Engineering PapersSearch

DOE OSTI · 3376475

3D reconstruction and neural rendering for adversarial machine learning

Abstract

While evasion attacks on computer vision systems have been widely studied, creating attacks that remain effective under significant changes in viewpoint continues to be challenging. Traditional approaches often rely on affine transformations of images, but these approaches degrade at larger perspective shifts and often produce unrealistic or ineffective perturbations. Recent methods use differentiable renderers to improve viewpoint robustness, but they typically depend on manually constructed 3D models. We introduce a semi-automated pipeline that generates physically printable and perspective-invariant adversarial patches using only a small set of 2D images. Our method integrates 3D reconstruction, neural rendering, adversarial patch optimization, and an object detection victim model into a unified workflow. We use 2D Gaussian Splatting for high fidelity mesh reconstruction and FlexPara for surface parameterization that produces texture maps suitable for patch editing. Together, these components form a fully differentiable pipeline in PyTorch3D that links texture modification to model outputs, enabling efficient optimization of patches that remain effective across many viewpoints. The complete process, from image capture to patch printing and physical evaluation, can be completed within a few hours. We demonstrate the effectiveness of the resulting patches through attacks on the YOLOv8 object detection model and discuss remaining challenges and opportunities for improving robustness and scalability.

Keep this discovery

Explore connections, maps & timelines

BibTeXRIS

Singhvi, Vivaan [ORNL] (ORCID:0009000586288221), Hutchins, Jack R [ORNL] (ORCID:0000000177618907), Sadovnik, Amir [ORNL] (ORCID:0000000190117365), Brogan, Joel [ORNL] (ORCID:0000000220697699), Bolme, David [ORNL] (ORCID:0000000338077436), Young, Steven [ORNL] (ORCID:0000000305914330). 2026-06-01. 3D reconstruction and neural rendering for adversarial machine learning. https://doi.org/10.1117/12.3094751

Cite the original work for its findings. Save a collection to share your selection of sources.