期刊文献+

多源遥感影像深度识别模型对抗攻击鲁棒性评估 被引量:1

Adversarial robustness evaluation of multiple-source remote sensing image recognition based on deep neural networks
原文传递
导出
摘要 基于深度神经网络的多源遥感影像目标识别系统已逐步在空天遥感情报侦察、无人作战自主环境认知、多模复合末制导等多个军事场景中广泛应用。然而,由于深度学习理论上的不完备性、深度神经网络结构设计工程上的强复用性、以及多源成像识别系统在复杂电磁环境中易受到各类干扰等多因素的影响,使得现有识别系统在对抗攻击鲁棒性方面评估不足,存在极大安全隐患。本文首先从深度学习理论不完备性和识别系统攻击样式两个方面分析了潜在安全风险,并重点介绍了深度识别模型对抗样本攻击基本原理和典型方法。其次,针对光学遥感影像和SAR遥感影像两类典型数据形式,从鲁棒正确识别率和对抗攻击可解释性两个方面开展多源遥感影像深度识别模型对抗攻击鲁棒性评估,覆盖了9类常见深度识别网络架构和7类典型对抗样本攻击方法,验证了现有深度识别模型对抗攻击鲁棒性普遍不足的问题,分析了对抗样本与正常样本的多隐层特征激活差异,为下一步设计对抗样本检测算法和提升模型对抗鲁棒性提供参考。 Deep-neural-network-based multiple-source remote sensing image recognition systems have been widely used in many military scenarios,such as in aerospace intelligence reconnaissance,unmanned aerial vehicles for autonomous environmental cognition,and multimode automatic target recognition systems.Deep learning models rely on the assumption that the training and testing data are from the same distribution.However,these models show poor performance under common corruption or adversarial attacks.In the remote sensing community,the adversarial robustness of deep-neural-network-based recognition models have not received much attention,thence increasing the risk for many security-sensitive applications.This article evaluates the adversarial robustness of deep-neural-network-based recognition models for multiple-source remote sensing images.First,we discuss the incompleteness of deep learning theory and reveal the presence of great security risks.The independent identical distribution assumption is often violated,and the system performance cannot be guaranteed under adversarial scenarios.The whole process chain of a deep-neural-network-based image recognition system is then analyzed for its vulnerabilities.Second,we introduce several representative algorithms for adversarial example generation under both the white-and black-box settings.The gradient-propagation-based visualization method is also proposed for analyzing adversarial attacks.We perform a detailed evaluation of nine deep neural networks across two publicly available remote sensing image datasets.Both optical remote sensing and SAR remote sensing images are used in our experiments.For each model,we generate seven perturbations,ranging from gradient-based optimization to unsupervised feature distortion,for each testing image.In all cases,we observe a significant reduction in average classification accuracy between the original clean data and their adversarial images.Apart from adversarial average recognition accuracy,feature attribution techniques have also been adopted to analyze the feature diffusion effect of adversarial attacks,hence contributing to the present understanding of the vulnerability of deep learning models.Experimental results demonstrate that all deep neural networks have suffered great losses in classification accuracy when the testing images are adversarial examples.Understanding such adversarial phenomena improves our understanding of the inner workings of deep learning models.Additional efforts are needed to enhance the adversarial robustness of deep learning models.
作者 孙浩 徐延杰 陈进 雷琳 计科峰 匡纲要 SUN Hao;XU Yanjie;CHEN Jin;LEI Lin;JI Kefeng;KUANG Gangyao(College of Electronic Science,National University of Defense Technology,Changsha 410073,China;Beijing Institute of Remote Sensing Information,Beijing 100192,China)
出处 《遥感学报》 EI CSCD 北大核心 2023年第8期1951-1963,共13页 NATIONAL REMOTE SENSING BULLETIN
基金 国家自然科学基金(编号:61971426)。
关键词 多源遥感影像目标识别 深度神经网络 对抗攻击 特征可视化 对抗鲁棒性评估 multiple source remote sensing images deep neural networks adversarial attack feature visualization adversarial robustness evaluation
  • 相关文献

参考文献2

二级参考文献26

  • 1Action Outline on Promoting the Development of Big Data ( [ 2015 ] 50). 2015.the State Council. the People's Republic of China.
  • 2中华人民共和国国务院《关于印发促进夫数据发展行动纲要的通知》.2015.国发[2015]50号.
  • 3Decision on Speeding up the Cultivation and Development of Strategic Emerging Industries ( [ 2010 ]32).2010. the State Council, the People's Republic of China.
  • 4中华人民处和同国务院《天于加快培育和发展战略性新兴产业的决定》.2010.国发[2010]32号).
  • 5Guidance on Innovation Investment and Financing Mechanisms in Key Areas to Encourage Social Investment ( [2014 ] 60).2014.the State Council, the People's Republic of China.
  • 6中华人民共和国国务院《创新重点领域投融资机制鼓励社会投资的指导意见》.2014国发[2014]60号).
  • 7National Strategic Emerging Industry Development Plan in 12^th Five- Year ( [ 2012 ] 28). 2012. the State Council, the People's Repub- lic of China.
  • 8中华人民共和国国务院《关于印发“十二五”国家战略性新兴产业发展规划的通知》.2012.国发[2012]28号).
  • 9Opinions on Promoting Information Consumption to expand Domestic Demand ([ 2013 ] 32).2013. the State Council, the People's Re-publicofChina.
  • 10中华人民共和国国务院《关于促进信息消费扩大内需的若干意见》2013.国发[2013]32号.

共引文献85

同被引文献4

引证文献1

相关作者

内容加载中请稍等...

相关机构

内容加载中请稍等...

相关主题

内容加载中请稍等...

浏览历史

内容加载中请稍等...
;
使用帮助 返回顶部