Deep networks have been widely used in remote sensing building change detection (BCD) and achieved good performances. However, the BCD networks are vulnerable to adversarial attacks. Previous physical adversarial attacks in remote sensing focused on image-level tasks and instance-level tasks, we propose a generalizable physical attacks (GPA) framework for the pixel-level BCD task. The GPA framework is in the joint task-instance space to generate the universal physical adversarial patch which can cheat unseen models. It involves white-box attacks and black-box attacks. To solve the problem of the singular adversarial patch position and the singular target task in existing works, we propose an adaptive adversarial patch position module and present a feature loss for bi-temporal remote sensing images in white-box attacks. To enhance the generalization of the patch, we propose a method in the joint task-instance space to learn the black-box adversarial patch. Extensive experiments on the widely used remote sensing image BCD dataset shows the proposed adversarial attacks against BCD achieve better performance compared with state-of-the-art methods. In particular, our GPA elevates <italic xmlns:mml="http://www.w3.org/1998/Math/MathML" xmlns:xlink="http://www.w3.org/1999/xlink">ASR<sub>p</sub></i> and <italic xmlns:mml="http://www.w3.org/1998/Math/MathML" xmlns:xlink="http://www.w3.org/1999/xlink">CD_Rate</i> for all buildings by an average of 29.31%, 13.92% in the white-box scenario, and 3.92%, 3.59% in the strict black-box scenario. Real-world experiments with printed patches on physical building models further demonstrate that our GPA can attack the BCD networks. The source code and associated datasets are available at https://github.com/hhhh420/adversarial patch BCD.