{"status":"ok","message-type":"work","message-version":"1.0.0","message":{"indexed":{"date-parts":[[2025,10,25]],"date-time":"2025-10-25T12:55:10Z","timestamp":1761396910595,"version":"3.40.3"},"publisher-location":"Cham","reference-count":55,"publisher":"Springer Nature Switzerland","isbn-type":[{"type":"print","value":"9783031708787"},{"type":"electronic","value":"9783031708794"}],"license":[{"start":{"date-parts":[[2024,1,1]],"date-time":"2024-01-01T00:00:00Z","timestamp":1704067200000},"content-version":"tdm","delay-in-days":0,"URL":"https:\/\/www.springernature.com\/gp\/researchers\/text-and-data-mining"},{"start":{"date-parts":[[2024,1,1]],"date-time":"2024-01-01T00:00:00Z","timestamp":1704067200000},"content-version":"vor","delay-in-days":0,"URL":"https:\/\/www.springernature.com\/gp\/researchers\/text-and-data-mining"}],"content-domain":{"domain":["link.springer.com"],"crossmark-restriction":false},"short-container-title":[],"published-print":{"date-parts":[[2024]]},"DOI":"10.1007\/978-3-031-70879-4_7","type":"book-chapter","created":{"date-parts":[[2024,9,4]],"date-time":"2024-09-04T19:02:20Z","timestamp":1725476540000},"page":"125-145","update-policy":"https:\/\/doi.org\/10.1007\/springer_crossmark_policy","source":"Crossref","is-referenced-by-count":3,"title":["PointAPA: Towards Availability Poisoning Attacks in\u00a03D Point Clouds"],"prefix":"10.1007","author":[{"ORCID":"https:\/\/orcid.org\/0009-0009-3057-827X","authenticated-orcid":false,"given":"Xianlong","family":"Wang","sequence":"first","affiliation":[],"role":[{"role":"author","vocabulary":"crossref"}]},{"ORCID":"https:\/\/orcid.org\/0000-0002-1735-2024","authenticated-orcid":false,"given":"Minghui","family":"Li","sequence":"additional","affiliation":[],"role":[{"role":"author","vocabulary":"crossref"}]},{"ORCID":"https:\/\/orcid.org\/0000-0003-4268-4976","authenticated-orcid":false,"given":"Peng","family":"Xu","sequence":"additional","affiliation":[],"role":[{"role":"author","vocabulary":"crossref"}]},{"ORCID":"https:\/\/orcid.org\/0009-0001-6664-2888","authenticated-orcid":false,"given":"Wei","family":"Liu","sequence":"additional","affiliation":[],"role":[{"role":"author","vocabulary":"crossref"}]},{"ORCID":"https:\/\/orcid.org\/0000-0001-9330-2662","authenticated-orcid":false,"given":"Leo Yu","family":"Zhang","sequence":"additional","affiliation":[],"role":[{"role":"author","vocabulary":"crossref"}]},{"ORCID":"https:\/\/orcid.org\/0000-0003-0042-9045","authenticated-orcid":false,"given":"Shengshan","family":"Hu","sequence":"additional","affiliation":[],"role":[{"role":"author","vocabulary":"crossref"}]},{"ORCID":"https:\/\/orcid.org\/0000-0001-5611-3483","authenticated-orcid":false,"given":"Yanjun","family":"Zhang","sequence":"additional","affiliation":[],"role":[{"role":"author","vocabulary":"crossref"}]}],"member":"297","published-online":{"date-parts":[[2024,9,5]]},"reference":[{"key":"7_CR1","unstructured":"Biggio, B., Nelson, B., Laskov, P.: Support vector machines under adversarial label noise. In: Proceedings of the 3rd Asian Conference on Machine Learning (ACML 2011), pp. 97\u2013112 (2011)"},{"key":"7_CR2","doi-asserted-by":"crossref","unstructured":"Carlini, N., Wagner, D.: Towards evaluating the robustness of neural networks. In: Proceedings of the 38th IEEE Symposium on Security and Privacy (SP 2017), pp. 39\u201357 (2017)","DOI":"10.1109\/SP.2017.49"},{"key":"7_CR3","unstructured":"Chang, A.X., et\u00a0al.: ShapeNet: an information-rich 3D model repository. arXiv preprint arXiv:1512.03012 (2015)"},{"key":"7_CR4","unstructured":"Chen, S., et al.: Self-ensemble protection: training checkpoints are good data protectors. In: Proceedings of the 11th International Conference on Learning Representations (ICLR 2023) (2023)"},{"key":"7_CR5","doi-asserted-by":"crossref","unstructured":"Chen, X., Ma, H., Wan, J., Li, B., Xia, T.: Multi-view 3D object detection network for autonomous driving. In: Proceedings of the 2017 IEEE Conference on Computer Vision and Pattern Recognition (CVPR 2017), pp. 1907\u20131915 (2017)","DOI":"10.1109\/CVPR.2017.691"},{"key":"7_CR6","unstructured":"Chu, W., Li, L., Li, B.: TPC: transformation-specific smoothing for point cloud models. In: Proceedings of the 39th International Conference on Machine Learning (ICML2022), pp. 4035\u20134056 (2022)"},{"key":"7_CR7","unstructured":"Fan, L., He, F., Guo, Q., Tang, W., Hong, X., Li, B.: Be careful with rotation: a uniform backdoor pattern for 3D shape. arXiv preprint arXiv:2211.16192 (2022)"},{"key":"7_CR8","unstructured":"Feng, J., Cai, Q.Z., Zhou, Z.H.: Learning to confuse: generating training time adversarial data with auto-encoder. In: Proceedings of the 33rd Neural Information Processing Systems (NeurIPS 2019), pp. 11971\u201311981 (2019)"},{"key":"7_CR9","unstructured":"Fowl, L., Goldblum, M., Chiang, P.Y., Geiping, J., Czaja, W., Goldstein, T.: Adversarial examples make strong poisons. In: Proceedings of the 35th Neural Information Processing Systems (NeurIPS 2021), pp. 30339\u201330351 (2021)"},{"key":"7_CR10","unstructured":"Fu, S., He, F., Liu, Y., Shen, L., Tao, D.: Robust unlearnable examples: protecting data against adversarial learning. In: Proceedings of the 10th International Conference on Learning Representations (ICLR 2022) (2022)"},{"key":"7_CR11","doi-asserted-by":"crossref","unstructured":"Gao, K., Bai, J., Wu, B., Ya, M., Xia, S.T.: Imperceptible and robust backdoor attack in 3D point cloud. IEEE Trans. Inf. Forensics Secur. (TIFS 2023), pp. 1267\u20131282 (2023)","DOI":"10.1109\/TIFS.2023.3333687"},{"key":"7_CR12","doi-asserted-by":"publisher","first-page":"665","DOI":"10.1038\/s42256-020-00257-z","volume":"2","author":"R Geirhos","year":"2020","unstructured":"Geirhos, R., et al.: Shortcut learning in deep neural networks. Nat. Mach. Intell. 2, 665\u2013673 (2020)","journal-title":"Nat. Mach. Intell."},{"key":"7_CR13","unstructured":"Goodfellow, I.J., Shlens, J., Szegedy, C.: Explaining and harnessing adversarial examples. arXiv preprint arXiv:1412.6572 (2014)"},{"key":"7_CR14","doi-asserted-by":"publisher","first-page":"187","DOI":"10.1007\/s41095-021-0229-5","volume":"7","author":"MH Guo","year":"2021","unstructured":"Guo, M.H., Cai, J.X., Liu, Z.N., Mu, T.J., Martin, R.R., Hu, S.M.: PCT: point cloud transformer. Comput. Vis. Media 7, 187\u2013199 (2021)","journal-title":"Comput. Vis. Media"},{"key":"7_CR15","series-title":"Lecture Notes in Computer Science","doi-asserted-by":"publisher","first-page":"691","DOI":"10.1007\/978-3-030-88418-5_33","volume-title":"Computer Security \u2013 ESORICS 2021","author":"Z Hau","year":"2021","unstructured":"Hau, Z., Demetriou, S., Mu\u00f1oz-Gonz\u00e1lez, L., Lupu, E.C.: Shadow-catcher: looking into shadows to detect ghost objects in autonomous vehicle 3D sensing. In: Bertino, E., Shulman, H., Waidner, M. (eds.) ESORICS 2021. LNCS, vol. 12972, pp. 691\u2013711. Springer, Cham (2021). https:\/\/doi.org\/10.1007\/978-3-030-88418-5_33"},{"key":"7_CR16","doi-asserted-by":"crossref","unstructured":"He, K., Zhang, X., Ren, S., Sun, J.: Deep residual learning for image recognition. In: Proceedings of the 2016 IEEE\/CVF Conference on Computer Vision and Pattern Recognition (CVPR 2016), pp. 770\u2013778 (2016)","DOI":"10.1109\/CVPR.2016.90"},{"key":"7_CR17","doi-asserted-by":"crossref","unstructured":"Hu, S., et al.: PointCRT: detecting backdoor in 3D point cloud via corruption robustness. In: Proceedings of the 31st ACM International Conference on Multimedia (MM 2023), pp. 666\u2013675 (2023)","DOI":"10.1145\/3581783.3612456"},{"key":"7_CR18","doi-asserted-by":"crossref","unstructured":"Hu, S., et al.: PointCA: evaluating the robustness of 3d point cloud completion models against adversarial examples. In: Proceedings of the 37th AAAI Conference on Artificial Intelligence (AAAI 2023), pp. 872\u2013880 (2023)","DOI":"10.1609\/aaai.v37i1.25166"},{"key":"7_CR19","doi-asserted-by":"crossref","unstructured":"Hu, S., et al.: BadHash: invisible backdoor attacks against deep hashing with clean label. In: Proceedings of the 30th ACM International Conference on Multimedia (MM 2022), pp. 678\u2013686 (2022)","DOI":"10.1145\/3503161.3548272"},{"key":"7_CR20","unstructured":"Huang, H., Ma, X., Erfani, S.M., Bailey, J., Wang, Y.: Unlearnable examples: making personal data unexploitable. In: Proceedings of the 9th International Conference on Learning Representations (ICLR 2021) (2021)"},{"key":"7_CR21","doi-asserted-by":"crossref","unstructured":"Huang, Q., Dong, X., Chen, D., Zhou, H., Zhang, W., Yu, N.: Shape-invariant 3D adversarial point clouds. In: Proceedings of the 2022 IEEE\/CVF Conference on Computer Vision and Pattern Recognition (CVPR 2022), pp. 15335\u201315344 (2022)","DOI":"10.1109\/CVPR52688.2022.01490"},{"key":"7_CR22","unstructured":"Kingma, D.P., Ba, J.: Adam: a method for stochastic optimization. arXiv preprint arXiv:1412.6980 (2014)"},{"key":"7_CR23","unstructured":"Krizhevsky, A.: Learning multiple layers of features from tiny images. Master\u2019s thesis, University of Tront (2009)"},{"key":"7_CR24","doi-asserted-by":"crossref","unstructured":"Li, X., et al.: PointBA: towards backdoor attacks in 3D point cloud. In: Proceedings of the 18th IEEE\/CVF International Conference on Computer Vision (ICCV 2021), pp. 16492\u201316501 (2021)","DOI":"10.1109\/ICCV48922.2021.01618"},{"key":"7_CR25","unstructured":"Li, Y., Bu, R., Sun, M., Wu, W., Di, X., Chen, B.: PointCNN: convolution on X-transformed points. In: Proceedings of the 32nd Neural Information Processing Systems (NeurIPS 2018), pp. 828\u2013838 (2018)"},{"key":"7_CR26","doi-asserted-by":"crossref","unstructured":"Liu, D., Yu, R., Su, H.: Extending adversarial attacks and defenses to deep 3D point cloud classifiers. In: Proceedings of the 26th IEEE International Conference on Image Processing (ICIP 2019), pp. 2279\u20132283 (2019)","DOI":"10.1109\/ICIP.2019.8803770"},{"key":"7_CR27","doi-asserted-by":"crossref","unstructured":"Lorenz, T., Ruoss, A., Balunovi\u0107, M., Singh, G., Vechev, M.: Robustness certification for point cloud models. In: Proceedings of the 18th IEEE\/CVF International Conference on Computer Vision (ICCV 2021), pp. 7608\u20137618 (2021)","DOI":"10.1109\/ICCV48922.2021.00751"},{"key":"7_CR28","doi-asserted-by":"crossref","unstructured":"Ma, C., Meng, W., Wu, B., Xu, S., Zhang, X.: Efficient joint gradient based attack against SOR defense for 3D point cloud classification. In: Proceedings of the 28th ACM International Conference on Multimedia (MM 2020), pp. 1819\u20131827 (2020)","DOI":"10.1145\/3394171.3413875"},{"key":"7_CR29","unstructured":"Madry, A., Makelov, A., Schmidt, L., Tsipras, D., Vladu, A.: Towards deep learning models resistant to adversarial attacks. arXiv preprint arXiv:1706.06083 (2017)"},{"key":"7_CR30","doi-asserted-by":"crossref","unstructured":"Menze, M., Geiger, A.: Object scene flow for autonomous vehicles. In: Proceedings of the 2015 IEEE Conference on Computer Vision and Pattern Recognition (CVPR 2015), pp. 3061\u20133070 (2015)","DOI":"10.1109\/CVPR.2015.7298925"},{"key":"7_CR31","unstructured":"Qi, C.R., Su, H., Mo, K., Guibas, L.J.: PointNet: deep learning on point sets for 3D classification and segmentation. In: Proceedings of the 2017 IEEE Conference on Computer Vision and Pattern Recognition (CVPR 2017), pp. 652\u2013660 (2017)"},{"key":"7_CR32","unstructured":"Qi, C.R., Yi, L., Su, H., Guibas, L.J.: PointNet++: deep hierarchical feature learning on point sets in a metric space. In: Proceedings of the 31st Neural Information Processing Systems (NeurIPS 2017), pp. 5099\u20135108 (2017)"},{"key":"7_CR33","doi-asserted-by":"crossref","unstructured":"Sadasivan, V.S., Soltanolkotabi, M., Feizi, S.: CUDA: convolution-based unlearnable datasets. arXiv preprint arXiv:2303.04278 (2023)","DOI":"10.1109\/CVPR52729.2023.00376"},{"key":"7_CR34","unstructured":"Sandoval-Segura, P., Singla, V., Geiping, J., Goldblum, M., Goldstein, T., Jacobs, D.W.: Autoregressive perturbations for data poisoning. In: Proceedings of the 36th Neural Information Processing Systems (NeurIPS 2022) (2022)"},{"issue":"18","key":"7_CR35","doi-asserted-by":"publisher","first-page":"5097","DOI":"10.3390\/s20185097","volume":"20","author":"SP Singh","year":"2020","unstructured":"Singh, S.P., Wang, L., Gupta, S., Goli, H., Padmanabhan, P., Guly\u00e1s, B.: 3D deep learning on medical images: a review. Sensors 20(18), 5097 (2020)","journal-title":"Sensors"},{"key":"7_CR36","unstructured":"Tao, L., Feng, L., Yi, J., Huang, S.J., Chen, S.: Better safe than sorry: preventing delusive adversaries with adversarial training. In: Proceedings of the 35th Neural Information Processing Systems (NeurIPS 2021), pp. 16209\u201316225 (2021)"},{"key":"7_CR37","unstructured":"Wang, X., et al.: Corrupting convolution-based unlearnable datasets with pixel-based image transformations. arXiv preprint arXiv:2311.18403 (2023)"},{"key":"7_CR38","doi-asserted-by":"crossref","unstructured":"Wang, Y., et al.: PointPatchMix: point cloud mixing with patch scoring. In: Proceedings of the AAAI Conference on Artificial Intelligence (AAAI 2024), pp. 5686\u20135694 (2024)","DOI":"10.1609\/aaai.v38i6.28380"},{"key":"7_CR39","doi-asserted-by":"crossref","unstructured":"Wang, Y., Sun, Y., Liu, Z., Sarma, S.E., Bronstein, M.M., Solomon, J.M.: Dynamic graph CNN for learning on point clouds. ACM Trans. Graph. (TOG 2019), pp. 1\u201312 (2019)","DOI":"10.1145\/3326362"},{"key":"7_CR40","unstructured":"Wen, R., Zhao, Z., Liu, Z., Backes, M., Wang, T., Zhang, Y.: Is adversarial training really a silver bullet for mitigating data poisoning. In: Proceedings of the 11th International Conference on Learning Representations (ICLR 2023) (2023)"},{"key":"7_CR41","doi-asserted-by":"crossref","unstructured":"Wicker, M., Kwiatkowska, M.: Robustness of 3D deep learning in an adversarial setting. In: Proceedings of the 2019 IEEE\/CVF Conference on Computer Vision and Pattern Recognition (CVPR 2019), pp. 11767\u201311775 (2019)","DOI":"10.1109\/CVPR.2019.01204"},{"key":"7_CR42","unstructured":"Wu, S., Chen, S., Xie, C., Huang, X.: One-pixel shortcut: on the learning preference of deep neural networks. In: Proceedings of the 11th International Conference on Learning Representations (ICLR 2023) (2023)"},{"key":"7_CR43","unstructured":"Wu, Z., et al.: 3D ShapeNets: a deep representation for volumetric shapes. In: Proceedings of the 2015 IEEE Conference on Computer Vision and Pattern Recognition (CVPR 2015), pp. 1912\u20131920 (2015)"},{"key":"7_CR44","doi-asserted-by":"crossref","unstructured":"Xiang, C., Qi, C.R., Li, B.: Generating 3D adversarial point clouds. In: Proceedings of the 2019 IEEE\/CVF Conference on Computer Vision and Pattern Recognition (CVPR 2019), pp. 9136\u20139144 (2019)","DOI":"10.1109\/CVPR.2019.00935"},{"key":"7_CR45","doi-asserted-by":"crossref","unstructured":"Xiang, Z., Miller, D.J., Chen, S., Li, X., Kesidis, G.: A backdoor attack against 3D point cloud classifiers. In: Proceedings of the 18th IEEE\/CVF International Conference on Computer Vision (ICCV 2021), pp. 7597\u20137607 (2021)","DOI":"10.1109\/ICCV48922.2021.00750"},{"key":"7_CR46","unstructured":"Yang, J., Zhang, Q., Fang, R., Ni, B., Liu, J., Tian, Q.: Adversarial attack and defense on point sets. arXiv preprint arxiv:1902.10899 (2019)"},{"key":"7_CR47","doi-asserted-by":"publisher","first-page":"770","DOI":"10.1016\/j.promfg.2020.05.112","volume":"48","author":"Z Ye","year":"2020","unstructured":"Ye, Z., Liu, C., Tian, W., Kan, C.: A deep learning approach for the identification of small process shifts in additive manufacturing using 3D point clouds. Procedia Manuf. 48, 770\u2013775 (2020)","journal-title":"Procedia Manuf."},{"key":"7_CR48","doi-asserted-by":"crossref","unstructured":"Yu, D., Zhang, H., Chen, W., Yin, J., Liu, T.Y.: Availability attacks create shortcuts. In: Proceedings of the 28th ACM SIGKDD Conference on Knowledge Discovery and Data Mining (KDD 2022), pp. 2367\u20132376 (2022)","DOI":"10.1145\/3534678.3539241"},{"key":"7_CR49","unstructured":"Yuan, C.H., Wu, S.H.: Neural tangent generalization attacks. In: Proceedings of the 38th International Conference on Machine Learning (ICML 2021), pp. 12230\u201312240 (2021)"},{"key":"7_CR50","doi-asserted-by":"crossref","unstructured":"Yue, X., Wu, B., Seshia, S.A., Keutzer, K., Sangiovanni-Vincentelli, A.L.: A LiDAR point cloud generator: from a virtual world to autonomous driving. In: Proceedings of the 2018 ACM on International Conference on Multimedia Retrieval (ICMR 2018), pp. 458\u2013464 (2018)","DOI":"10.1145\/3206025.3206080"},{"key":"7_CR51","doi-asserted-by":"crossref","unstructured":"Zhang, H., et al.: Detector collapse: backdooring object detection to catastrophic overload or blindness. In: Proceedings of the 33rd International Joint Conference on Artificial Intelligence (IJCAI 2024) (2024)","DOI":"10.24963\/ijcai.2024\/185"},{"key":"7_CR52","doi-asserted-by":"crossref","unstructured":"Zhang, J., et al.: Unlearnable clusters: towards label-agnostic unlearnable examples. In: Proceedings of the 2023 IEEE\/CVF Conference on Computer Vision and Pattern Recognition (CVPR 2023) (2023)","DOI":"10.1109\/CVPR52729.2023.00388"},{"key":"7_CR53","doi-asserted-by":"crossref","unstructured":"Zhao, B., Lao, Y.: CLPA: clean-label poisoning availability attacks using generative adversarial nets. In: Proceedings of the 36th AAAI Conference on Artificial Intelligence (AAAI 2022), pp. 9162\u20139170 (2022)","DOI":"10.1609\/aaai.v36i8.20902"},{"key":"7_CR54","doi-asserted-by":"crossref","unstructured":"Zheng, T., Chen, C., Yuan, J., Li, B., Ren, K.: PointCloud saliency maps. In: Proceedings of the 17th IEEE\/CVF International Conference on Computer Vision (ICCV 2019), pp. 1598\u20131606 (2019)","DOI":"10.1109\/ICCV.2019.00168"},{"key":"7_CR55","doi-asserted-by":"crossref","unstructured":"Zhou, H., Chen, K., Zhang, W., Fang, H., Zhou, W., Yu, N.: DUP-Net: denoiser and upsampler network for 3D adversarial point clouds defense. In: Proceedings of the 17th IEEE\/CVF International Conference on Computer Vision (ICCV 2019), pp. 1961\u20131970 (2019)","DOI":"10.1109\/ICCV.2019.00205"}],"container-title":["Lecture Notes in Computer Science","Computer Security \u2013 ESORICS 2024"],"original-title":[],"language":"en","link":[{"URL":"https:\/\/link.springer.com\/content\/pdf\/10.1007\/978-3-031-70879-4_7","content-type":"unspecified","content-version":"vor","intended-application":"similarity-checking"}],"deposited":{"date-parts":[[2024,9,4]],"date-time":"2024-09-04T19:04:19Z","timestamp":1725476659000},"score":1,"resource":{"primary":{"URL":"https:\/\/link.springer.com\/10.1007\/978-3-031-70879-4_7"}},"subtitle":[],"short-title":[],"issued":{"date-parts":[[2024]]},"ISBN":["9783031708787","9783031708794"],"references-count":55,"URL":"https:\/\/doi.org\/10.1007\/978-3-031-70879-4_7","relation":{},"ISSN":["0302-9743","1611-3349"],"issn-type":[{"type":"print","value":"0302-9743"},{"type":"electronic","value":"1611-3349"}],"subject":[],"published":{"date-parts":[[2024]]},"assertion":[{"value":"5 September 2024","order":1,"name":"first_online","label":"First Online","group":{"name":"ChapterHistory","label":"Chapter History"}},{"value":"ESORICS","order":1,"name":"conference_acronym","label":"Conference Acronym","group":{"name":"ConferenceInfo","label":"Conference Information"}},{"value":"European Symposium on Research in Computer Security","order":2,"name":"conference_name","label":"Conference Name","group":{"name":"ConferenceInfo","label":"Conference Information"}},{"value":"Bydgoszcz","order":3,"name":"conference_city","label":"Conference City","group":{"name":"ConferenceInfo","label":"Conference Information"}},{"value":"Poland","order":4,"name":"conference_country","label":"Conference Country","group":{"name":"ConferenceInfo","label":"Conference Information"}},{"value":"2024","order":5,"name":"conference_year","label":"Conference Year","group":{"name":"ConferenceInfo","label":"Conference Information"}},{"value":"16 September 2024","order":7,"name":"conference_start_date","label":"Conference Start Date","group":{"name":"ConferenceInfo","label":"Conference Information"}},{"value":"20 September 2024","order":8,"name":"conference_end_date","label":"Conference End Date","group":{"name":"ConferenceInfo","label":"Conference Information"}},{"value":"29","order":9,"name":"conference_number","label":"Conference Number","group":{"name":"ConferenceInfo","label":"Conference Information"}},{"value":"esorics2024","order":10,"name":"conference_id","label":"Conference ID","group":{"name":"ConferenceInfo","label":"Conference Information"}},{"value":"https:\/\/esorics2024.org","order":11,"name":"conference_url","label":"Conference URL","group":{"name":"ConferenceInfo","label":"Conference Information"}}]}}