{"id":"https://openalex.org/W7137990765","doi":"https://doi.org/10.1609/aaai.v40i16.38377","title":"Certified L2-Norm Robustness of 3D Point Cloud Recognition in the Frequency Domain","display_name":"Certified L2-Norm Robustness of 3D Point Cloud Recognition in the Frequency Domain","publication_year":2026,"publication_date":"2026-03-14","ids":{"openalex":"https://openalex.org/W7137990765","doi":"https://doi.org/10.1609/aaai.v40i16.38377"},"language":null,"primary_location":{"id":"doi:10.1609/aaai.v40i16.38377","is_oa":true,"landing_page_url":"https://doi.org/10.1609/aaai.v40i16.38377","pdf_url":null,"source":{"id":"https://openalex.org/S4210191458","display_name":"Proceedings of the AAAI Conference on Artificial Intelligence","issn_l":"2159-5399","issn":["2159-5399","2374-3468"],"is_oa":true,"is_in_doaj":false,"is_core":false,"host_organization":"https://openalex.org/P4310320058","host_organization_name":"Association for the Advancement of Artificial Intelligence","host_organization_lineage":["https://openalex.org/P4310320058"],"host_organization_lineage_names":["Association for the Advancement of Artificial Intelligence"],"type":"conference"},"license":null,"license_id":null,"version":"publishedVersion","is_accepted":true,"is_published":true,"raw_source_name":"Proceedings of the AAAI Conference on Artificial Intelligence","raw_type":"journal-article"},"type":"article","indexed_in":["crossref"],"open_access":{"is_oa":true,"oa_status":"diamond","oa_url":"https://doi.org/10.1609/aaai.v40i16.38377","any_repository_has_fulltext":false},"authorships":[{"author_position":"first","author":{"id":"https://openalex.org/A5129731686","display_name":"Liang Zhou","orcid":null},"institutions":[],"countries":[],"is_corresponding":true,"raw_author_name":"Liang Zhou","raw_affiliation_strings":[],"affiliations":[]},{"author_position":"middle","author":{"id":"https://openalex.org/A5129699793","display_name":"Qiming Wang","orcid":null},"institutions":[],"countries":[],"is_corresponding":false,"raw_author_name":"Qiming Wang","raw_affiliation_strings":[],"affiliations":[]},{"author_position":"last","author":{"id":"https://openalex.org/A5046826993","display_name":"Tianze Chen","orcid":"https://orcid.org/0009-0004-9016-5294"},"institutions":[],"countries":[],"is_corresponding":false,"raw_author_name":"Tianze Chen","raw_affiliation_strings":[],"affiliations":[]}],"institutions":[],"countries_distinct_count":0,"institutions_distinct_count":3,"corresponding_author_ids":["https://openalex.org/A5129731686"],"corresponding_institution_ids":[],"apc_list":null,"apc_paid":null,"fwci":0.0,"has_fulltext":false,"cited_by_count":0,"citation_normalized_percentile":{"value":0.20010701,"is_in_top_1_percent":false,"is_in_top_10_percent":false},"cited_by_percentile_year":null,"biblio":{"volume":"40","issue":"16","first_page":"13701","last_page":"13709"},"is_retracted":false,"is_paratext":false,"is_xpac":false,"primary_topic":{"id":"https://openalex.org/T11689","display_name":"Adversarial Robustness in Machine Learning","score":0.9404000043869019,"subfield":{"id":"https://openalex.org/subfields/1702","display_name":"Artificial Intelligence"},"field":{"id":"https://openalex.org/fields/17","display_name":"Computer Science"},"domain":{"id":"https://openalex.org/domains/3","display_name":"Physical Sciences"}},"topics":[{"id":"https://openalex.org/T11689","display_name":"Adversarial Robustness in Machine Learning","score":0.9404000043869019,"subfield":{"id":"https://openalex.org/subfields/1702","display_name":"Artificial Intelligence"},"field":{"id":"https://openalex.org/fields/17","display_name":"Computer Science"},"domain":{"id":"https://openalex.org/domains/3","display_name":"Physical Sciences"}},{"id":"https://openalex.org/T11512","display_name":"Anomaly Detection Techniques and Applications","score":0.006899999920278788,"subfield":{"id":"https://openalex.org/subfields/1702","display_name":"Artificial Intelligence"},"field":{"id":"https://openalex.org/fields/17","display_name":"Computer Science"},"domain":{"id":"https://openalex.org/domains/3","display_name":"Physical Sciences"}},{"id":"https://openalex.org/T10719","display_name":"3D Shape Modeling and Analysis","score":0.00559999980032444,"subfield":{"id":"https://openalex.org/subfields/2206","display_name":"Computational Mechanics"},"field":{"id":"https://openalex.org/fields/22","display_name":"Engineering"},"domain":{"id":"https://openalex.org/domains/3","display_name":"Physical Sciences"}}],"keywords":[{"id":"https://openalex.org/keywords/robustness","display_name":"Robustness (evolution)","score":0.7466999888420105},{"id":"https://openalex.org/keywords/point-cloud","display_name":"Point cloud","score":0.6686999797821045},{"id":"https://openalex.org/keywords/cloud-computing","display_name":"Cloud computing","score":0.5950999855995178},{"id":"https://openalex.org/keywords/frequency-domain","display_name":"Frequency domain","score":0.4717000126838684},{"id":"https://openalex.org/keywords/certification","display_name":"Certification","score":0.430400013923645},{"id":"https://openalex.org/keywords/fourier-transform","display_name":"Fourier transform","score":0.33719998598098755}],"concepts":[{"id":"https://openalex.org/C63479239","wikidata":"https://www.wikidata.org/wiki/Q7353546","display_name":"Robustness (evolution)","level":3,"score":0.7466999888420105},{"id":"https://openalex.org/C131979681","wikidata":"https://www.wikidata.org/wiki/Q1899648","display_name":"Point cloud","level":2,"score":0.6686999797821045},{"id":"https://openalex.org/C79974875","wikidata":"https://www.wikidata.org/wiki/Q483639","display_name":"Cloud computing","level":2,"score":0.5950999855995178},{"id":"https://openalex.org/C41008148","wikidata":"https://www.wikidata.org/wiki/Q21198","display_name":"Computer science","level":0,"score":0.5286999940872192},{"id":"https://openalex.org/C19118579","wikidata":"https://www.wikidata.org/wiki/Q786423","display_name":"Frequency domain","level":2,"score":0.4717000126838684},{"id":"https://openalex.org/C46304622","wikidata":"https://www.wikidata.org/wiki/Q374814","display_name":"Certification","level":2,"score":0.430400013923645},{"id":"https://openalex.org/C11413529","wikidata":"https://www.wikidata.org/wiki/Q8366","display_name":"Algorithm","level":1,"score":0.3734999895095825},{"id":"https://openalex.org/C124101348","wikidata":"https://www.wikidata.org/wiki/Q172491","display_name":"Data mining","level":1,"score":0.3634999990463257},{"id":"https://openalex.org/C102519508","wikidata":"https://www.wikidata.org/wiki/Q6520159","display_name":"Fourier transform","level":2,"score":0.33719998598098755},{"id":"https://openalex.org/C154945302","wikidata":"https://www.wikidata.org/wiki/Q11660","display_name":"Artificial intelligence","level":1,"score":0.29100000858306885},{"id":"https://openalex.org/C33923547","wikidata":"https://www.wikidata.org/wiki/Q395","display_name":"Mathematics","level":0,"score":0.2903999984264374},{"id":"https://openalex.org/C103824480","wikidata":"https://www.wikidata.org/wiki/Q185889","display_name":"Time domain","level":2,"score":0.27239999175071716},{"id":"https://openalex.org/C36503486","wikidata":"https://www.wikidata.org/wiki/Q11235244","display_name":"Domain (mathematical analysis)","level":2,"score":0.2712000012397766},{"id":"https://openalex.org/C28719098","wikidata":"https://www.wikidata.org/wiki/Q44946","display_name":"Point (geometry)","level":2,"score":0.26759999990463257},{"id":"https://openalex.org/C80444323","wikidata":"https://www.wikidata.org/wiki/Q2878974","display_name":"Theoretical computer science","level":1,"score":0.2596000134944916}],"mesh":[],"locations_count":1,"locations":[{"id":"doi:10.1609/aaai.v40i16.38377","is_oa":true,"landing_page_url":"https://doi.org/10.1609/aaai.v40i16.38377","pdf_url":null,"source":{"id":"https://openalex.org/S4210191458","display_name":"Proceedings of the AAAI Conference on Artificial Intelligence","issn_l":"2159-5399","issn":["2159-5399","2374-3468"],"is_oa":true,"is_in_doaj":false,"is_core":false,"host_organization":"https://openalex.org/P4310320058","host_organization_name":"Association for the Advancement of Artificial Intelligence","host_organization_lineage":["https://openalex.org/P4310320058"],"host_organization_lineage_names":["Association for the Advancement of Artificial Intelligence"],"type":"conference"},"license":null,"license_id":null,"version":"publishedVersion","is_accepted":true,"is_published":true,"raw_source_name":"Proceedings of the AAAI Conference on Artificial Intelligence","raw_type":"journal-article"}],"best_oa_location":{"id":"doi:10.1609/aaai.v40i16.38377","is_oa":true,"landing_page_url":"https://doi.org/10.1609/aaai.v40i16.38377","pdf_url":null,"source":{"id":"https://openalex.org/S4210191458","display_name":"Proceedings of the AAAI Conference on Artificial Intelligence","issn_l":"2159-5399","issn":["2159-5399","2374-3468"],"is_oa":true,"is_in_doaj":false,"is_core":false,"host_organization":"https://openalex.org/P4310320058","host_organization_name":"Association for the Advancement of Artificial Intelligence","host_organization_lineage":["https://openalex.org/P4310320058"],"host_organization_lineage_names":["Association for the Advancement of Artificial Intelligence"],"type":"conference"},"license":null,"license_id":null,"version":"publishedVersion","is_accepted":true,"is_published":true,"raw_source_name":"Proceedings of the AAAI Conference on Artificial Intelligence","raw_type":"journal-article"},"sustainable_development_goals":[{"id":"https://metadata.un.org/sdg/16","score":0.8076063394546509,"display_name":"Peace, Justice and strong institutions"}],"awards":[],"funders":[],"has_content":{"pdf":false,"grobid_xml":false},"content_urls":null,"referenced_works_count":0,"referenced_works":[],"related_works":[],"abstract_inverted_index":{"3D":[0,234],"point":[1,24,105,235],"cloud":[2,25,106,236],"classification":[3],"is":[4,125,136],"a":[5,74,129,171,191],"fundamental":[6],"task":[7],"in":[8,41,233],"safety-critical":[9,42],"applications":[10],"such":[11],"as":[12],"autonomous":[13],"driving,":[14],"robotics,":[15],"and":[16,33,132,161,181,187,203,214],"augmented":[17],"reality.":[18],"However,":[19],"recent":[20],"studies":[21],"reveal":[22],"that":[23,55,78,207,223],"classifiers":[26],"are":[27,143],"vulnerable":[28],"to":[29,38,66,89,118],"structured":[30,94,115],"adversarial":[31],"perturbations":[32,49,160],"geometric":[34,53],"corruptions,":[35],"posing":[36],"risks":[37],"their":[39],"deployment":[40],"scenarios.":[43],"Existing":[44],"certified":[45,177,212],"defenses":[46,84],"limit":[47],"point-wise":[48],"but":[50],"overlook":[51],"subtle":[52],"distortions":[54],"preserve":[56],"individual":[57],"points":[58],"yet":[59],"alter":[60],"the":[61,90,103,108,133,154,165,176,201],"overall":[62],"structure,":[63],"potentially":[64],"leading":[65],"misclassification.":[67],"In":[68],"this":[69],"work,":[70],"we":[71],"propose":[72],"FreqCert,":[73],"novel":[75],"certification":[76,95],"framework":[77],"departs":[79],"from":[80],"conventional":[81],"spatial":[82,151],"domain":[83,196],"by":[85,128],"shifting":[86],"robustness":[87,179,232],"analysis":[88],"frequency":[91,195],"domain,":[92],"enabling":[93],"against":[96],"global":[97],"l2-bounded":[98],"perturbations.":[99,219],"FreqCert":[100,208],"first":[101],"transforms":[102],"input":[104],"via":[107],"graph":[109],"Fourier":[110],"transform":[111],"(GFT),":[112],"then":[113],"applies":[114],"frequency-aware":[116],"subsampling":[117],"generate":[119],"multiple":[120],"sub-point":[121],"clouds.":[122],"Each":[123],"sub-cloud":[124],"independently":[126],"classified":[127],"standard":[130],"model,":[131],"final":[134],"prediction":[135],"obtained":[137],"through":[138],"majority":[139],"voting,":[140],"where":[141],"sub-clouds":[142],"constructed":[144],"based":[145],"on":[146,175,200],"spectral":[147,224],"similarity":[148],"rather":[149],"than":[150],"proximity,":[152],"making":[153],"partitioning":[155],"more":[156],"stable":[157],"under":[158,185,217],"l2":[159,178],"better":[162],"aligned":[163],"with":[164],"object\u2019s":[166],"intrinsic":[167],"structure.":[168],"We":[169],"derive":[170],"closed-form":[172],"lower":[173],"bound":[174],"radius":[180],"prove":[182],"its":[183],"tightness":[184],"minimal":[186],"interpretable":[188],"assumptions,":[189],"establishing":[190],"theoretical":[192],"foundation":[193],"for":[194],"certification.":[197],"Extensive":[198],"experiments":[199],"ModelNet40":[202],"ScanObjectNN":[204],"datasets":[205],"demonstrate":[206],"consistently":[209],"achieves":[210],"higher":[211],"accuracy":[213,216],"empirical":[215],"strong":[218],"Our":[220],"results":[221],"suggest":[222],"representations":[225],"provide":[226],"an":[227],"effective":[228],"pathway":[229],"toward":[230],"certifiable":[231],"recognition.":[237]},"counts_by_year":[],"updated_date":"2026-03-18T06:31:55.123368","created_date":"2026-03-18T00:00:00"}
