• Home
  • Search
  • Attack Selectivity of Adversarial Examples in Remote Sensing Image Scene Classification
  • Cite Icon22
  • https://doi.org/10.1109/access.2020.3011639Copy DOI Icon

Attack Selectivity of Adversarial Examples in Remote Sensing Image Scene Classification

Show More
  • Abstract
  • Highlights & Summary
  • PDF
  • Literature Map
  • References
  • Citations
  • Similar Papers
Abstract

Remote sensing image (RSI) scene classification is the foundation and important technology of ground object detection, land use management and geographic analysis. During recent years, convolutional neural networks (CNNs) have achieved significant success and are widely applied in RSI scene classification. However, crafted images that serve as adversarial examples can potentially fool CNNs with high confidence and are hard for human eyes to interpret. For the increasing security and robust requirements of RSI scene classification, the adversarial example problem poses a serious problem for the classification results derived from systems using CNN models, which has not been fully recognized by previous research. In this study, to explore the properties of adversarial examples of RSI scene classification, we create different scenarios by testing two major attack algorithms (i.e., the fast gradient sign method (FGSM) and basic iterative method (BIM)) trained on different RSI benchmark datasets to fool CNNs (i.e., InceptionV1, ResNet and a simple CNN). In the experiment, our results show that CNNs of RSI scene classification are also vulnerable to adversarial examples, and some of them have a fooling rate of over 80%. These adversarial examples are affected by the architecture of CNNs and the type of RSI dataset. InceptionV1 has a fooling rate of less than 5%, which is lower than the others. Adversarial examples generated on the UCM dataset are easier than other datasets. Importantly, we also find that the classes of adversarial examples have an attack selectivity property. Misclassifications of adversarial examples of RSIs are related to the similarity of the original classes in the CNN feature space. Attack selectivity reveals potential classes of adversarial examples and provides insights into the design of defensive algorithms in future research.

Loading PDF

Similar Papers
  • Research Article
  • Citations86

An Empirical Study of Adversarial Examples on Remote Sensing Image Scene Classification

  • Sep 01, 2021
  • IEEE Transactions on Geoscience and Remote Sensing
  • Li Chen +5
  • Research Article
  • Citations110

Perturbation-Seeking Generative Adversarial Networks: A Defense Framework for Remote Sensing Image Scene Classification

  • Jan 01, 2022
  • IEEE Transactions on Geoscience and Remote Sensing
  • Gong Cheng +4
  • PDF
  • Research Article
  • Citations3

Adversarial Defense Method Based on Latent Representation Guidance for Remote Sensing Image Scene Classification.

  • Sep 07, 2023
  • Entropy
  • Qingan Da +6
  • Research Article
  • Citations46

A Supervised Progressive Growing Generative Adversarial Network for Remote Sensing Image Scene Classification

  • Jan 01, 2022
  • IEEE Transactions on Geoscience and Remote Sensing
  • Ailong Ma +4
  • PDF
  • Research Article
  • Citations62

CLRS: Continual Learning Benchmark for Remote Sensing Image Scene Classification.

  • Feb 24, 2020
  • Sensors
  • Haifeng Li +6
  • Research Article
  • Citations214

Scale-Free Convolutional Neural Network for Remote Sensing Scene Classification

  • Sep 01, 2019
  • IEEE Transactions on Geoscience and Remote Sensing
  • Jie Xie +3
  • Research Article
  • Citations144

Domain Adaptation for Convolutional Neural Networks-Based Remote Sensing Scene Classification

  • Aug 01, 2019
  • IEEE Geoscience and Remote Sensing Letters
  • Shaoyue Song +5
  • Research Article
  • Citations21

Reconstruction-Assisted and Distance-Optimized Adversarial Training: A Defense Framework for Remote Sensing Scene Classification

  • Jan 01, 2023
  • IEEE Transactions on Geoscience and Remote Sensing
  • Yuru Su +5
  • Conference Article

Approximating JPEG 2000 wavelet representation through deep neural networks for remote sensing image scene classification

  • Oct 15, 2019
  • Akshara Preethy Byju +3
  • PDF
  • Research Article
  • Citations17

Complete Defense Framework to Protect Deep Neural Networks against Adversarial Examples

  • May 11, 2020
  • Mathematical Problems in Engineering
  • Guangling Sun +5
  • Research Article
  • Citations5

A multi-layered defense against adversarial attacks in brain tumor classification using ensemble adversarial training and feature squeezing

  • May 14, 2025
  • Scientific Reports
  • Ahmeed Yinusa +1
  • PDF
  • Research Article
  • Citations152

Convolutional neural networks: A magic bullet for gravitational-wave detection?

  • Sep 26, 2019
  • Physical Review D
  • Timothy D Gebhard +3
  • Research Article
  • Citations28

Review: The evolution of chemometrics coupled with near infrared spectroscopy for fruit quality evaluation. II. The rise of convolutional neural networks

  • May 23, 2023
  • Journal of Near Infrared Spectroscopy
  • Jeremy Walsh +4
  • PDF
  • Research Article
  • Citations15

Detection of adversarial attacks based on differences in image entropy

  • Aug 17, 2023
  • International Journal of Information Security
  • Gwonsang Ryu +1
  • Research Article
  • Citations16

A Scene Images Diversity Improvement Generative Adversarial Network for Remote Sensing Image Scene Classification

  • Dec 05, 2019
  • IEEE Geoscience and Remote Sensing Letters
  • Xin Pan +2
Cactus Communications logo

Copyright 2026 Cactus Communications. All rights reserved.