提出首个反高光谱异常检测方法,让目标隐身且无需知晓探测器位置。
Anti-Hyperspectral Anomaly Detection: A First Study on Stealthy Lipschitz-Forcing Perturbations Against Unknown Detectors

- 通过新型正则化将真实异常融入背景,生成伪异常迷惑检测器。
- 设计的单个扰动信号可同时规避几乎所有基准检测器。
- 适合安全防护场景,尤其适用于探测器类型未知时的隐蔽需求。
高光谱成像技术是远程检测异常物体的最先进技术,但现有高光谱异常检测(HAD)方法会使地面设施完全暴露。本文首次提出反高光谱异常检测(AHAD)技术,使关键目标在未获探测器精确坐标/位置状态信息(CSI,如侦察机位置)的情况下仍能隐藏。所提算法适用于防御几乎所有现有数据驱动与模型驱动的基准HAD方法。不同于传统对抗攻击,需建立新理论:通过定制正则化(ARAB),将真实异常融入背景并生成伪异常,优化出能量高效的隐蔽扰动信号;该正则化在特征空间中等价于平滑拓扑增强的异常/背景结构,称为利普希茨强制扰动。针对不完善的CSI,进一步提出鲁棒性准则,用矩阵偏移失配建模不确定性,实现稳健扰动生成。大量实验表明,该方法在多种真实数据集上均具高效性与鲁棒性。值得注意的是,单一扰动信号即可同时规避几乎所有基准检测器,显著提升实用性。据我们所知,这是首篇正式的反高光谱异常检测研究。附带贡献为提出新量化指标ArmCBA,用于评估HAD方法对本扰动的鲁棒性。
原文摘要 · Abstract (English)
Hyperspectral imagery represents the best contemporary technology to remotely detect anomalous objects. Nevertheless, hyperspectral anomaly detection (HAD) technique makes ground facilities/situations completely exposed. For the first time, we develop the first anti-HAD (AHAD) technique rendering the key objects undetected, without perfect coordinate/position state information (CSI) of the detectors (e.g., reconnaissance aircraft). Our AHAD algorithm is generally applicable to defend against almost all the existing benchmark data-driven and model-driven HAD methods. AHAD is fundamentally different from conventional adversarial attacks, so novel theory is needed. We customize novel regularizers for assimilating real anomalies into the backgrounds (ARAB) and fooling the detectors with pseudo-anomalies, thereby optimizing an energy-efficient stealthy perturbation signal for AHAD. The ARAB regularization is mathematically interpretable as flattening the topology-enhanced anomaly/background structures in the feature space, hence termed Lipschitz-forcing perturbations. Considering the imperfect CSI, we further develop a robust AHAD criterion, where the uncertainty is mathematically described as matrix-shifting misalignment for statistically generating the robust perturbation. Comprehensive experiments demonstrate the effectiveness and robustness of our AHAD algorithm across diverse real-world datasets. Remarkably, our algorithm generates a single AHAD perturbation signal that can simultaneously evade almost all benchmark detectors, greatly enhancing its practicality, given that the reconnaissance detector type is usually unknown. To the best of our knowledge, this is the first formal AHAD study. As a side contribution, we propose a new quantitative performance index, ArmCBA, to evaluate the robustness of an HAD method against our AHAD signal.
Thank you to arXiv for use of its open access interoperability. PaperDance 不是 arXiv 官方产品;中文卡片由大模型生成,请以原文为准。