Ppca: precise perturbation and feature approximation for enhanced black-box attacks in remote sensing image classification
摘要
The emergence of adversarial examples has revealed the vulnerabilities of deep neural networks (DNNs), where carefully crafted perturbations added to the original images can lead to misclassification. The remote sensing image (RSI) scene classification is heavily based on the spatial and textural features of the images. This dependence makes it susceptible to attacks that exploit these characteristics and presents significant challenges. This study introduces a novel transferable black-box adversarial attack technique called PPCA for remote sensing images. This method generates adversarial examples by approximating input images to synthetic target classes while applying precise perturbation constraints and HV (Heat Value) perturbation control. Extensive and rigorous experiments, conducted with meticulous attention to detail on standard remote sensing classification datasets such as UC Merced and AID, demonstrate that adversarial examples generated using the PPCA method can effectively deceive various DNNs in most evaluated black-box scenarios and show improved transferability compared to baseline methods. Furthermore, it achieves competitive performance compared to existing untargeted black-box attack methods, showing notable improvements in specific black-box scenarios and demonstrating robustness against common defense mechanisms.