Our new X account is live! Follow @wizwand_team for updates
WorkDL logo mark

RemedyGS: Defend 3D Gaussian Splatting against Computation Cost Attacks

About

As a mainstream technique for 3D reconstruction, 3D Gaussian splatting (3DGS) has been applied in a wide range of applications and services. Recent studies have revealed critical vulnerabilities in this pipeline and introduced computation cost attacks that lead to malicious resource occupancies and even denial-of-service (DoS) conditions, thereby hindering the reliable deployment of 3DGS. In this paper, we propose the first effective and comprehensive black-box defense framework, named RemedyGS, against such computation cost attacks, safeguarding 3DGS reconstruction systems and services. Our pipeline comprises two key components: a detector to identify the attacked input images with poisoned textures and a purifier to recover the benign images from their attacked counterparts, mitigating the adverse effects of these attacks. Moreover, we incorporate adversarial training into the purifier to enforce distributional alignment between the recovered and original natural images, thereby enhancing the defense efficacy. Experimental results demonstrate that our framework effectively defends against white-box, black-box, and adaptive attacks in 3DGS systems, achieving state-of-the-art performance in both safety and utility.

Yanping Li, Zhening Liu, Zijian Li, Zehong Lin, Jun Zhang• 2025

Related benchmarks

TaskDatasetResultRank
3D Scene ReconstructionMip-NeRF360
Training Time (min)18.63
37
3D Scene ReconstructionTanks&Temples
Training Time (min)10.07
25
3D Scene ReconstructionNeRF Synthetic
Training Time (min)9.48
25
3D ReconstructionMip-NeRF 360 (test)
PSNR27.31
24
Neural Scene ReconstructionNeRF Synthetic
PSNR34.295
18
3D ReconstructionTanks&Temples (test)
PSNR24.073
15
Novel View SynthesisMip-NeRF360 (room)
PSNR31.311
13
3D ReconstructionNeRF-Synthetic (NS) standard (test)
PSNR33.07
11
Novel View Synthesis Efficiency DefenseNeRF-Synthetic NS-ficus standard (test)
Peak GPU Memory (MB)4.00e+3
9
Novel View Synthesis Efficiency DefenseNeRF-Synthetic NS-chair standard (test)
Peak GPU Memory (MB)4.80e+3
9
Showing 10 of 15 rows

Other info

Follow for update