Universal Adversarial Examples in Remote Sensing: Methodology and Benchmark
arXiv:2202.07054 · doi:10.1109/TGRS.2022.3156392
Abstract
Deep neural networks have achieved great success in many important remote sensing tasks. Nevertheless, their vulnerability to adversarial examples should not be neglected. In this study, we systematically analyze the universal adversarial examples in remote sensing data for the first time, without any knowledge from the victim model. Specifically, we propose a novel black-box adversarial attack method, namely Mixup-Attack, and its simple variant Mixcut-Attack, for remote sensing data. The key idea of the proposed methods is to find common vulnerabilities among different networks by attacking the features in the shallow layer of a given surrogate model. Despite their simplicity, the proposed methods can generate transferable adversarial examples that deceive most of the state-of-the-art deep neural networks in both scene classification and semantic segmentation tasks with high success rates. We further provide the generated universal adversarial examples in the dataset named UAE-RS, which is the first dataset that provides black-box adversarial samples in the remote sensing field. We hope UAE-RS may serve as a benchmark that helps researchers to design deep neural networks with strong resistance toward adversarial attacks in the remote sensing field. Codes and the UAE-RS dataset are available online (https://github.com/YonghaoXu/UAE-RS).
References in corpus (6)
- Very Deep Convolutional Networks for Large-Scale Image Recognition
- Explaining and Harnessing Adversarial Examples
- Understanding Neural Networks Through Deep Visualization
- Delving into Transferable Adversarial Examples and Black-box Attacks
- Deep Learning for UAV-based Object Detection and Tracking: A Survey
- Adversarial Example in Remote Sensing Image Recognition
Cited by in corpus (8)
- Benchmarking Adversarial Patch Against Aerial Detection
- AI Security for Geoscience and Remote Sensing: Challenges and Future Trends
- Scattering Model Guided Adversarial Examples for SAR Target Recognition: Attack and Defense
- Txt2Img-MHN: Remote Sensing Image Generation from Text Using Modern Hopfield Networks
- CBA: Contextual Background Attack against Optical Aerial Detection in the Physical World
- Backdoor Attacks for Remote Sensing Data with Wavelet Transform
- Towards Assessing the Synthetic-to-Measured Adversarial Vulnerability of SAR ATR
- On the Adversarial Vulnerabilities of Transfer Learning in Remote Sensing