Most existing adversarial attack methods for remote sensing images merely add adversarial noise or patches, which are not natural and can be easily noticed by humans. Shadow is a common natural phenomenon in remote sensing images. Generating shadow on these images can produce adversarial examples better aligning with human perception. Thus, we propose a shadow-based physical-world adversarial attack method under the black-box setting. We first construct a shadow mask dataset for remote sensing images. Then, we define the shadow perturbation generation rules that manipulate shadows’ position, area, color and shape under the constraints of physical laws (e.g., light direction, attenuation). The simulated annealing algorithm is then introduced to iteratively optimizes shadow generation parameters to maximize classifier misprediction while preserving visual coherence. Experiments demonstrate attack success rates exceeding 90% across multiple state-of-the-art classification networks, underscoring its effectiveness. This work offers new insights for evaluating and enhancing model robustness in remote sensing applications.

错误:搜索内容不能为空,请输入英文关键词
错误:关键词超出字数限制,请精简
高级检索

A Shadow-Based Adversarial Attack Approach for Remote Sensing Image Classification

  • Cheng Yang,
  • Haojie Yu,
  • Fei Ma,
  • Yuqiang Feng

摘要

Most existing adversarial attack methods for remote sensing images merely add adversarial noise or patches, which are not natural and can be easily noticed by humans. Shadow is a common natural phenomenon in remote sensing images. Generating shadow on these images can produce adversarial examples better aligning with human perception. Thus, we propose a shadow-based physical-world adversarial attack method under the black-box setting. We first construct a shadow mask dataset for remote sensing images. Then, we define the shadow perturbation generation rules that manipulate shadows’ position, area, color and shape under the constraints of physical laws (e.g., light direction, attenuation). The simulated annealing algorithm is then introduced to iteratively optimizes shadow generation parameters to maximize classifier misprediction while preserving visual coherence. Experiments demonstrate attack success rates exceeding 90% across multiple state-of-the-art classification networks, underscoring its effectiveness. This work offers new insights for evaluating and enhancing model robustness in remote sensing applications.