Rethinking High-Frequency Forensic Signals for Poison-Splat Detection
Abstract
Poison-Splat exploits adaptive densification in 3D Gaussian Splatting (3DGS) to increase reconstruction cost through perturbed training images. Recent defenses use high-frequency patterns as forensic evidence of poisoning and report strong performance on standard benchmarks. We question whether these signals provide a reliable fingerprint of Poison-Splat when legitimate scene content itself contains texture. To investigate, we introduce TextureBench, a benchmark of ordinary, naturally occurring scenes with legitimate fine-scale texture, paired with valid clean 3DGS reconstructions and matched poisoned views. Using this benchmark, we analyze three aspects of defense reliability: detection, preservation of clean content during purification, and their interaction in composed pipelines. The RemedyGS detector's AUROC drops from 0.980 on existing benchmarks to 0.617 on TextureBench, while several high-frequency statistics reverse their clean–poisoned ordering. Purification also causes larger reconstruction losses on clean textured scenes, and false-positive detections propagate this damage through the composed defense. Finally, under the same task-specific training supervision, a detector using frozen DINOv2 features improves TextureBench AUROC to 0.904 and reduces downstream damage with the purifier held fixed, although substantial errors remain. Our results prompt re-thinking of using high frequency patterns for Poison-Splat detection. We include the code and benchmark in the submission.
Then back it, or bet against it.
Related papers
Open the market on this paper to see 7 more related papers.