arXiv:2509.07495cs.CVcs.AI2025-09被引 1

通过局部混合与对数优化,提升遥感目标识别的攻击迁移性。

Generating Transferrable Adversarial Examples via Local Mixing and Logits Optimization for Remote Sensing Object Recognition

  • 局部区域混合保留全局语义,避免图像结构破坏。
  • 采用对数损失缓解梯度消失,提升对抗样本质量。
  • 适合研究遥感图像安全与模型鲁棒性的研究人员。

深度神经网络在遥感应用中易受对抗攻击威胁。现有基于混合的方法或进行全局融合,或直接替换图像区域,可能破坏全局语义特征并误导对抗样本优化。此外,其依赖交叉熵损失导致迭代更新中梯度衰减,影响对抗样本质量。为此,本文针对非目标攻击,提出一种基于局部混合与对数优化的新框架。首先,设计局部混合策略生成多样且语义一致的输入;不同于全局混合的MixUp和拼接式的MixCut,本方法仅混合局部区域以保持全局结构。其次,将目标攻击中的对数损失适配至非目标场景,缓解交叉熵损失的梯度消失问题。第三,引入扰动平滑损失抑制高频噪声,增强迁移性。在FGSCR-42和MTARSI数据集上的实验表明,本方法优于12种前沿方法,在6个代理模型上表现优异。尤其在MTARSI上以ResNet为代理模型时,黑盒攻击成功率平均提升17.28%。

原文摘要 · Abstract (English)

Deep Neural Networks (DNNs) are vulnerable to adversarial attacks, posing significant security threats to their deployment in remote sensing applications. Research on adversarial attacks not only reveals model vulnerabilities but also provides critical insights for enhancing robustness. Although current mixing-based strategies have been proposed to increase the transferability of adversarial examples, they either perform global blending or directly exchange a region in the images, which may destroy global semantic features and mislead the optimization of adversarial examples. Furthermore, their reliance on cross-entropy loss for perturbation optimization leads to gradient diminishing during iterative updates, compromising adversarial example quality. To address these limitations, we focus on non-targeted attacks and propose a novel framework via local mixing and logits optimization. First, we present a local mixing strategy to generate diverse yet semantically consistent inputs. Different from MixUp, which globally blends two images, and MixCut, which stitches images together, our method merely blends local regions to preserve global semantic information. Second, we adapt the logit loss from targeted attacks to non-targeted scenarios, mitigating the gradient vanishing problem of cross-entropy loss. Third, a perturbation smoothing loss is applied to suppress high-frequency noise and enhance transferability. Extensive experiments on FGSCR-42 and MTARSI datasets demonstrate superior performance over 12 state-of-the-art methods across 6 surrogate models. Notably, with ResNet as the surrogate on MTARSI, our method achieves a 17.28% average improvement in black-box attack success rate.

对抗攻击遥感图像迁移性

Thank you to arXiv for use of its open access interoperability. PaperDance 不是 arXiv 官方产品;中文卡片由大模型生成,请以原文为准。