ValidGS: Validation-Guided Defense Against View-Dependent Poisoning in 3D Gaussian Splatting
Abstract
The rapid progress of 3D Gaussian Splatting (3DGS), characterized by its explicit representation and highly efficient rendering, has facilitated the broad adoption of realistic 3D scene reconstruction. However, current 3DGS training pipelines lack a robust validation process to separate trustworthy Gaussians, which enable clean and accurate scene modeling, from questionable Gaussians that generate target-view-specific illusions, leaving 3DGS systems exposed to view-dependent poisoning attacks. A recent work, StealthAttack, shows that attackers can subtly corrupt only a small portion of the training views, causing the resulting 3DGS models to render illusions from certain target viewpoints while largely preserving rendering quality for innocent views. To address this problem, we introduce ValidGS, a validation-guided defense method against view-dependent poisoning. Specifically, ValidGS first constructs clean reference supervision by enforcing cross-view consistency, then applies a candidate target-view validation criterion to determine when these references are trustworthy. With this validation, our approach aggregates Gaussian-level statistics from validated clean regions, excludes Gaussians that also influence suspicious areas, and safeguards only the validated clean Gaussians, while periodically pruning Gaussians that remain suspicious. Comprehensive experiments on the well-known Mip-NeRF360, Tanks & Temples, and Free datasets show that ValidGS effectively mitigates target-view illusions while preserving high reconstruction fidelity for innocent views.
Then back it, or bet against it.
Related papers
Open the market on this paper to see 7 more related papers.