Characterizing Detectability in 3DGS Poisoning: A Stage-wise Benchmark
Abstract
3D Gaussian Splatting (3DGS) has rapidly emerged as a leading representation for real-time novel view synthesis, but recent work has shown that it is vulnerable to diverse poisoning attacks, including illusory object injection, computation cost amplification, and post hoc model watermarking. Despite this expanding threat surface, existing studies primarily focus on attack success, while defense and detection remain underexplored. From a detection perspective, a key challenge and opportunity arise from the multi-stage nature of the 3DGS reconstruction pipeline, which produces heterogeneous intermediate representations. Importantly, forensic signals for detecting poisoning are inherently stage dependent: an attack introduced at one stage may produce signals that emerge only at later stages or become more detectable as the pipeline progresses. This motivates a \em stage-wise view of detectability that goes beyond single-stage evaluation. In this work, we introduce Poison-3DGS, a benchmark designed for stage-wise characterization of poisoning detection in 3DGS, comprising 100 diverse base scenes and 1,253 poisoned variants. Moving beyond attack-specific evaluation, Poison-3DGS systematically exposes the stage-specific representations naturally produced throughout the standard 3DGS reconstruction pipeline, including multi-view images, SfM-derived geometry, training dynamics, and the final Gaussian representation. This representation-centric design enables an attack-agnostic, stage-wise evaluation protocol that naturally accommodates existing and future poisoning attacks. Using this benchmark, we conduct the first systematic study of poisoning detectability across the 3DGS reconstruction pipeline. Our study reveals that the stage where an attack is introduced is not necessarily the stage where it is most detectable. Instead, downstream reconstruction transforms attack effects into stage-specific forensic signals whose detectability varies substantially across stages and attack types. Overall, Poison-3DGS provides a principled benchmark and the first systematic characterization of stage-dependent detectability in 3DGS, establishing a foundation for future research on robust and reliable 3DGS systems. We include the code and benchmark in the submission.
est. 32% chance this paper gets accepted at ICLR 2027.
What do you think this paper will get?
All positions stay anonymous.