PANDA: Diffusion-Guided Purification and Adaptation for Robust Point Cloud Classification Against Adversarial Attack
Abstract
Deep learning models for point cloud classification are highly vulnerable to adversarial attacks, while recent advances in diffusion-based purification have shown promising defensive performance. However, existing diffusion-based purification methods harbor two fundamental limitations. First, a distributional gap arises from their training on clean-to-clean paths, which fails to generalize to the required adversarial-to-clean transition. Second, a semantic mismatch occurs because the fixed victim classifier cannot adapt to the decision boundaries of the purified data distribution. To address this, we propose PANDA, a two-stage framework that combines robust purification with classifier adaptation. For purification, we introduce PANDA-P, a novel dual-branch diffusion training strategy that simultaneously optimizes on both clean-to-clean and adversarial-to-clean paths. This unified formulation boosts the purification effectiveness while preserving fidelity. For adaptation, we design PANDA-A, a fine-tuning scheme that leverages a consistency-driven learning objective to reshape the classifier’s feature space and recalibrate a robust decision boundary for the purified data. Extensive experiments show that PANDA achieves consistently superior robustness over existing purification-based defenses on both synthetic and real-world benchmarks.