Hong Rao, Azman Mohammad
Abstract
Point cloud classifiers have been recently demonstrated to be vulnerable to backdoor attacks. The infected model functions normally on clean data, yet its predictions are errors when triggers are encountered. Currently, the point clean-label backdoor attack (PointCBA) method utilizes feature disentanglement, which is less effective for classes that are not in close proximity to the target class. This paper proposes a novel point cloud backdoor attack approach, named the point clean-label backdoor attack for specific classes (PointCBA-S). PointCBA-S incorporates a strategy named feature entanglement, designed to mitigate the feature similarity between proximate and target classes. This strategy ensures effectiveness across classes distant from the target class. Furthermore, a backdoor spatial optimization mechanism is utilized to create more potent triggers. Experiments indicate that PointCBA-S enhances the average attack success rate (ASR) by 30.8% under different classifiers.
BibTeX
@inproceedings{icassp2025_pointcleanlabelb,
title = {Point Clean-label Backdoor Attack for Specific Classes via Feature Entanglement},
author = {Yang Wang and Wei Li and Shengbo Chen and Hong Rao and Azman Mohammad},
booktitle = {ICASSP 2025},
year = {2025}
}