Adversarial attack resistance in next-best-view prediction using spherical harmonics

Konferenz: ISR Europe 2023 - 56th International Symposium on Robotics
26.09.2023-27.09.2023 in Stuttgart, Germany

Tagungsband: ISR Europe 2023

Seiten: 7Sprache: EnglischTyp: PDF

Autoren:
Pop, Alexandru; Tamas, Levente

Inhalt:
The next-best-view(NBV) generation problem is relevant in a number of research fields including robotics path planning, computer vision bundle adjustment and reconstruction, as well as in real-life applications such as 3D volumetric estimation. On the other hand, the next-best-view estimation is vulnerable to a number of perturbances, thus the evaluation of these methods from the robustness perspective is essential. In this paper, we present a defense for an adversarial attack performed on a next-best view predicting network, which is able to alternate the 3D point-cloud data in a barely visible manner and corrupt the NBV estimation. The defense mechanism implies a preprocessing of the input data using spherical harmonics. The adversarial attack manages to change the estimation of the unprotected network for the majority of the validation dataset, but the same attack is unsuccessful for the network with our preprocessing. The tests were performed solely on a synthetic dataset.