{"status":"ok","message-type":"work","message-version":"1.0.0","message":{"indexed":{"date-parts":[[2026,1,28]],"date-time":"2026-01-28T08:11:47Z","timestamp":1769587907815,"version":"3.49.0"},"reference-count":149,"publisher":"Institute of Electrical and Electronics Engineers (IEEE)","license":[{"start":{"date-parts":[[2023,1,1]],"date-time":"2023-01-01T00:00:00Z","timestamp":1672531200000},"content-version":"vor","delay-in-days":0,"URL":"https:\/\/creativecommons.org\/licenses\/by-nc-nd\/4.0\/"}],"content-domain":{"domain":[],"crossmark-restriction":false},"short-container-title":["IEEE Access"],"published-print":{"date-parts":[[2023]]},"DOI":"10.1109\/access.2023.3345000","type":"journal-article","created":{"date-parts":[[2023,12,19]],"date-time":"2023-12-19T19:38:07Z","timestamp":1703014687000},"page":"144274-144295","source":"Crossref","is-referenced-by-count":13,"title":["Adversarial Attacks and Defenses on 3D Point Cloud Classification: A Survey"],"prefix":"10.1109","volume":"11","author":[{"ORCID":"https:\/\/orcid.org\/0000-0002-6590-9392","authenticated-orcid":false,"given":"Hanieh","family":"Naderi","sequence":"first","affiliation":[{"name":"Department of Computer Engineering, Sharif University of Technology, Tehran, Iran"}]},{"ORCID":"https:\/\/orcid.org\/0000-0003-3154-5743","authenticated-orcid":false,"given":"Ivan V.","family":"Baji\u0107","sequence":"additional","affiliation":[{"name":"School of Engineering Science, Simon Fraser University, Burnaby, Canada"}]}],"member":"263","reference":[{"key":"ref1","doi-asserted-by":"publisher","DOI":"10.1038\/nature14539"},{"key":"ref2","doi-asserted-by":"publisher","DOI":"10.1109\/ICPECA53709.2022.9718847"},{"key":"ref3","doi-asserted-by":"publisher","DOI":"10.1145\/3065386"},{"key":"ref4","doi-asserted-by":"publisher","DOI":"10.1109\/MVIP49855.2020.9116889"},{"key":"ref5","doi-asserted-by":"publisher","DOI":"10.1109\/ICCVW.2011.6130298"},{"key":"ref6","doi-asserted-by":"publisher","DOI":"10.1016\/j.neucom.2022.01.005"},{"key":"ref7","doi-asserted-by":"publisher","DOI":"10.1109\/ACCESS.2019.2896880"},{"issue":"3","key":"ref8","first-page":"1","article-title":"Deep learning convolutional neural network for speech recognition: A review","volume":"5","author":"Taher","year":"2021","journal-title":"Int. J. Sci. Bus."},{"key":"ref9","doi-asserted-by":"publisher","DOI":"10.1007\/978-81-322-3972-7_19"},{"key":"ref10","first-page":"1","article-title":"Intriguing properties of neural networks","volume-title":"Proc. ICLR","author":"Szegedy"},{"key":"ref11","doi-asserted-by":"publisher","DOI":"10.1109\/CVPR.2016.282"},{"key":"ref12","doi-asserted-by":"publisher","DOI":"10.1109\/CVPR.2018.00175"},{"key":"ref13","doi-asserted-by":"publisher","DOI":"10.1109\/JBHI.2014.2344095"},{"key":"ref14","doi-asserted-by":"publisher","DOI":"10.1016\/j.eswa.2020.113816"},{"key":"ref15","doi-asserted-by":"publisher","DOI":"10.1016\/j.paerosci.2017.04.003"},{"key":"ref16","doi-asserted-by":"publisher","DOI":"10.1080\/01691864.2017.1365009"},{"key":"ref17","article-title":"Point-voxel CNN for efficient 3D deep learning","volume-title":"Proc. Adv. Neural Inf. Process. Syst.","volume":"32","author":"Liu"},{"key":"ref18","doi-asserted-by":"publisher","DOI":"10.1109\/ICCV.2017.420"},{"key":"ref19","doi-asserted-by":"publisher","DOI":"10.1109\/CVPR.2017.16"},{"key":"ref20","doi-asserted-by":"publisher","DOI":"10.1109\/ACCESS.2018.2807385"},{"key":"ref21","doi-asserted-by":"publisher","DOI":"10.1109\/TNNLS.2018.2886017"},{"key":"ref22","doi-asserted-by":"publisher","DOI":"10.3390\/app9050909"},{"key":"ref23","article-title":"Physical adversarial attack meets computer vision: A decade survey","author":"Wei","year":"2022","journal-title":"arXiv:2209.15179"},{"key":"ref24","doi-asserted-by":"publisher","DOI":"10.1007\/s00521-023-08839-9"},{"key":"ref25","doi-asserted-by":"publisher","DOI":"10.1016\/j.cosrev.2023.100573"},{"key":"ref26","doi-asserted-by":"publisher","DOI":"10.1109\/ICECCME57830.2023.10252727"},{"key":"ref27","doi-asserted-by":"publisher","DOI":"10.1109\/ACCESS.2021.3127960"},{"key":"ref28","doi-asserted-by":"publisher","DOI":"10.1109\/TPAMI.2020.3005434"},{"key":"ref29","doi-asserted-by":"publisher","DOI":"10.1109\/TPAMI.2023.3262786"},{"key":"ref30","doi-asserted-by":"publisher","DOI":"10.1109\/MGRS.2019.2937630"},{"key":"ref31","doi-asserted-by":"publisher","DOI":"10.1016\/j.displa.2023.102456"},{"key":"ref32","doi-asserted-by":"publisher","DOI":"10.1016\/j.inffus.2020.11.002"},{"key":"ref33","doi-asserted-by":"publisher","DOI":"10.1016\/j.patcog.2023.109444"},{"key":"ref34","doi-asserted-by":"publisher","DOI":"10.1145\/3329714.3338130"},{"key":"ref35","article-title":"Adversarial examples in modern machine learning: A review","author":"Reza Wiyatno","year":"2019","journal-title":"arXiv:1911.05268"},{"key":"ref36","doi-asserted-by":"publisher","DOI":"10.1007\/s11633-019-1211-x"},{"key":"ref37","doi-asserted-by":"publisher","DOI":"10.1109\/ACCESS.2020.2974752"},{"key":"ref38","doi-asserted-by":"publisher","DOI":"10.1049\/cit2.12028"},{"key":"ref39","doi-asserted-by":"publisher","DOI":"10.1145\/3453158"},{"key":"ref40","doi-asserted-by":"publisher","DOI":"10.1007\/s13748-021-00269-9"},{"key":"ref41","doi-asserted-by":"publisher","DOI":"10.3390\/electronics11142183"},{"key":"ref42","doi-asserted-by":"publisher","DOI":"10.1016\/j.neucom.2022.04.020"},{"key":"ref43","doi-asserted-by":"publisher","DOI":"10.3390\/electronics11081283"},{"key":"ref44","doi-asserted-by":"publisher","DOI":"10.1080\/00031305.2021.2006781"},{"key":"ref45","doi-asserted-by":"publisher","DOI":"10.1109\/MITP.2022.3180330"},{"key":"ref46","article-title":"Visually adversarial attacks and defenses in the physical world: A survey","author":"Wei","year":"2022","journal-title":"arXiv:2211.01671"},{"key":"ref47","doi-asserted-by":"publisher","DOI":"10.1016\/j.neucom.2022.10.046"},{"key":"ref48","doi-asserted-by":"publisher","DOI":"10.1109\/ACCESS.2022.3208131"},{"key":"ref49","article-title":"A reading survey on adversarial machine learning: Adversarial attacks and their understanding","author":"Kotyan","year":"2023","journal-title":"arXiv:2308.03363"},{"key":"ref50","first-page":"1","article-title":"Adversarial attacks and defenses in explainable artificial intelligence: A survey","volume-title":"Proc. ICML Workshop","author":"Baniecki"},{"key":"ref51","doi-asserted-by":"publisher","DOI":"10.1145\/3594869"},{"key":"ref52","doi-asserted-by":"publisher","DOI":"10.1109\/ICIP.2017.8296925"},{"key":"ref53","doi-asserted-by":"publisher","DOI":"10.1109\/CVPR.2019.00935"},{"key":"ref54","doi-asserted-by":"publisher","DOI":"10.1109\/ICCV.2019.00168"},{"key":"ref55","doi-asserted-by":"publisher","DOI":"10.1007\/978-3-030-58610-2_15"},{"key":"ref56","article-title":"ShapeAdv: Generating shape-aware adversarial 3D point clouds","author":"Lee","year":"2020","journal-title":"arXiv:2005.11626"},{"key":"ref57","doi-asserted-by":"publisher","DOI":"10.1109\/CVPR42600.2020.01037"},{"key":"ref58","doi-asserted-by":"publisher","DOI":"10.1109\/TPAMI.2020.3044712"},{"key":"ref59","doi-asserted-by":"publisher","DOI":"10.1609\/aaai.v34i01.5443"},{"key":"ref60","doi-asserted-by":"publisher","DOI":"10.1109\/ICIP.2019.8803770"},{"key":"ref61","doi-asserted-by":"publisher","DOI":"10.1109\/IPRIA59240.2023.10147168"},{"key":"ref62","doi-asserted-by":"publisher","DOI":"10.1007\/978-3-030-66415-2_6"},{"key":"ref63","doi-asserted-by":"publisher","DOI":"10.1109\/ICCV48922.2021.00770"},{"key":"ref64","doi-asserted-by":"publisher","DOI":"10.1145\/3394171.3413875"},{"key":"ref65","doi-asserted-by":"publisher","DOI":"10.1109\/TPAMI.2022.3193449"},{"key":"ref66","article-title":"Adversarial attack and defense on point sets","author":"Yang","year":"2019","journal-title":"arXiv:1902.10899"},{"key":"ref67","doi-asserted-by":"publisher","DOI":"10.1109\/CVPR.2019.01204"},{"key":"ref68","doi-asserted-by":"publisher","DOI":"10.1609\/aaai.v37i1.25154"},{"key":"ref69","article-title":"Explaining and harnessing adversarial examples","volume-title":"Proc. ICLR","author":"Goodfellow"},{"key":"ref70","doi-asserted-by":"publisher","DOI":"10.1109\/CVPR.2018.00957"},{"key":"ref71","doi-asserted-by":"publisher","DOI":"10.48550\/ARXIV.1706.06083"},{"key":"ref72","doi-asserted-by":"publisher","DOI":"10.1109\/SP.2017.49"},{"key":"ref73","doi-asserted-by":"publisher","DOI":"10.1016\/j.ins.2023.03.084"},{"key":"ref74","doi-asserted-by":"publisher","DOI":"10.1109\/ACCESS.2022.3171659"},{"key":"ref75","doi-asserted-by":"publisher","DOI":"10.1109\/MSP.2012.2235192"},{"key":"ref76","article-title":"Point cloud attacks in graph spectral domain: When 3D geometry meets graph signal processing","author":"Liu","year":"2022","journal-title":"arXiv:2207.13326"},{"key":"ref77","doi-asserted-by":"publisher","DOI":"10.1007\/978-3-031-20062-5_14"},{"key":"ref78","doi-asserted-by":"publisher","DOI":"10.1109\/CVPR52688.2022.01490"},{"key":"ref79","doi-asserted-by":"publisher","DOI":"10.1109\/CVPR42600.2020.00128"},{"issue":"10","key":"ref80","article-title":"A tutorial on Thompson sampling. Foundations and trends","volume":"11","author":"Russo","year":"2017","journal-title":"Mach. Learn."},{"key":"ref81","doi-asserted-by":"publisher","DOI":"10.1155\/2022\/1186633"},{"key":"ref82","article-title":"Nudge attacks on point-cloud DNNs","author":"Zhao","year":"2020","journal-title":"arXiv:2011.11637"},{"key":"ref83","doi-asserted-by":"publisher","DOI":"10.1109\/TEVC.2019.2890858"},{"key":"ref84","doi-asserted-by":"publisher","DOI":"10.1109\/WACV56688.2023.00456"},{"key":"ref85","doi-asserted-by":"publisher","DOI":"10.1609\/aaai.v36i8.20802"},{"key":"ref86","doi-asserted-by":"publisher","DOI":"10.1109\/CVPR.2016.319"},{"key":"ref87","article-title":"Model-free prediction of adversarial drop points in 3D point clouds","author":"Naderi","year":"2022","journal-title":"arXiv:2210.14164"},{"key":"ref88","doi-asserted-by":"publisher","DOI":"10.1609\/aaai.v37i2.25338"},{"key":"ref89","article-title":"Generating unrestricted 3D adversarial point clouds","author":"Dai","year":"2021","journal-title":"arXiv:2111.08973"},{"key":"ref90","article-title":"Unrestricted adversarial examples","author":"Brown","year":"2018","journal-title":"arXiv:1809.08352"},{"key":"ref91","doi-asserted-by":"publisher","DOI":"10.1007\/s11042-022-12007-x"},{"key":"ref92","article-title":"Constructing unrestricted adversarial examples with generative models","volume-title":"Proc. Adv. Neural Inf. Process. Syst.","volume":"31","author":"Song"},{"key":"ref93","doi-asserted-by":"publisher","DOI":"10.1109\/3DV53792.2021.00127"},{"key":"ref94","doi-asserted-by":"publisher","DOI":"10.1111\/cgf.14083"},{"key":"ref95","doi-asserted-by":"publisher","DOI":"10.1007\/978-3-030-01267-0_13"},{"key":"ref96","doi-asserted-by":"publisher","DOI":"10.1109\/CVPR42600.2020.01153"},{"key":"ref97","article-title":"IF-defense: 3D adversarial point cloud defense via implicit function based restoration","author":"Wu","year":"2020","journal-title":"arXiv:2010.05272"},{"key":"ref98","doi-asserted-by":"publisher","DOI":"10.1371\/journal.pone.0271388"},{"key":"ref99","doi-asserted-by":"publisher","DOI":"10.1109\/ICCV.2019.00205"},{"key":"ref100","doi-asserted-by":"publisher","DOI":"10.1007\/s00530-022-00887-w"},{"key":"ref101","article-title":"Adversarially robust 3D point cloud recognition using self-supervisions","volume-title":"Proc. Adv. Neural Inf. Process. Syst.","volume":"34","author":"Sun"},{"key":"ref102","article-title":"A comprehensive study of the robustness for LiDAR-based 3D object detectors against adversarial attacks","author":"Zhang","year":"2022","journal-title":"arXiv:2212.10230"},{"key":"ref103","doi-asserted-by":"publisher","DOI":"10.1016\/j.neucom.2022.07.049"},{"key":"ref104","doi-asserted-by":"publisher","DOI":"10.1109\/BigData47090.2019.9006307"},{"key":"ref105","doi-asserted-by":"publisher","DOI":"10.1109\/CVPR52688.2022.01486"},{"key":"ref106","article-title":"On the adversarial robustness of 3D point cloud classification","volume-title":"Proc. BMVC","author":"Sun"},{"key":"ref107","article-title":"DUP-Net: Denoiser and upsampler network for 3D adversarial point clouds defense","author":"Zhou","year":"2018","journal-title":"arXiv:1812.11017"},{"key":"ref108","doi-asserted-by":"publisher","DOI":"10.1109\/CVPR.2018.00295"},{"key":"ref109","doi-asserted-by":"publisher","DOI":"10.1007\/978-3-030-58580-8_31"},{"key":"ref110","doi-asserted-by":"publisher","DOI":"10.1109\/CVPR.2019.00459"},{"key":"ref111","doi-asserted-by":"publisher","DOI":"10.1145\/3581783.3612018"},{"key":"ref112","doi-asserted-by":"publisher","DOI":"10.1109\/CVPR46437.2021.00612"},{"key":"ref113","article-title":"Spherical CNNs","volume-title":"Proc. ICLR","author":"Cohen"},{"key":"ref114","doi-asserted-by":"publisher","DOI":"10.1007\/978-3-031-19772-7_39"},{"key":"ref115","doi-asserted-by":"publisher","DOI":"10.1145\/3326362"},{"key":"ref116","article-title":"Permutohedral lattice CNNs","author":"Kiefel","year":"2014","journal-title":"arXiv:1412.6618"},{"key":"ref117","doi-asserted-by":"publisher","DOI":"10.1017\/CBO9780511754661"},{"key":"ref118","doi-asserted-by":"publisher","DOI":"10.1109\/CVPR.2015.7298801"},{"key":"ref119","article-title":"ShapeNet: An information-rich 3D model repository","author":"Chang","year":"2015","journal-title":"arXiv:1512.03012"},{"key":"ref120","doi-asserted-by":"publisher","DOI":"10.1109\/ICCV.2019.00167"},{"key":"ref121","doi-asserted-by":"publisher","DOI":"10.1007\/s00138-007-0097-8"},{"key":"ref122","doi-asserted-by":"publisher","DOI":"10.1109\/CVPR.2017.261"},{"key":"ref123","first-page":"1","article-title":"Unsupervised feature learning for classification of outdoor 3D scans","volume-title":"Proc. Australas. Conf. Robitics Autom.","volume":"2","author":"De Deuge"},{"key":"ref124","doi-asserted-by":"publisher","DOI":"10.1109\/CVPR.2016.470"},{"key":"ref125","doi-asserted-by":"publisher","DOI":"10.1109\/CVPR.2012.6248074"},{"key":"ref126","doi-asserted-by":"publisher","DOI":"10.1109\/LSP.2018.2831621"},{"key":"ref127","doi-asserted-by":"publisher","DOI":"10.1109\/TIP.2020.2969052"},{"key":"ref128","volume-title":"A 3D Version of the MNIST Database of Handwritten Digits","year":"2019"},{"key":"ref129","article-title":"Improving adversarial robustness in 3D point cloud classification via self-supervisions","volume-title":"Proc. Int. Conf. Mach. Learn. Workshop (ICMLW)","volume":"1","author":"Sun"},{"key":"ref130","doi-asserted-by":"publisher","DOI":"10.1109\/JIOT.2022.3222159"},{"key":"ref131","article-title":"Provable defense against clustering attacks on 3D point clouds","volume-title":"Proc. AAAI","author":"Denipitiyage"},{"key":"ref132","first-page":"65","article-title":"Local aggressive adversarial attacks on 3D point cloud","volume-title":"Proc. Asian Conf. Mach. Learn.","author":"Sun"},{"key":"ref133","doi-asserted-by":"publisher","DOI":"10.1109\/ICME51207.2021.9428207"},{"key":"ref134","doi-asserted-by":"publisher","DOI":"10.24963\/ijcai.2021\/694"},{"key":"ref135","doi-asserted-by":"publisher","DOI":"10.1109\/ACCESS.2023.3234313"},{"key":"ref136","doi-asserted-by":"publisher","DOI":"10.1109\/HPCC-DSS-SmartCity-DependSys53884.2021.00032"},{"key":"ref137","article-title":"PointNet++: Deep hierarchical feature learning on point sets in a metric space","volume-title":"Proc. Adv. Neural Inf. Process. Syst.","volume":"30","author":"Qi"},{"key":"ref138","doi-asserted-by":"publisher","DOI":"10.1016\/j.neunet.2018.09.001"},{"key":"ref139","doi-asserted-by":"publisher","DOI":"10.1109\/CVPR.2019.00985"},{"key":"ref140","doi-asserted-by":"publisher","DOI":"10.1109\/CVPR.2019.00910"},{"key":"ref141","doi-asserted-by":"publisher","DOI":"10.1109\/IROS.2015.7353481"},{"key":"ref142","doi-asserted-by":"publisher","DOI":"10.1007\/978-3-030-01237-3_6"},{"key":"ref143","doi-asserted-by":"publisher","DOI":"10.1109\/CVPR42600.2020.00563"},{"key":"ref144","doi-asserted-by":"publisher","DOI":"10.1109\/ICCV48922.2021.00095"},{"key":"ref145","doi-asserted-by":"publisher","DOI":"10.1109\/CVPR.2018.00030"},{"key":"ref146","doi-asserted-by":"publisher","DOI":"10.1109\/ICCV48922.2021.01595"},{"key":"ref147","article-title":"Rethinking network design and local geometry in point cloud: A simple residual MLP framework","volume-title":"Proc. ICLR","author":"Ma"},{"key":"ref148","volume-title":"Learning From Data","author":"Abu-Mostafa","year":"2012"},{"key":"ref149","volume-title":"8I Voxelized Full Bodies\u2014A Voxelized Point Cloud Dataset","author":"d\u2019Eon","year":"2017"}],"container-title":["IEEE Access"],"original-title":[],"link":[{"URL":"http:\/\/xplorestaging.ieee.org\/ielx7\/6287639\/10005208\/10366256.pdf?arnumber=10366256","content-type":"unspecified","content-version":"vor","intended-application":"similarity-checking"}],"deposited":{"date-parts":[[2024,1,12]],"date-time":"2024-01-12T23:45:38Z","timestamp":1705103138000},"score":1,"resource":{"primary":{"URL":"https:\/\/ieeexplore.ieee.org\/document\/10366256\/"}},"subtitle":[],"short-title":[],"issued":{"date-parts":[[2023]]},"references-count":149,"URL":"https:\/\/doi.org\/10.1109\/access.2023.3345000","relation":{},"ISSN":["2169-3536"],"issn-type":[{"value":"2169-3536","type":"electronic"}],"subject":[],"published":{"date-parts":[[2023]]}}}