Skip to content
Book Open access

GaussTrap: Stealthy Backdoor Attacks on 3D Gaussian Splatting for Targeted Scene Misperception

Aug 2026 · Proceedings of the 32nd ACM SIGKDD Conference on Knowledge Discovery and Data Mining V.2 · 1 citation · 58 references

Abstract

3D Gaussian Splatting (3DGS) has recently emerged as a powerful paradigm for real-time scene representation and novel view synthesis, gaining traction in safety-critical applications such as autonomous driving and AR/VR systems. However, the security vulnerabilities of 3DGS remain largely unexplored. In this paper, we conduct a comprehensive study of backdoor threats in 3DGS pipelines. We uncover an inherent security vulnerability in the adaptive density control mechanism of 3DGS—originally designed for detailed reconstruction—which enables attackers to induce localized gaussian proliferation, effectively embedding malicious backdoors into the scene geometry while remaining invisible from other viewpoints. To expose this threat, we propose GaussTrap, a novel stealthy poisoning framework tailored for 3DGS. GaussTrap operates in three stages---adversarial injection, geometric stabilization, and global fidelity restoration ---to embed imperceptible yet adversarial Gaussian components into the reconstruction. It ensures consistent poisoning effects at specific viewpoints while preserving photorealism in benign views, thereby achieving high attack efficacy with low detectability. Extensive experiments on both synthetic and real-world benchmarks demonstrate that GaussTrap reliably induces targeted visual corruption under trigger conditions while maintaining high rendering fidelity elsewhere, highlighting a critical security blind spot in modern 3D rendering systems. The code is available at https://github.com/acang425/GaussTrap.

Read PDF

We use cookies to run the site and, with your consent, for analytics and to show ads. See our Cookie Policy.