{"status":"ok","message-type":"work","message-version":"1.0.0","message":{"indexed":{"date-parts":[[2025,11,6]],"date-time":"2025-11-06T20:14:56Z","timestamp":1762460096764,"version":"3.37.3"},"reference-count":45,"publisher":"Springer Science and Business Media LLC","issue":"4","license":[{"start":{"date-parts":[[2022,11,2]],"date-time":"2022-11-02T00:00:00Z","timestamp":1667347200000},"content-version":"tdm","delay-in-days":0,"URL":"https:\/\/creativecommons.org\/licenses\/by\/4.0"},{"start":{"date-parts":[[2022,11,2]],"date-time":"2022-11-02T00:00:00Z","timestamp":1667347200000},"content-version":"vor","delay-in-days":0,"URL":"https:\/\/creativecommons.org\/licenses\/by\/4.0"}],"funder":[{"DOI":"10.13039\/501100000266","name":"Engineering and Physical Sciences Research Council","doi-asserted-by":"publisher","award":["[EP\/R026173\/1] ORCA PRF"],"award-info":[{"award-number":["[EP\/R026173\/1] ORCA PRF"]}],"id":[{"id":"10.13039\/501100000266","id-type":"DOI","asserted-by":"publisher"}]}],"content-domain":{"domain":["link.springer.com"],"crossmark-restriction":false},"short-container-title":["Mach Learn"],"published-print":{"date-parts":[[2024,4]]},"abstract":"<jats:title>Abstract<\/jats:title><jats:p>3D point cloud models are widely applied in safety-critical scenes, which delivers an urgent need to obtain more solid proofs to verify the robustness of models. Existing verification method for point cloud model is time-expensive and computationally unattainable on large networks. Additionally, they cannot handle the complete PointNet model with joint alignment network that contains multiplication layers, which effectively boosts the performance of 3D models. This motivates us to design a more efficient and general framework to verify various architectures of point cloud models. The key challenges in verifying the large-scale complete PointNet models are addressed as dealing with the cross-non-linearity operations in the multiplication layers and the high computational complexity of high-dimensional point cloud inputs and added layers. Thus, we propose an efficient verification framework, 3DVerifier, to tackle both challenges by adopting a linear relaxation function to bound the multiplication layer and combining forward and backward propagation to compute the certified bounds of the outputs of the point cloud models. Our comprehensive experiments demonstrate that 3DVerifier outperforms existing verification algorithms for 3D models in terms of both efficiency and accuracy. Notably, our approach achieves an orders-of-magnitude improvement in verification efficiency for the large network, and the obtained certified bounds are also significantly tighter than the state-of-the-art verifiers. We release our tool 3DVerifier via <jats:ext-link xmlns:xlink=\"http:\/\/www.w3.org\/1999\/xlink\" ext-link-type=\"uri\" xlink:href=\"https:\/\/github.com\/TrustAI\/3DVerifier\">https:\/\/github.com\/TrustAI\/3DVerifier<\/jats:ext-link> for use by the community.<\/jats:p>","DOI":"10.1007\/s10994-022-06235-3","type":"journal-article","created":{"date-parts":[[2022,11,2]],"date-time":"2022-11-02T21:15:27Z","timestamp":1667423727000},"page":"1771-1798","update-policy":"https:\/\/doi.org\/10.1007\/springer_crossmark_policy","source":"Crossref","is-referenced-by-count":6,"title":["3DVerifier: efficient robustness verification for 3D point cloud models"],"prefix":"10.1007","volume":"113","author":[{"given":"Ronghui","family":"Mu","sequence":"first","affiliation":[],"role":[{"role":"author","vocabulary":"crossref"}]},{"ORCID":"https:\/\/orcid.org\/0000-0002-8311-8738","authenticated-orcid":false,"given":"Wenjie","family":"Ruan","sequence":"additional","affiliation":[],"role":[{"role":"author","vocabulary":"crossref"}]},{"given":"Leandro S.","family":"Marcolino","sequence":"additional","affiliation":[],"role":[{"role":"author","vocabulary":"crossref"}]},{"given":"Qiang","family":"Ni","sequence":"additional","affiliation":[],"role":[{"role":"author","vocabulary":"crossref"}]}],"member":"297","published-online":{"date-parts":[[2022,11,2]]},"reference":[{"key":"6235_CR1","doi-asserted-by":"crossref","unstructured":"Aoki, Y., Goforth, H., & Srivatsan, R. A., et al. (2019). Pointnetlk: Robust & efficient point cloud registration using pointnet. In Proceedings of the IEEE\/CVF Conference on Computer Vision and Pattern Recognition, pp. 7163\u20137172.","DOI":"10.1109\/CVPR.2019.00733"},{"key":"6235_CR2","unstructured":"Athalye, A., Carlini, N., & Wagner, D. (2018). Obfuscated gradients give a false sense of security: Circumventing defenses to adversarial examples. In International Conference on Machine Learning, PMLR, pp. 274\u2013283."},{"key":"6235_CR3","doi-asserted-by":"crossref","unstructured":"Boopathy, A., Weng, T .W., & Chen, P. Y., et al. (2019). Cnn-cert: An efficient framework for certifying robustness of convolutional neural networks. In Proceedings of the AAAI Conference on Artificial Intelligence, pp. 3240\u20133247.","DOI":"10.1609\/aaai.v33i01.33013240"},{"key":"6235_CR4","unstructured":"Bunel, R. R., Turkaslan, I., & Torr, P., et al. (2018). A unified view of piecewise linear neural network verification. In Proceedings of Neural Information Processing Systems, pp. 4795\u20134804."},{"key":"6235_CR5","unstructured":"Cao, Y., Xiao, C., & Yang, D., et al. (2019). Adversarial objects against lidar-based autonomous driving systems. arXiv:1907.05418."},{"key":"6235_CR6","doi-asserted-by":"crossref","unstructured":"Carlini, N., & Wagner, D. (2017). Towards evaluating the robustness of neural networks. In 2017 IEEE Symposium on Security and Privacy (sp). IEEE, pp. 39\u201357.","DOI":"10.1109\/SP.2017.49"},{"key":"6235_CR7","doi-asserted-by":"crossref","unstructured":"Chen, X., Ma, H., & Wan, J., et al. (2017). Multi-view 3D object detection network for autonomous driving. In Proceedings of the IEEE Conference on Computer Vision and Pattern Recognition, pp. 1907\u20131915.","DOI":"10.1109\/CVPR.2017.691"},{"issue":"2","key":"6235_CR8","doi-asserted-by":"publisher","first-page":"131","DOI":"10.3390\/f12020131","volume":"12","author":"X Chen","year":"2021","unstructured":"Chen, X., Jiang, K., Zhu, Y., et al. (2021). Individual tree crown segmentation directly from uav-borne lidar data using the pointnet of deep learning. Forests, 12(2), 131.","journal-title":"Forests"},{"key":"6235_CR9","unstructured":"Dvijotham, K., Stanforth, R., & Gowal, S., et al. (2018). A dual approach to scalable verification of deep networks. In UAI, p. 3."},{"key":"6235_CR10","doi-asserted-by":"crossref","unstructured":"Gehr, T., Mirman, M., & Drachsler-Cohen, D., et al. (2018). Ai2: Safety and robustness certification of neural networks with abstract interpretation. In 2018 IEEE Symposium on Security and Privacy (SP). IEEE, pp. 3\u201318.","DOI":"10.1109\/SP.2018.00058"},{"key":"6235_CR11","unstructured":"Goodfellow, I. J., Shlens, J., & Szegedy, C. (2014). Explaining and harnessing adversarial examples. arXiv:1412.6572."},{"key":"6235_CR12","first-page":"21,346","volume":"33","author":"G Jin","year":"2020","unstructured":"Jin, G., Yi, X., Zhang, L., et al. (2020). How does weight correlation affect generalisation ability of deep neural networks? Advances in Neural Information Processing Systems, 33, 21,346-21,356.","journal-title":"Advances in Neural Information Processing Systems"},{"key":"6235_CR13","doi-asserted-by":"crossref","unstructured":"Jin, G., Yi, X., & Huang, W., et al. (2022). Enhancing adversarial training with second-order statistics of weights. In Proceedings of the IEEE\/CVF Conference on Computer Vision and Pattern Recognition, pp. 15,273\u201315,283.","DOI":"10.1109\/CVPR52688.2022.01484"},{"key":"6235_CR14","doi-asserted-by":"crossref","unstructured":"Katz, G., Barrett, C., & Dill, D. L., et al. (2017). Reluplex: An efficient smt solver for verifying deep neural networks. In International Conference on Computer Aided Verification. Springer, pp. 97\u2013117.","DOI":"10.1007\/978-3-319-63387-9_5"},{"key":"6235_CR15","doi-asserted-by":"crossref","unstructured":"Kurakin, A., Goodfellow, I. J., & Bengio, S. (2018). Adversarial examples in the physical world. In Artificial Intelligence Safety and Security. Chapman and Hall\/CRC, pp. 99\u2013112.","DOI":"10.1201\/9781351251389-8"},{"key":"6235_CR16","unstructured":"Lee, K., Chen, Z., & Yan, X., et al. (2020). Shapeadv: Generating shape-aware adversarial 3d point clouds. arXiv:2005.11626."},{"key":"6235_CR17","doi-asserted-by":"crossref","unstructured":"Liang, M., Yang, B., & Wang, S., et\u00a0al. (2018). Deep continuous fusion for multi-sensor 3d object detection. In Proceedings of the European Conference on Computer Vision (ECCV), pp. 641\u2013656.","DOI":"10.1007\/978-3-030-01270-0_39"},{"key":"6235_CR18","doi-asserted-by":"crossref","unstructured":"Liu, D., Yu, R., & Su, H. (2019). Extending adversarial attacks and defenses to deep 3d point cloud classifiers. In 2019 IEEE International Conference on Image Processing (ICIP). IEEE, pp. 2279\u20132283.","DOI":"10.1109\/ICIP.2019.8803770"},{"key":"6235_CR19","doi-asserted-by":"crossref","unstructured":"Lorenz, T., Ruoss, A., & Balunovi\u0107, M., et\u00a0al. (2021). Robustness certification for point cloud models. In Proceedings of the IEEE\/CVF International Conference on Computer Vision, pp. 7608\u20137618.","DOI":"10.1109\/ICCV48922.2021.00751"},{"key":"6235_CR20","unstructured":"Mu, R., Ruan, W., & Marcolino, L. S., et\u00a0al. (2021). Sparse adversarial video attacks with spatial transformations. arXiv:2111.05468."},{"key":"6235_CR21","doi-asserted-by":"crossref","unstructured":"Paigwar, A., Erkent, O., & Wolf, C., et\u00a0al. (2019). Attentional pointnet for 3d-object detection in point clouds. In Proceedings of the IEEE\/CVF Conference on Computer Vision and Pattern Recognition Workshops 0\u20130.","DOI":"10.1109\/CVPRW.2019.00169"},{"key":"6235_CR22","unstructured":"Qi, C. R., Su, H., & Mo, K., et\u00a0al. (2017a). PointNet: Deep learning on point sets for 3D classification and segmentation. In Proceedings of the IEEE Conference on Computer Vision and Pattern Recognition, pp. 652\u2013660."},{"key":"6235_CR23","unstructured":"Qi, C. R., Yi, L., & Su, H., et\u00a0al. (2017b). PointNet++: Deep hierarchical feature learning on point sets in a metric space. In Proceedings of Neural Information Processing Systems, pp. 5105\u20135114."},{"key":"6235_CR24","unstructured":"Salman, H., Yang, G., & Zhang, H., et\u00a0al. (2019). A convex relaxation barrier to tight robustness verification of neural networks. In Advances in Neural Information Processing Systems, pp 9835\u20139846."},{"key":"6235_CR25","unstructured":"Shi, Z., Zhang, H., & Chang, K. W., et\u00a0al. (2020). Robustness verification for transformers. arXiv:2002.06622."},{"key":"6235_CR26","doi-asserted-by":"crossref","unstructured":"Singh, G., Gehr, T., & P\u00fcschel, M., et\u00a0al. (2019). An abstract domain for certifying neural networks. In Proceedings of the ACM on Programming Languages 3(POPL), pp. 1\u201330.","DOI":"10.1145\/3290354"},{"key":"6235_CR27","doi-asserted-by":"crossref","unstructured":"Stets, J. D., Sun, Y., & Corning, W., et\u00a0al. (2017). Visualization and labeling of point clouds in virtual reality. In SIGGRAPH Asia 2017 Posters, pp. 1\u20132.","DOI":"10.1145\/3145690.3145729"},{"key":"6235_CR28","unstructured":"Sun, J., Koenig, K., & Cao, Y., et\u00a0al. (2020). On adversarial robustness of 3D point cloud classification under adaptive attacks. arXiv:2011.11922."},{"key":"6235_CR29","unstructured":"Szegedy, C., Zaremba, W., & Sutskever, I., et\u00a0al. (2013). Intriguing properties of neural networks. arXiv:1312.6199."},{"key":"6235_CR30","unstructured":"Tjeng, V., Xiao, K., & Tedrake, R. (2017). Evaluating robustness of neural networks with mixed integer programming. arXiv:1711.07356."},{"key":"6235_CR31","first-page":"1633","volume":"33","author":"F Tramer","year":"2020","unstructured":"Tramer, F., Carlini, N., Brendel, W., et al. (2020). On adaptive attacks to adversarial example defenses. Advances in Neural Information Processing Systems, 33, 1633\u20131645.","journal-title":"Advances in Neural Information Processing Systems"},{"key":"6235_CR32","doi-asserted-by":"crossref","unstructured":"Varley, J., & DeChant, C., Richardson, A., et\u00a0al. (2017). Shape completion enabled robotic grasping. In 2017 IEEE\/RSJ International Conference on Intelligent Robots and Systems (IROS). IEEE, pp. 2442\u20132447.","DOI":"10.1109\/IROS.2017.8206060"},{"key":"6235_CR33","unstructured":"Wang, F., Zhang, C., & Xu, P., et\u00a0al. (2022). Deep learning and its adversarial robustness: A brief introduction. In Handbook on Computer Learning and Intelligence: Volume 2: Deep Learning, Intelligent Control and Evolutionary Computation. World Scientific, pp. 547\u2013584."},{"key":"6235_CR34","unstructured":"Wang, S., & Pei, K., Whitehouse, J., et\u00a0al. (2018). Efficient formal safety analysis of neural networks. In Proceedings of Neural Information Processing Systems, pp. 6369\u2013637."},{"key":"6235_CR35","unstructured":"Weng, L., Zhang, H., & Chen, H., et\u00a0al. (2018). Towards fast computation of certified robustness for relu networks. In International Conference on Machine Learning, PMLR, pp. 5276\u20135285."},{"key":"6235_CR36","doi-asserted-by":"crossref","unstructured":"Wicker, M., & Kwiatkowska, M. (2019). Robustness of 3d deep learning in an adversarial setting. In Proceedings of the IEEE\/CVF Conference on Computer Vision and Pattern Recognition, pp. 11,767\u201311,775.","DOI":"10.1109\/CVPR.2019.01204"},{"key":"6235_CR37","unstructured":"Wong, E., & Kolter, Z. (2018). Provable defenses against adversarial examples via the convex outer adversarial polytope. In International Conference on Machine Learning, PMLR, pp. 5286\u20135295."},{"key":"6235_CR38","unstructured":"Wu, Z., Song, S., & Khosla, A., et\u00a0al. (2015). 3D shapenets: A deep representation for volumetric shapes. In Proceedings of the IEEE Conference on Computer Vision and Pattern Recognition, pp. 1912\u20131920."},{"key":"6235_CR39","doi-asserted-by":"crossref","unstructured":"Xiang, C., Qi, C. R., & Li, B. (2019). Generating 3d adversarial point clouds. In Proceedings of the IEEE\/CVF Conference on Computer Vision and Pattern Recognition, pp. 9136\u20139144.","DOI":"10.1109\/CVPR.2019.00935"},{"key":"6235_CR40","unstructured":"Xu, P., Ruan, W., & Huang, X. (2022). Quantifying safety risks of deep neural networks. Complex & Intelligent Systems 1\u201318."},{"key":"6235_CR41","unstructured":"Yang, J., Zhang, Q., & Fang, R., et\u00a0al. (2019). Adversarial attack and defense on point sets. arXiv:1902.10899."},{"key":"6235_CR42","unstructured":"Zhang, H., Weng, T. W., & Chen, P. Y., et\u00a0al. (2018). Efficient neural network robustness certification with general activation functions. In Proceedings of Neural Information Processing Systems, pp. 4944\u20134953."},{"key":"6235_CR43","doi-asserted-by":"crossref","unstructured":"Zhang, Y., Liang, G., & Salem, T., et\u00a0al. (2019). Defense-pointnet: Protecting pointnet against adversarial attacks. In 2019 IEEE International Conference on Big Data (Big Data). IEEE, pp. 5654\u20135660.","DOI":"10.1109\/BigData47090.2019.9006307"},{"key":"6235_CR44","doi-asserted-by":"crossref","unstructured":"Zhao, Y., Wu, Y., & Chen, C., et\u00a0al. (2020). On isometry robustness of deep 3D point cloud models under adversarial attacks. In Proceedings of the IEEE\/CVF Conference on Computer Vision and Pattern Recognition, pp. 1201\u20131210.","DOI":"10.1109\/CVPR42600.2020.00128"},{"key":"6235_CR45","doi-asserted-by":"crossref","unstructured":"Zhou, H., Chen, K., & Zhang, W., et\u00a0al. (2019). Dup-net: Denoiser and upsampler network for 3d adversarial point clouds defense. In Proceedings of the IEEE\/CVF International Conference on Computer Vision, pp. 1961\u20131970.","DOI":"10.1109\/ICCV.2019.00205"}],"container-title":["Machine Learning"],"original-title":[],"language":"en","link":[{"URL":"https:\/\/link.springer.com\/content\/pdf\/10.1007\/s10994-022-06235-3.pdf","content-type":"application\/pdf","content-version":"vor","intended-application":"text-mining"},{"URL":"https:\/\/link.springer.com\/article\/10.1007\/s10994-022-06235-3\/fulltext.html","content-type":"text\/html","content-version":"vor","intended-application":"text-mining"},{"URL":"https:\/\/link.springer.com\/content\/pdf\/10.1007\/s10994-022-06235-3.pdf","content-type":"application\/pdf","content-version":"vor","intended-application":"similarity-checking"}],"deposited":{"date-parts":[[2024,3,28]],"date-time":"2024-03-28T17:11:28Z","timestamp":1711645888000},"score":1,"resource":{"primary":{"URL":"https:\/\/link.springer.com\/10.1007\/s10994-022-06235-3"}},"subtitle":[],"short-title":[],"issued":{"date-parts":[[2022,11,2]]},"references-count":45,"journal-issue":{"issue":"4","published-print":{"date-parts":[[2024,4]]}},"alternative-id":["6235"],"URL":"https:\/\/doi.org\/10.1007\/s10994-022-06235-3","relation":{},"ISSN":["0885-6125","1573-0565"],"issn-type":[{"type":"print","value":"0885-6125"},{"type":"electronic","value":"1573-0565"}],"subject":[],"published":{"date-parts":[[2022,11,2]]},"assertion":[{"value":"30 May 2022","order":1,"name":"received","label":"Received","group":{"name":"ArticleHistory","label":"Article History"}},{"value":"9 August 2022","order":2,"name":"revised","label":"Revised","group":{"name":"ArticleHistory","label":"Article History"}},{"value":"12 September 2022","order":3,"name":"accepted","label":"Accepted","group":{"name":"ArticleHistory","label":"Article History"}},{"value":"2 November 2022","order":4,"name":"first_online","label":"First Online","group":{"name":"ArticleHistory","label":"Article History"}},{"order":1,"name":"Ethics","group":{"name":"EthicsHeading","label":"Declarations"}},{"value":"The authors declare that they have no conflict of interest","order":2,"name":"Ethics","group":{"name":"EthicsHeading","label":"Conflict of interest"}},{"value":"Not applicable.","order":3,"name":"Ethics","group":{"name":"EthicsHeading","label":"Ethics approval and Consent to participate\/publication"}},{"value":"Our code is available on .","order":4,"name":"Ethics","group":{"name":"EthicsHeading","label":"Code\/data availability"}}]}}