用真实雾霾结构生成对抗样本,提升遥感图像分类的攻击效果与隐蔽性。
Physically-Induced Atmospheric Adversarial Perturbations: Enhancing Transferability and Robustness in Remote Sensing Image Classification

- 基于珀林噪声迭代优化大气模式,生成类雾对抗扰动。
- 黑盒迁移成功率达83.74%,对压缩滤波等防御手段鲁棒。
- 适合研究遥感模型安全性的研究人员参考。
对抗攻击严重威胁遥感图像分类中深度学习模型的可靠性。现有方法多依赖像素级扰动,未能利用遥感图像固有的大气特性,也难以应对真实世界的图像退化。本文提出FogFool,一种物理上合理的对抗框架,通过基于珀林噪声迭代优化大气模式,生成基于雾的扰动。该方法模拟自然不规则的雾形成过程,生成的对抗样本在视觉上与真实的遥感场景一致且具有欺骗性。凭借大气现象的空间一致性与中低频特性,FogFool将对抗信息嵌入跨架构共享的结构特征中。在两个基准遥感数据集上的实验表明,FogFool不仅在白盒设置下表现优异,更展现出卓越的黑盒迁移能力(达到83.74% TASR),并能有效抵御JPEG压缩、滤波等常见预处理防御。详细分析包括混淆矩阵与类别激活图(CAM)可视化,揭示了大气驱动扰动引发模型注意力的普遍转移。结果表明,FogFool代表了一种实际、隐蔽且持久的遥感分类系统威胁,为复杂环境下的模型可靠性评估提供了坚实基准。
原文摘要 · Abstract (English)
Adversarial attacks pose a severe threat to the reliability of deep learning models in remote sensing (RS) image classification. Most existing methods rely on direct pixel-wise perturbations, failing to exploit the inherent atmospheric characteristics of RS imagery or survive real-world image degradations. In this paper, we propose FogFool, a physically plausible adversarial framework that generates fog-based perturbations by iteratively optimizing atmospheric patterns based on Perlin noise. By modeling fog formations with natural, irregular structures, FogFool generates adversarial examples that are not only visually consistent with authentic RS scenes but also deceptive. By leveraging the spatial coherence and mid-to-low-frequency nature of atmospheric phenomena, FogFool embeds adversarial information into structural features shared across diverse architectures. Extensive experiments on two benchmark RS datasets demonstrate that FogFool achieves superior performance: not only does it exceed in white-box settings, but also exhibits exceptional black-box transferability (reaching 83.74% TASR) and robustness against common preprocessing-based defenses such as JPEG compression and filtering. Detailed analyses, including confusion matrices and Class Activation Map (CAM) visualizations, reveal that our atmospheric-driven perturbations induce a universal shift in model attention. These results indicate that FogFool represents a practical, stealthy, and highly persistent threat to RS classification systems, providing a robust benchmark for evaluating model reliability in complex environments.
Thank you to arXiv for use of its open access interoperability. PaperDance 不是 arXiv 官方产品;中文卡片由大模型生成,请以原文为准。