Universal Adversarial Examples in Remote Sensing: Methodology and Benchmark

被引:52
|
作者
Xu, Yonghao [1 ]
Ghamisi, Pedram [1 ,2 ]
机构
[1] Inst Adv Res Artificial Intelligence IARAI, A-1030 Vienna, Austria
[2] Helmholtz Zenuum Dresden Rossendorf, Machine Learning Grp, Helmholtz Inst Freiberg Resource Technol, D-09599 Freiberg, Germany
关键词
Remote sensing; Neural networks; Deep learning; Perturbation methods; Task analysis; Forestry; Optimization; Adversarial attack; adversarial example; remote sensing; scene classification; semantic segmentation; DATA FUSION; ATTACKS;
D O I
10.1109/TGRS.2022.3156392
中图分类号
P3 [地球物理学]; P59 [地球化学];
学科分类号
0708 ; 070902 ;
摘要
Deep neural networks have achieved great success in many important remote sensing tasks. Nevertheless, their vulnerability to adversarial examples should not be neglected. In this study, we systematically analyze the Universal Adversarial Examples in Remote Sensing (UAE-RS) data for the first time, without any knowledge from the victim model. Specifically, we propose a novel black-box adversarial attack method, namely, Mixup-Attack, and its simple variant Mixcut-Attack, for remote sensing data. The key idea of the proposed methods is to find common vulnerabilities among different networks by attacking the features in the shallow layer of a given surrogate model. Despite their simplicity, the proposed methods can generate transferable adversarial examples that deceive most of the state-of-the-art deep neural networks in both scene classification and semantic segmentation tasks with high success rates. We further provide the generated universal adversarial examples in the dataset named UAE-RS, which is the first dataset that provides black-box adversarial samples in the remote sensing field. We hope UAE-RS may serve as a benchmark that helps researchers design deep neural networks with strong resistance toward adversarial attacks in the remote sensing field. Codes and the UAE-RS dataset are available online (https://github.com/YonghaoXu/UAE-RS).
引用
下载
收藏
页数:15
相关论文
共 50 条
  • [1] Targeted Universal Adversarial Examples for Remote Sensing
    Bai, Tao
    Wang, Hao
    Wen, Bihan
    REMOTE SENSING, 2022, 14 (22)
  • [2] Adversarial Examples in Remote Sensing
    Czaja, Wojciech
    Fendley, Neil
    Pekala, Michael
    Ratto, Christopher
    Wang, I-Jeng
    26TH ACM SIGSPATIAL INTERNATIONAL CONFERENCE ON ADVANCES IN GEOGRAPHIC INFORMATION SYSTEMS (ACM SIGSPATIAL GIS 2018), 2018, : 408 - 411
  • [3] Universal adversarial perturbation for remote sensing images
    Wang, Qingyu
    Feng, Guorui
    Yin, Zhaoxia
    Luo, Bin
    2022 IEEE 24TH INTERNATIONAL WORKSHOP ON MULTIMEDIA SIGNAL PROCESSING (MMSP), 2022,
  • [4] Stealthy Adversarial Examples for Semantic Segmentation in Remote Sensing
    Bai, Tao
    Cao, Yiming
    Xu, Yonghao
    Wen, Bihan
    IEEE TRANSACTIONS ON GEOSCIENCE AND REMOTE SENSING, 2024, 62 : 1 - 17
  • [5] An Empirical Study of Adversarial Examples on Remote Sensing Image Scene Classification
    Chen, Li
    Xu, Zewei
    Li, Qi
    Peng, Jian
    Wang, Shaowen
    Li, Haifeng
    IEEE TRANSACTIONS ON GEOSCIENCE AND REMOTE SENSING, 2021, 59 (09): : 7419 - 7433
  • [6] Attack Selectivity of Adversarial Examples in Remote Sensing Image Scene Classification
    Chen, Li
    Li, Haifeng
    Zhu, Guowei
    Li, Qi
    Zhu, Jiawei
    Huang, Haozhe
    Peng, Jian
    Zhao, Lin
    IEEE ACCESS, 2020, 8 : 137477 - 137489
  • [7] Towards Universal Adversarial Examples and Defenses
    Rakin, Adnan Siraj
    Wang, Ye
    Aeron, Shuchin
    Koike-Akino, Toshiaki
    Moulin, Pierre
    Parsons, Kieran
    2021 IEEE INFORMATION THEORY WORKSHOP (ITW), 2021,
  • [8] Generating Adversarial Examples Against Remote Sensing Scene Classification via Feature Approximation
    Zhu, Rui
    Ma, Shiping
    Lian, Jiawei
    He, Linyuan
    Mei, Shaohui
    IEEE JOURNAL OF SELECTED TOPICS IN APPLIED EARTH OBSERVATIONS AND REMOTE SENSING, 2024, 17 : 10174 - 10187
  • [9] Lie to Me: A Soft Threshold Defense Method for Adversarial Examples of Remote Sensing Images
    Chen, Li
    Xiao, Jun
    Zou, Pu
    Li, Haifeng
    IEEE GEOSCIENCE AND REMOTE SENSING LETTERS, 2022, 19
  • [10] Universal adversarial examples and perturbations for quantum classifiers
    Weiyuan Gong
    Dong-Ling Deng
    National Science Review, 2022, 9 (06) : 48 - 55