提升高光谱图像对抗样本迁移性,增强攻击鲁棒性。
Boosting Adversarial Transferability for Hyperspectral Image Classification Using 3D Structure-invariant Transformation and Weighted Intermediate Feature Divergence
- 分块3D变换保持结构不变,增加输入多样性。
- 加权中间特征差异损失提升跨模型迁移能力。
- 适合评估高光谱分类模型安全性的研究人员。
深度神经网络(DNN)在高光谱图像(HSI)分类中面临对抗攻击的安全挑战。与自然图像不同,高光谱图像具有高维丰富的光谱信息,为生成对抗样本带来新挑战。本文基于高光谱图像特性,提出一种结合3D结构不变变换与加权中间特征差异的新型方法,以增强对抗样本在高光谱图像分类中的迁移性。该方法在保持图像结构不变的前提下,将图像在空间和光谱维度上分块,并对每块应用多种变换,提升输入多样性并缓解对替代模型的过拟合。同时,设计加权中间特征差异损失,利用原始与对抗样本间中间特征的差异,通过放大原始特征图来约束扰动方向,并为不同特征通道分配不同权重,以破坏对高光谱分类影响更大的特征。大量实验表明,所提方法在三个公开高光谱数据集上生成的对抗样本表现出更强的迁移性,且在防御策略下仍保持鲁棒攻击性能。
原文摘要 · Abstract (English)
Deep Neural Networks (DNNs) are vulnerable to adversarial attacks, which pose security challenges to hyperspectral image (HSI) classification based on DNNs. Numerous adversarial attack methods have been designed in the domain of natural images. However, different from natural images, HSIs contains high-dimensional rich spectral information, which presents new challenges for generating adversarial examples. Based on the specific characteristics of HSIs, this paper proposes a novel method to enhance the transferability of the adversarial examples for HSI classification using 3D structure-invariant transformation and weighted intermediate feature divergence. While keeping the HSIs structure invariant, the proposed method divides the image into blocks in both spatial and spectral dimensions. Then, various transformations are applied on each block to increase input diversity and mitigate the overfitting to substitute models. Moreover, a weighted intermediate feature divergence loss is also designed by leveraging the differences between the intermediate features of original and adversarial examples. It constrains the perturbation direction by enlarging the feature maps of the original examples, and assigns different weights to different feature channels to destroy the features that have a greater impact on HSI classification. Extensive experiments demonstrate that the adversarial examples generated by the proposed method achieve more effective adversarial transferability on three public HSI datasets. Furthermore, the method maintains robust attack performance even under defense strategies.
Thank you to arXiv for use of its open access interoperability. PaperDance 不是 arXiv 官方产品;中文卡片由大模型生成,请以原文为准。