• Home
  • Search
  • Toward Generalizable Physical Attacks Against Remote Sensing Building Change Detection
  • https://doi.org/10.1109/tgrs.2025.3565634Copy DOI Icon

Toward Generalizable Physical Attacks Against Remote Sensing Building Change Detection

Show More
  • Abstract
  • Literature Map
  • References
  • Similar Papers
Abstract

Deep networks have been widely used in remote sensing building change detection (BCD) and achieved good performances. However, the BCD networks are vulnerable to adversarial attacks. Previous physical adversarial attacks in remote sensing focused on image-level tasks and instance-level tasks, we propose a generalizable physical attacks (GPA) framework for the pixel-level BCD task. The GPA framework is in the joint task-instance space to generate the universal physical adversarial patch which can cheat unseen models. It involves white-box attacks and black-box attacks. To solve the problem of the singular adversarial patch position and the singular target task in existing works, we propose an adaptive adversarial patch position module and present a feature loss for bi-temporal remote sensing images in white-box attacks. To enhance the generalization of the patch, we propose a method in the joint task-instance space to learn the black-box adversarial patch. Extensive experiments on the widely used remote sensing image BCD dataset shows the proposed adversarial attacks against BCD achieve better performance compared with state-of-the-art methods. In particular, our GPA elevates <italic xmlns:mml="http://www.w3.org/1998/Math/MathML" xmlns:xlink="http://www.w3.org/1999/xlink">ASR<sub>p</sub></i> and <italic xmlns:mml="http://www.w3.org/1998/Math/MathML" xmlns:xlink="http://www.w3.org/1999/xlink">CD_Rate</i> for all buildings by an average of 29.31%, 13.92% in the white-box scenario, and 3.92%, 3.59% in the strict black-box scenario. Real-world experiments with printed patches on physical building models further demonstrate that our GPA can attack the BCD networks. The source code and associated datasets are available at https://github.com/hhhh420/adversarial patch BCD.

Similar Papers
  • Conference Article
  • Citations2

Physical Adversarial Attacks Against Deep Learning Based Channel Decoding Systems

  • Jan 01, 2020
  • 2020 IEEE Region 10 Symposium (TENSYMP)
  • Surabhi Ashok Babu +1
  • Research Article
  • Citations20

Misleading attention and classification: An adversarial attack to fool object detection models in the real world

  • Aug 17, 2022
  • Computers &amp; Security
  • Haotian Zhang +1
  • PDF
  • Research Article
  • Citations1

D-UAP: Initially Diversified Universal Adversarial Patch Generation Method

  • Jul 14, 2023
  • Electronics
  • Lei Sun +3
  • Conference Article
  • Citations98

Segment and Complete: Defending Object Detectors against Adversarial Patch Attacks with Robust Patch Detection

  • Jun 01, 2022
  • Jiang Liu +4
  • Research Article
  • Citations1

Towards Robust Physical Adversarial Attacks on UAV Object Detection: A Multi-Dimensional Feature Optimization Approach

  • Nov 17, 2025
  • Machines
  • Hailong Xi +8
  • Book Chapter
  • Citations2

Spatially Localized Perturbation GAN (SLP-GAN) for Generating Invisible Adversarial Patches

  • Jan 01, 2020
  • Yongsu Kim +5
  • PDF
  • Research Article
  • Citations8

Ally patches for spoliation of adversarial patches

  • Jun 07, 2019
  • Journal of Big Data
  • Alaa E Abdel-Hakim
  • Research Article
  • Citations5

URAdv: A Novel Framework for Generating Ultra-Robust Adversarial Patches Against UAV Object Detection

  • Feb 11, 2025
  • Mathematics
  • Hailong Xi +6
  • Conference Article
  • Citations2

Generating Adversarial Patches Using Data-Driven MultiD-WGAN

  • May 01, 2021
  • Wei Wang +7
  • Conference Article
  • Citations155

QEBA: Query-Efficient Boundary-Based Blackbox Attack

  • Jun 01, 2020
  • Huichen Li +4
  • Conference Article
  • Citations59

Adversarial patch camouflage against aerial detection

  • Sep 20, 2020
  • Richard Den Hollander +11
  • PDF
  • Research Article
  • Citations2

Physical adversarial attack in artificial intelligence of things

  • Dec 22, 2023
  • IET Communications
  • Xin Ma +4
  • Research Article
  • Citations2

FIBTNet: Building Change Detection for Remote Sensing Images Using Feature Interactive Bi-Temporal Network

  • Jan 01, 2024
  • Computers, Materials &amp; Continua
  • Jing Wang +3
  • Research Article
  • Citations66

Cosegmentation for Object-Based Building Change Detection From High-Resolution Remotely Sensed Images

  • Mar 01, 2017
  • IEEE Transactions on Geoscience and Remote Sensing
  • Pengfeng Xiao +4
  • Research Article

MTFM: Multi-Teacher Feature Matching for Cross-Dataset and Cross-Architecture Adversarial Robustness Transfer in Remote Sensing Applications

  • Dec 19, 2025
  • Remote Sensing
  • Ravi Kumar Rogannagari +1
Cactus Communications logo

Copyright 2026 Cactus Communications. All rights reserved.