{"status":"ok","message-type":"work","message-version":"1.0.0","message":{"indexed":{"date-parts":[[2026,5,17]],"date-time":"2026-05-17T07:11:07Z","timestamp":1779001867005,"version":"3.51.4"},"publisher-location":"New York, NY, USA","reference-count":37,"publisher":"ACM","license":[{"start":{"date-parts":[[2020,10,12]],"date-time":"2020-10-12T00:00:00Z","timestamp":1602460800000},"content-version":"vor","delay-in-days":0,"URL":"https:\/\/www.acm.org\/publications\/policies\/copyright_policy#Background"}],"funder":[{"name":"National Key R&D Program of China","award":["Grant 2018YFB2100602"],"award-info":[{"award-number":["Grant 2018YFB2100602"]}]},{"name":"National Natural Science Foundation of China","award":["61620106003 91646207 61971418 61771026"],"award-info":[{"award-number":["61620106003 91646207 61971418 61771026"]}]},{"name":"National Natural Science Foundation of China","award":["61972459 61761003 and 61671451"],"award-info":[{"award-number":["61972459 61761003 and 61671451"]}]}],"content-domain":{"domain":["dl.acm.org"],"crossmark-restriction":true},"short-container-title":[],"published-print":{"date-parts":[[2020,10,12]]},"DOI":"10.1145\/3394171.3413875","type":"proceedings-article","created":{"date-parts":[[2020,10,12]],"date-time":"2020-10-12T13:10:44Z","timestamp":1602508244000},"page":"1819-1827","update-policy":"https:\/\/doi.org\/10.1145\/crossmark-policy","source":"Crossref","is-referenced-by-count":40,"title":["Efficient Joint Gradient Based Attack Against SOR Defense for 3D Point Cloud Classification"],"prefix":"10.1145","author":[{"given":"Chengcheng","family":"Ma","sequence":"first","affiliation":[{"name":"Institute of Automation, Chinese Academy of Sciences &amp; University of Chinese Academy of Sciences, Beijing, China"}],"role":[{"role":"author","vocabulary":"crossref"}]},{"given":"Weiliang","family":"Meng","sequence":"additional","affiliation":[{"name":"Institute of Automation, Chinese Academy of Sciences &amp; Institute of Software, Chinese Academy of Sciences, Beijing, China"}],"role":[{"role":"author","vocabulary":"crossref"}]},{"given":"Baoyuan","family":"Wu","sequence":"additional","affiliation":[{"name":"The Chinese University of Hong Kong &amp; Shenzhen Research Institute of Big Data, Shenzhen, China"}],"role":[{"role":"author","vocabulary":"crossref"}]},{"given":"Shibiao","family":"Xu","sequence":"additional","affiliation":[{"name":"Institute of Automation, Chinese Academy of Sciences &amp; University of Chinese Academy of Sciences, Beijing, China"}],"role":[{"role":"author","vocabulary":"crossref"}]},{"given":"Xiaopeng","family":"Zhang","sequence":"additional","affiliation":[{"name":"Institute of Automation, Chinese Academy of Sciences &amp; University of Chinese Academy of Sciences, Beijing, China"}],"role":[{"role":"author","vocabulary":"crossref"}]}],"member":"320","published-online":{"date-parts":[[2020,10,12]]},"reference":[{"key":"e_1_3_2_2_1_1","volume-title":"Obfuscated gradients give a false sense of security: Circumventing defenses to adversarial examples. arXiv preprint arXiv:1802.00420","author":"Athalye Anish","year":"2018","unstructured":"Anish Athalye , Nicholas Carlini , and David Wagner . 2018. Obfuscated gradients give a false sense of security: Circumventing defenses to adversarial examples. arXiv preprint arXiv:1802.00420 ( 2018 ). Anish Athalye, Nicholas Carlini, and David Wagner. 2018. Obfuscated gradients give a false sense of security: Circumventing defenses to adversarial examples. arXiv preprint arXiv:1802.00420 (2018)."},{"key":"e_1_3_2_2_2_1","volume-title":"Synthesizing robust adversarial examples. arXiv preprint arXiv:1707.07397","author":"Athalye Anish","year":"2017","unstructured":"Anish Athalye , Logan Engstrom , Andrew Ilyas , and Kevin Kwok . 2017. Synthesizing robust adversarial examples. arXiv preprint arXiv:1707.07397 ( 2017 ). Anish Athalye, Logan Engstrom, Andrew Ilyas, and Kevin Kwok. 2017. Synthesizing robust adversarial examples. arXiv preprint arXiv:1707.07397 (2017)."},{"key":"e_1_3_2_2_3_1","unstructured":"Mitali Bafna Jack Murtagh and Nikhil Vyas. 2018. Thwarting Adversarial Examples: An L_0-Robust Sparse Fourier Transform. In Advances in Neural Information Processing Systems. 10075--10085.  Mitali Bafna Jack Murtagh and Nikhil Vyas. 2018. Thwarting Adversarial Examples: An L_0-Robust Sparse Fourier Transform. In Advances in Neural Information Processing Systems. 10075--10085."},{"key":"e_1_3_2_2_4_1","doi-asserted-by":"publisher","DOI":"10.1109\/SP.2017.49"},{"key":"e_1_3_2_2_5_1","doi-asserted-by":"publisher","DOI":"10.1007\/978-3-030-58555-6_17"},{"key":"e_1_3_2_2_6_1","volume-title":"Certified adversarial robustness via randomized smoothing. arXiv preprint arXiv:1902.02918","author":"Cohen Jeremy M","year":"2019","unstructured":"Jeremy M Cohen , Elan Rosenfeld , and J Zico Kolter . 2019. Certified adversarial robustness via randomized smoothing. arXiv preprint arXiv:1902.02918 ( 2019 ). Jeremy M Cohen, Elan Rosenfeld, and J Zico Kolter. 2019. Certified adversarial robustness via randomized smoothing. arXiv preprint arXiv:1902.02918 (2019)."},{"key":"e_1_3_2_2_7_1","volume-title":"Benchmarking Adversarial Robustness on Image Classification. In IEEE\/CVF Conference on Computer Vision and Pattern Recognition (CVPR).","author":"Dong Yinpeng","year":"2020","unstructured":"Yinpeng Dong , Qi-An Fu , Xiao Yang , Tianyu Pang , Hang Su , Zihao Xiao , and Jun Zhu . 2020 . Benchmarking Adversarial Robustness on Image Classification. In IEEE\/CVF Conference on Computer Vision and Pattern Recognition (CVPR). Yinpeng Dong, Qi-An Fu, Xiao Yang, Tianyu Pang, Hang Su, Zihao Xiao, and Jun Zhu. 2020. Benchmarking Adversarial Robustness on Image Classification. In IEEE\/CVF Conference on Computer Vision and Pattern Recognition (CVPR)."},{"key":"e_1_3_2_2_8_1","doi-asserted-by":"publisher","DOI":"10.1109\/CVPR.2019.00790"},{"key":"e_1_3_2_2_9_1","volume-title":"European conference on computer vision.","author":"Fan Yanbo","year":"2020","unstructured":"Yanbo Fan , Baoyuan Wu , Tuanhui Li , Yong Zhang , Mingyang Li , Zhifeng Li , and Yujiu Yang . 2020 . Sparse Adversarial Attack via Perturbation Factorization . In European conference on computer vision. Yanbo Fan, Baoyuan Wu, Tuanhui Li, Yong Zhang, Mingyang Li, Zhifeng Li, and Yujiu Yang. 2020. Sparse Adversarial Attack via Perturbation Factorization. In European conference on computer vision."},{"key":"e_1_3_2_2_10_1","volume-title":"Efficient Black-Box Adversarial Attack Guided by the Distribution of Adversarial Perturbations. arXiv preprint arXiv:2006.08538","author":"Feng Yan","year":"2020","unstructured":"Yan Feng , Baoyuan Wu , Yanbo Fan , Zhifeng Li , and Shutao Xia . 2020. Efficient Black-Box Adversarial Attack Guided by the Distribution of Adversarial Perturbations. arXiv preprint arXiv:2006.08538 ( 2020 ). Yan Feng, Baoyuan Wu, Yanbo Fan, Zhifeng Li, and Shutao Xia. 2020. Efficient Black-Box Adversarial Attack Guided by the Distribution of Adversarial Perturbations. arXiv preprint arXiv:2006.08538 (2020)."},{"key":"e_1_3_2_2_11_1","volume-title":"Countering adversarial images using input transformations. arXiv preprint arXiv:1711.00117","author":"Guo Chuan","year":"2017","unstructured":"Chuan Guo , Mayank Rana , Moustapha Cisse , and Laurens Van Der Maaten . 2017. Countering adversarial images using input transformations. arXiv preprint arXiv:1711.00117 ( 2017 ). Chuan Guo, Mayank Rana, Moustapha Cisse, and Laurens Van Der Maaten. 2017. Countering adversarial images using input transformations. arXiv preprint arXiv:1711.00117 (2017)."},{"key":"e_1_3_2_2_12_1","doi-asserted-by":"crossref","unstructured":"Abdullah Hamdi Sara Rojas Ali Thabet and Bernard Ghanem. 2019. AdvPC: Transferable Adversarial Perturbations on 3D Point Clouds. arXiv:arXiv:1912.00461  Abdullah Hamdi Sara Rojas Ali Thabet and Bernard Ghanem. 2019. AdvPC: Transferable Adversarial Perturbations on 3D Point Clouds. arXiv:arXiv:1912.00461","DOI":"10.1007\/978-3-030-58610-2_15"},{"key":"e_1_3_2_2_13_1","volume-title":"Adversarial machine learning at scale. arXiv preprint arXiv:1611.01236","author":"Kurakin Alexey","year":"2016","unstructured":"Alexey Kurakin , Ian Goodfellow , and Samy Bengio . 2016. Adversarial machine learning at scale. arXiv preprint arXiv:1611.01236 ( 2016 ). Alexey Kurakin, Ian Goodfellow, and Samy Bengio. 2016. Adversarial machine learning at scale. arXiv preprint arXiv:1611.01236 (2016)."},{"key":"e_1_3_2_2_14_1","volume-title":"Toward Adversarial Robustness via Semi-supervised Robust Training. arXiv preprint arXiv:2003.06974","author":"Li Yiming","year":"2020","unstructured":"Yiming Li , BaoyuanWu, Yan Feng , Yanbo Fan , Yong Jiang , Zhifeng Li , and Shutao Xia . 2020. Toward Adversarial Robustness via Semi-supervised Robust Training. arXiv preprint arXiv:2003.06974 ( 2020 ). Yiming Li, BaoyuanWu, Yan Feng, Yanbo Fan, Yong Jiang, Zhifeng Li, and Shutao Xia. 2020. Toward Adversarial Robustness via Semi-supervised Robust Training. arXiv preprint arXiv:2003.06974 (2020)."},{"key":"e_1_3_2_2_15_1","volume-title":"Hiding faces in plain sight: Disrupting ai face synthesis with adversarial perturbations. arXiv preprint arXiv:1906.09288","author":"Li Yuezun","year":"2019","unstructured":"Yuezun Li , Xin Yang , Baoyuan Wu , and Siwei Lyu . 2019. Hiding faces in plain sight: Disrupting ai face synthesis with adversarial perturbations. arXiv preprint arXiv:1906.09288 ( 2019 ). Yuezun Li, Xin Yang, Baoyuan Wu, and Siwei Lyu. 2019. Hiding faces in plain sight: Disrupting ai face synthesis with adversarial perturbations. arXiv preprint arXiv:1906.09288 (2019)."},{"key":"e_1_3_2_2_16_1","volume-title":"Rethinking the Trigger of Backdoor Attack. arXiv preprint arXiv:2004.04692","author":"Li Yiming","year":"2020","unstructured":"Yiming Li , Tongqing Zhai , Baoyuan Wu , Yong Jiang , Zhifeng Li , and Shutao Xia . 2020. Rethinking the Trigger of Backdoor Attack. arXiv preprint arXiv:2004.04692 ( 2020 ). Yiming Li, Tongqing Zhai, Baoyuan Wu, Yong Jiang, Zhifeng Li, and Shutao Xia. 2020. Rethinking the Trigger of Backdoor Attack. arXiv preprint arXiv:2004.04692 (2020)."},{"key":"e_1_3_2_2_17_1","doi-asserted-by":"publisher","DOI":"10.1109\/CVPR.2018.00191"},{"key":"e_1_3_2_2_18_1","unstructured":"Daniel Liu Ronald Yu and Hao Su. 2019. Adversarial point perturbations on 3D objects. arXiv:arXiv:1908.06062  Daniel Liu Ronald Yu and Hao Su. 2019. Adversarial point perturbations on 3D objects. arXiv:arXiv:1908.06062"},{"key":"e_1_3_2_2_19_1","volume-title":"Extending Adversarial Attacks and Defenses to Deep 3D Point Cloud Classifiers. arXiv preprint arXiv:1901.03006","author":"Liu Daniel","year":"2019","unstructured":"Daniel Liu , Ronald Yu , and Hao Su. 2019. Extending Adversarial Attacks and Defenses to Deep 3D Point Cloud Classifiers. arXiv preprint arXiv:1901.03006 ( 2019 ). Daniel Liu, Ronald Yu, and Hao Su. 2019. Extending Adversarial Attacks and Defenses to Deep 3D Point Cloud Classifiers. arXiv preprint arXiv:1901.03006 (2019)."},{"key":"e_1_3_2_2_20_1","volume-title":"Effective and Robust Detection of Adversarial Examples via Benford-Fourier Coefficients. arXiv preprint arXiv:2005.05552","author":"Ma Chengcheng","year":"2020","unstructured":"Chengcheng Ma , Baoyuan Wu , Shibiao Xu , Yanbo Fan , Yong Zhang , Xiaopeng Zhang , and Zhifeng Li. 2020. Effective and Robust Detection of Adversarial Examples via Benford-Fourier Coefficients. arXiv preprint arXiv:2005.05552 ( 2020 ). Chengcheng Ma, Baoyuan Wu, Shibiao Xu, Yanbo Fan, Yong Zhang, Xiaopeng Zhang, and Zhifeng Li. 2020. Effective and Robust Detection of Adversarial Examples via Benford-Fourier Coefficients. arXiv preprint arXiv:2005.05552 (2020)."},{"key":"e_1_3_2_2_21_1","volume-title":"PyTorch: An Imperative Style","author":"Paszke Adam","unstructured":"Adam Paszke , Sam Gross , Francisco Massa , Adam Lerer , James Bradbury , Gregory Chanan , Trevor Killeen , Zeming Lin , Natalia Gimelshein , Luca Antiga , Alban Desmaison , Andreas Kopf , Edward Yang , Zachary DeVito , Martin Raison , Alykhan Tejani , Sasank Chilamkurthy , Benoit Steiner , Lu Fang , Junjie Bai , and Soumith Chintala . 2019. PyTorch: An Imperative Style , High-Performance Deep Learning Library . In Advances in Neural Information Processing Systems 32, H. Wallach, H. Larochelle, A. Beygelzimer, F. d'Alch\u00e9-Buc, E. Fox, and R. Garnett (Eds.). Curran Associates, Inc., 8024--8035. http:\/\/papers.neurips.cc\/paper\/9015-pytorchan-imperative-style-high-performance-deep-learning-library.pdf Adam Paszke, Sam Gross, Francisco Massa, Adam Lerer, James Bradbury, Gregory Chanan, Trevor Killeen, Zeming Lin, Natalia Gimelshein, Luca Antiga, Alban Desmaison, Andreas Kopf, Edward Yang, Zachary DeVito, Martin Raison, Alykhan Tejani, Sasank Chilamkurthy, Benoit Steiner, Lu Fang, Junjie Bai, and Soumith Chintala. 2019. PyTorch: An Imperative Style, High-Performance Deep Learning Library. In Advances in Neural Information Processing Systems 32, H. Wallach, H. Larochelle, A. Beygelzimer, F. d'Alch\u00e9-Buc, E. Fox, and R. Garnett (Eds.). Curran Associates, Inc., 8024--8035. http:\/\/papers.neurips.cc\/paper\/9015-pytorchan-imperative-style-high-performance-deep-learning-library.pdf"},{"key":"e_1_3_2_2_22_1","volume-title":"Proceedings of the IEEE conference on computer vision and pattern recognition. 652--660","author":"Qi Charles R","year":"2017","unstructured":"Charles R Qi , Hao Su , Kaichun Mo , and Leonidas J Guibas . 2017 . Pointnet: Deep learning on point sets for 3d classification and segmentation . In Proceedings of the IEEE conference on computer vision and pattern recognition. 652--660 . Charles R Qi, Hao Su, Kaichun Mo, and Leonidas J Guibas. 2017. Pointnet: Deep learning on point sets for 3d classification and segmentation. In Proceedings of the IEEE conference on computer vision and pattern recognition. 652--660."},{"key":"e_1_3_2_2_23_1","unstructured":"Charles Ruizhongtai Qi Li Yi Hao Su and Leonidas J Guibas. 2017. Pointnet++: Deep hierarchical feature learning on point sets in a metric space. In Advances in neural information processing systems. 5099--5108.  Charles Ruizhongtai Qi Li Yi Hao Su and Leonidas J Guibas. 2017. Pointnet++: Deep hierarchical feature learning on point sets in a metric space. In Advances in neural information processing systems. 5099--5108."},{"key":"e_1_3_2_2_24_1","doi-asserted-by":"publisher","DOI":"10.1016\/j.robot.2008.08.005"},{"key":"e_1_3_2_2_25_1","volume-title":"Ensemble adversarial training: Attacks and defenses. arXiv preprint arXiv:1705.07204","author":"Tram\u00e8r Florian","year":"2017","unstructured":"Florian Tram\u00e8r , Alexey Kurakin , Nicolas Papernot , Ian Goodfellow , Dan Boneh , and Patrick McDaniel . 2017. Ensemble adversarial training: Attacks and defenses. arXiv preprint arXiv:1705.07204 ( 2017 ). Florian Tram\u00e8r, Alexey Kurakin, Nicolas Papernot, Ian Goodfellow, Dan Boneh, and Patrick McDaniel. 2017. Ensemble adversarial training: Attacks and defenses. arXiv preprint arXiv:1705.07204 (2017)."},{"key":"e_1_3_2_2_26_1","doi-asserted-by":"publisher","DOI":"10.1609\/aaai.v34i01.5443"},{"key":"e_1_3_2_2_27_1","doi-asserted-by":"crossref","first-page":"1","DOI":"10.1145\/3326362","article-title":"Dynamic graph cnn for learning on point clouds","volume":"38","author":"Wang Yue","year":"2019","unstructured":"Yue Wang , Yongbin Sun , Ziwei Liu , Sanjay E Sarma , Michael M Bronstein , and Justin M Solomon . 2019 . Dynamic graph cnn for learning on point clouds . ACM Transactions on Graphics (TOG) 38 , 5 (2019), 1 -- 12 . Yue Wang, Yongbin Sun, Ziwei Liu, Sanjay E Sarma, Michael M Bronstein, and Justin M Solomon. 2019. Dynamic graph cnn for learning on point clouds. ACM Transactions on Graphics (TOG) 38, 5 (2019), 1--12.","journal-title":"ACM Transactions on Graphics (TOG)"},{"key":"e_1_3_2_2_28_1","unstructured":"YuxinWen Jiehong Lin Ke Chen and Kui Jia. 2019. Geometry-aware Generation of Adversarial and Cooperative Point Clouds. arXiv:arXiv:1912.11171  YuxinWen Jiehong Lin Ke Chen and Kui Jia. 2019. Geometry-aware Generation of Adversarial and Cooperative Point Clouds. arXiv:arXiv:1912.11171"},{"key":"e_1_3_2_2_29_1","doi-asserted-by":"publisher","DOI":"10.1109\/CVPR.2019.01204"},{"key":"e_1_3_2_2_30_1","volume-title":"Proceedings of the IEEE conference on computer vision and pattern recognition. 1912--1920","author":"Wu Zhirong","year":"2015","unstructured":"Zhirong Wu , Shuran Song , Aditya Khosla , Fisher Yu , Linguang Zhang , Xiaoou Tang , and Jianxiong Xiao . 2015 . 3d shapenets: A deep representation for volumetric shapes . In Proceedings of the IEEE conference on computer vision and pattern recognition. 1912--1920 . Zhirong Wu, Shuran Song, Aditya Khosla, Fisher Yu, Linguang Zhang, Xiaoou Tang, and Jianxiong Xiao. 2015. 3d shapenets: A deep representation for volumetric shapes. In Proceedings of the IEEE conference on computer vision and pattern recognition. 1912--1920."},{"key":"e_1_3_2_2_31_1","doi-asserted-by":"publisher","DOI":"10.1109\/CVPR.2019.00935"},{"key":"e_1_3_2_2_32_1","doi-asserted-by":"publisher","DOI":"10.1109\/CVPR.2019.00426"},{"key":"e_1_3_2_2_33_1","volume-title":"Adversarial attack and defense on point sets. arXiv preprint arXiv:1902.10899","author":"Yang Jiancheng","year":"2019","unstructured":"Jiancheng Yang , Qiang Zhang , Rongyao Fang , Bingbing Ni , Jinxian Liu , and Qi Tian . 2019. Adversarial attack and defense on point sets. arXiv preprint arXiv:1902.10899 ( 2019 ). Jiancheng Yang, Qiang Zhang, Rongyao Fang, Bingbing Ni, Jinxian Liu, and Qi Tian. 2019. Adversarial attack and defense on point sets. arXiv preprint arXiv:1902.10899 (2019)."},{"key":"e_1_3_2_2_34_1","doi-asserted-by":"publisher","DOI":"10.1109\/CVPR.2018.00295"},{"key":"e_1_3_2_2_35_1","volume-title":"On Isometry Robustness of Deep 3D Point Cloud Models under Adversarial Attacks. arXiv preprint arXiv:2002.12222","author":"Zhao Yue","year":"2020","unstructured":"Yue Zhao , Yuwei Wu , Caihua Chen , and Andrew Lim . 2020. On Isometry Robustness of Deep 3D Point Cloud Models under Adversarial Attacks. arXiv preprint arXiv:2002.12222 ( 2020 ). Yue Zhao, Yuwei Wu, Caihua Chen, and Andrew Lim. 2020. On Isometry Robustness of Deep 3D Point Cloud Models under Adversarial Attacks. arXiv preprint arXiv:2002.12222 (2020)."},{"key":"e_1_3_2_2_36_1","doi-asserted-by":"crossref","unstructured":"Tianhang Zheng Changyou Chen Junsong Yuan Bo Li and Kui Ren. 2018. PointCloud Saliency Maps. arXiv:arXiv:1812.01687  Tianhang Zheng Changyou Chen Junsong Yuan Bo Li and Kui Ren. 2018. PointCloud Saliency Maps. arXiv:arXiv:1812.01687","DOI":"10.1109\/ICCV.2019.00168"},{"key":"e_1_3_2_2_37_1","doi-asserted-by":"publisher","DOI":"10.1109\/ICCV.2019.00205"}],"event":{"name":"MM '20: The 28th ACM International Conference on Multimedia","location":"Seattle WA USA","acronym":"MM '20","sponsor":["SIGMM ACM Special Interest Group on Multimedia"]},"container-title":["Proceedings of the 28th ACM International Conference on Multimedia"],"original-title":[],"link":[{"URL":"https:\/\/dl.acm.org\/doi\/10.1145\/3394171.3413875","content-type":"unspecified","content-version":"vor","intended-application":"text-mining"},{"URL":"https:\/\/dl.acm.org\/doi\/pdf\/10.1145\/3394171.3413875","content-type":"unspecified","content-version":"vor","intended-application":"similarity-checking"}],"deposited":{"date-parts":[[2025,6,17]],"date-time":"2025-06-17T22:01:18Z","timestamp":1750197678000},"score":1,"resource":{"primary":{"URL":"https:\/\/dl.acm.org\/doi\/10.1145\/3394171.3413875"}},"subtitle":[],"short-title":[],"issued":{"date-parts":[[2020,10,12]]},"references-count":37,"alternative-id":["10.1145\/3394171.3413875","10.1145\/3394171"],"URL":"https:\/\/doi.org\/10.1145\/3394171.3413875","relation":{},"subject":[],"published":{"date-parts":[[2020,10,12]]},"assertion":[{"value":"2020-10-12","order":2,"name":"published","label":"Published","group":{"name":"publication_history","label":"Publication History"}}]}}