Less Adaptation, More Transfer: Spectral View Randomization for 3D Point Cloud Transfer Attacks
Yang Gao, Jingyi Liu, Hongjia Liu, Hui Li, Jian Xu
Point cloud perception is important in autonomous driving, robotics, and other security-critical 3D systems, yet learned point cloud classifiers remain vulnerable to transferable adversarial perturbations. A central difficulty in transfer-based black-box attacks is surrogate overfitting: an update that is highly effective on an accessible source model may not generalize to an unknown target architecture. We introduce SpecEOT, a source-agnostic and graph-spectral expectation-over-transformation attack. A fixed graph Fourier transform (GFT) basis is constructed from each clean point cloud. At every optimization iteration, each non-identity view independently samples a frequency band and a perturbation sign from uniform distributions; the resulting view gradients are averaged with equal weights and used to update the adversarial point cloud through projected Adam ascent. We evaluate the stochastic method over repeated seeds, extend the ablation to two source architectures, and analyze the interaction between band count and randomization strength while reporting computational cost and assessing robustness to Gaussian jitter and point dropout. SpecEOT achieves strong transferability on ModelNet40 and ShapeNet.