FFA: Foreground Feature Approximation Digitally against Remote Sensing Object Detection

Author:

Zhu Rui1ORCID,Ma Shiping2,He Linyuan2,Ge Wei3

Affiliation:

1. Graduate School, Air Force Engineering University, Xi’an 710038, China

2. Aviations Engineering College, Air Force Engineering University, Xi’an 710038, China

3. Fundamentals Department, Air Force Engineering University, Xi’an 710038, China

Abstract

In recent years, research on adversarial attack techniques for remote sensing object detection (RSOD) has made great progress. Still, most of the research nowadays is on end-to-end attacks, which mainly design adversarial perturbations based on the prediction information of the object detectors (ODs) to achieve the attack. These methods do not discover the common vulnerabilities of the ODs and, thus, the transferability is weak. Based on this, this paper proposes a foreground feature approximation (FFA) method to generate adversarial examples (AEs) that discover the common vulnerabilities of the ODs by changing the feature information carried by the image itself to implement the attack. Specifically, firstly, the high-quality predictions are filtered as attacked objects using the detector, after which a hybrid image without any target is made, and the hybrid foreground is created based on the attacked targets. The images’ shallow features are extracted using the backbone network, and the features of the input foreground are approximated towards the hybrid foreground to implement the attack. In contrast, the model predictions are used to assist in realizing the attack. In addition, we have found the effectiveness of FFA for targeted attacks, and replacing the hybrid foreground with the targeted foreground can realize targeted attacks. Extensive experiments are conducted on the remote sensing target detection datasets DOTA and UCAS-AOD with seven rotating target detectors. The results show that the mAP of FFA under the IoU threshold of 0.5 untargeted attack is 3.4% lower than that of the advanced method, and the mAP of FFA under targeted attack is 1.9% lower than that of the advanced process.

Publisher

MDPI AG

Reference62 articles.

1. Remote sensing image classification using an ensemble framework without multiple classifiers;Dou;ISPRS J. Photogramm. Remote Sens.,2024

2. Generating Adversarial Examples Against Remote Sensing Scene Classification via Feature Approximation;Zhu;IEEE J. Sel. Top. Appl. Earth Obs. Remote Sens.,2024

3. Universal adversarial examples in remote sensing: Methodology and benchmark;Xu;IEEE Trans. Geosci. Remote Sens.,2022

4. Gu, H., Gu, G., Liu, Y., Lin, H., and Xu, Y. (2024). Multi-Branch Attention Fusion Network for Cloud and Cloud Shadow Segmentation. Remote Sens., 16.

5. Enhancing multiscale representations with transformer for remote sensing image semantic segmentation;Xiao;IEEE Trans. Geosci. Remote Sens.,2023

同舟云学术

1.学者识别学者识别

2.学术分析学术分析

3.人才评估人才评估

"同舟云学术"是以全球学者为主线,采集、加工和组织学术论文而形成的新型学术文献查询和分析系统,可以对全球学者进行文献检索和人才价值评估。用户可以通过关注某些学科领域的顶尖人物而持续追踪该领域的学科进展和研究前沿。经过近期的数据扩容,当前同舟云学术共收录了国内外主流学术期刊6万余种,收集的期刊论文及会议论文总量共计约1.5亿篇,并以每天添加12000余篇中外论文的速度递增。我们也可以为用户提供个性化、定制化的学者数据。欢迎来电咨询!咨询电话:010-8811{复制后删除}0370

www.globalauthorid.com

TOP

Copyright © 2019-2024 北京同舟云网络信息技术有限公司
京公网安备11010802033243号  京ICP备18003416号-3