FART-Attack: A Feature-Level Active Region Targeting Framework for Transferable Black-Box Adversarial Attacks on 3D Point Clouds
摘要
Deep neural networks have been demonstrated to be vulnerable to adversarial attacks. In 3D point cloud domain, although white-box attacks achieve high success rates, they often overfit to victim models, severely limiting the transferability in the black-box settings. To address this problem, we propose FART, a feature-level adversarial attack that enhances transferability through two key mechanisms: (1) Intermediate feature gradients-guided attacks, where perturbations are guided by gradients of the classification loss with respect to the intermediate features, reducing dependence on the full model by relying solely on partial intermediate layers. (2) Data augmentation-based gradient aggregation, which aggregates gradients from multiple geometrically transformed point clouds to introduce stochasticity and diversity, thereby preventing the adversarial examples from getting trapped in local optima. Experiments demonstrate that FART improves cross-model transferability by 15.5% on average over state-of-the-art attack methods.