DeMPAA: Deployable Multi-Mini-Patch Adversarial Attack for Remote Sensing Image Classification

Jun-Jie Huang,Ziyue Wang,Tianrui Liu,Wenhan Luo,Zihan Chen,Wentao Zhao,Meng Wang
DOI: https://doi.org/10.1109/tgrs.2024.3397354
IF: 8.2
2024-05-25
IEEE Transactions on Geoscience and Remote Sensing
Abstract:Deep neural networks (DNNs) have demonstrated excellent performance in image classification, yet remain vulnerable to adversarial attacks. Generating deployable adversarial patches (AdvPatchs) represents a promising approach to safeguard critical facilities against DNN-based classifiers used for remote sensing images (RSIs). While existing AdvPatch attack methods are designed for natural images, they typically generate a single and large patch which is impractically oversize for RSI applications. In this article, we propose a deployable multi-mini-patch adversarial attack (DeMPAA) method for RSI classification task, which deploys multiple small AdvPatchs on key locations considering both the feasibility and the effectiveness. The proposed DeMPAA method formulates the problem as a constrained optimization problem that jointly optimizes patch locations and AdvPatchs. The proposed DeMPAA method takes a searching and optimization strategy to tackle it. The DeMPAA framework consists of a feasible and effective map generation (FEMG) module and a patch generation (PG) module. The FEMG module generates a location map to guide the AdvPatch location sampling by excluding the infeasible locations and considering the location effectiveness. In the PG module, a probability-guided random sampling (PRSamp)-based patch location selection method is used to search better locations, and then we optimize the AdvPatchs using gradient descent with respect to an adversarial classification (AdvC) loss and an imperceptibility loss. Extensive experimental results conducted on aerial image dataset (AID) show that the proposed DeMPAA method achieves 94.80% attacking success rate (ASR) against ResNet50 using 16 small patches, which significantly outperforms other AdvPatch methods.
imaging science & photographic technology,remote sensing,engineering, electrical & electronic,geochemistry & geophysics
What problem does this paper attempt to address?