BadPVD: Backdoor Attacks on Point-Voxel Diffusion Models
Abstract
Diffusion models have demonstrated strong capabilities in synthesizing high fidelity and diverse data distributions, and diffusion based 3D point cloud generation methods have also achieved impressive generation performance. However, despite their strong generative ability, the security risks of these models remain largely unexplored, especially under backdoor attacks. Attackers can implant hidden backdoors into 3D point cloud diffusion models, causing the model to behave normally under benign inputs while generating attacker specified target objects once a trigger is introduced. In this paper, we investigate the vulnerability of point-voxel diffusion models to backdoor attacks and propose a noise driven backdoor injection method. By manipulating the noise generation and denoising trajectory, the model learns to associate trigger signals with attacker defined target shapes. Under trigger-conditioned initialization, the implanted backdoor can be activated while remaining inactive under the reported benign settings. Experiments under the evaluated settings demonstrate targeted generation while retaining generation capability with limited degradation on the reported metrics. These results suggest that backdoor security should be considered when deploying or reusing diffusion based 3D point cloud generation models.
est. 32% chance this paper gets accepted at ICLR 2027.
What do you think this paper will get?
All positions stay anonymous.