arXiv:2510.01014cs.CV2025-10被引 1

针对高光谱图像抗攻击弱点,提出两种新防御方法。

Revisiting Adversarial Training under Hyperspectral Image

  • 设计新损失函数缓解对抗扰动导致的语义失真
  • 引入光谱增强提升多样性,保持空间平滑性
  • 在4个数据集上优于现有方法,适合安全敏感场景

近期研究发现,基于深度学习的高光谱图像(HSI)分类模型极易受到对抗攻击,带来重大安全风险。尽管多数方法通过优化网络结构来增强鲁棒性,但这些方案常依赖定制化设计,可扩展性差,且难以抵御强攻击。为此,本文将对抗训练(AT)引入高光谱领域。由于高光谱数据具有高维光谱特征和强波段相关性,判别信息依赖细微光谱语义与光谱-空间一致性,对对抗扰动极为敏感。实证分析表明,对抗扰动与对抗样本的非光滑性会扭曲甚至消除关键光谱语义。为此,提出两种高光谱专用的AT方法:AT-HARL利用光谱特性差异与类别分布比率设计新型损失函数,缓解语义失真;AT-RA引入光谱数据增强,提升光谱多样性同时保持空间平滑性。在四个基准高光谱数据集上的实验表明,所提方法在对抗攻击下性能优于当前最优方案。

原文摘要 · Abstract (English)

Recent studies have shown that deep learning-based hyperspectral image (HSI) classification models are highly vulnerable to adversarial attacks, posing significant security risks. Although most approaches attempt to enhance robustness by optimizing network architectures, these methods often rely on customized designs with limited scalability and struggle to defend against strong attacks. To address this issue, we introduce adversarial training (AT), one of the most effective defense strategies, into the hyperspectral domain. However, unlike conventional RGB image classification, directly applying AT to HSI classification introduces unique challenges due to the high-dimensional spectral signatures and strong inter-band correlations of hyperspectral data, where discriminative information relies on subtle spectral semantics and spectral-spatial consistency that are highly sensitive to adversarial perturbations. Through extensive empirical analyses, we observe that adversarial perturbations and the non-smooth nature of adversarial examples can distort or even eliminate important spectral semantic information. To mitigate this issue, we propose two hyperspectral-specific AT methods, termed AT-HARL and AT-RA. Specifically, AT-HARL exploits spectral characteristic differences and class distribution ratios to design a novel loss function that alleviates semantic distortion caused by adversarial perturbations. Meanwhile, AT-RA introduces spectral data augmentation to enhance spectral diversity while preserving spatial smoothness. Experiments on four benchmark HSI datasets demonstrate that the proposed methods achieve competitive performance compared with state-of-the-art approaches under adversarial attacks.

高光谱对抗训练图像安全鲁棒性

Thank you to arXiv for use of its open access interoperability. PaperDance 不是 arXiv 官方产品;中文卡片由大模型生成,请以原文为准。