CCPortal
DOI10.1109/ACCESS.2019.2927376
Spear and Shield: Attack and Detection for CNN-Based High Spatial Resolution Remote Sensing Images Identification
Li, Wenmei1,2,3; Li, Zhuangzhuang2; Sun, Jinlong2; Wang, Yu2; Liu, Haiyan2; Yang, Jie2; Gui, Guan2
发表日期2019
ISSN2169-3536
卷号7页码:94583-94592
英文摘要

High spatial resolution remote sensing (HSRRS) images classification and identification is an important technology to acquire land surface information for land resource management, geographical situation monitoring, and global climate change. As the hottest deep learning method, convolutional neural network (CNN) has been successfully applied in HSRRS image classification and identification due to its powerful information extraction capability. However, adversarial perturbations caused by radiation transfer process or artificial or other unpredictable disturbances often deteriorate the stability of CNN. Under this background, we propose a robust architecture for adversarial attack and detection to classify and identify HSRRS images. First of all, two white-box attacks [i.e., large Broyden-Fletcher-Goldfarb-Shanno (L-BFGS) and fast gradient sign method (FGSM)] are adopted respectively to generate adversarial images to confuse the model, and to assess the robustness of the HSRRS image classifier. Second, adversarial detection models based on support vector machine (SVM) with single or fused two level features are proposed to improve the detection accuracy. The features extracted from the testing CNN full connected layers contain adversarial perturbations and real information, from which SVM classifier and discriminate the real and the adversarial images. The adversarial attack model is evaluated in terms of overall accuracy (OA) and kappa coefficient (kc). The simulation results show that the OA decreases from 96.4% to 44.4% and 33.3% for L-BFGS and FGSM attacked classifier model, respectively. The adversarial detection is evaluated via OA, detection probability P-D, false alarm probability P-FA, and miss probability P-M. The simulation results indicate that the fused model with two different level features based on SVM can obtain the best OA (94.5%), P-D (0.933), P-FA (0.040), and P-M (0.067) among the detectors if the classifier is attacked by the FGSM. Meanwhile, when facing the L-BFGS attack, the fused model presents similar performance if the best single level features are utilized.


WOS研究方向Computer Science ; Engineering ; Telecommunications
来源期刊IEEE ACCESS
文献类型期刊论文
条目标识符http://gcip.llas.ac.cn/handle/2XKMVOVA/90676
作者单位1.Nanjing Univ Posts & Telecommun, Sch Geog & Biol Informat, Nanjing 210023, Jiangsu, Peoples R China;
2.Nanjing Univ Posts & Telecommun, Coll Telecommun & Informat Engn, Nanjing 210003, Jiangsu, Peoples R China;
3.Smart Hlth Big Data Anal & Locat Serv Engn Lab Ji, Nanjing 210023, Jiangsu, Peoples R China
推荐引用方式
GB/T 7714
Li, Wenmei,Li, Zhuangzhuang,Sun, Jinlong,et al. Spear and Shield: Attack and Detection for CNN-Based High Spatial Resolution Remote Sensing Images Identification[J],2019,7:94583-94592.
APA Li, Wenmei.,Li, Zhuangzhuang.,Sun, Jinlong.,Wang, Yu.,Liu, Haiyan.,...&Gui, Guan.(2019).Spear and Shield: Attack and Detection for CNN-Based High Spatial Resolution Remote Sensing Images Identification.IEEE ACCESS,7,94583-94592.
MLA Li, Wenmei,et al."Spear and Shield: Attack and Detection for CNN-Based High Spatial Resolution Remote Sensing Images Identification".IEEE ACCESS 7(2019):94583-94592.
条目包含的文件
条目无相关文件。
个性服务
推荐该条目
保存到收藏夹
导出为Endnote文件
谷歌学术
谷歌学术中相似的文章
[Li, Wenmei]的文章
[Li, Zhuangzhuang]的文章
[Sun, Jinlong]的文章
百度学术
百度学术中相似的文章
[Li, Wenmei]的文章
[Li, Zhuangzhuang]的文章
[Sun, Jinlong]的文章
必应学术
必应学术中相似的文章
[Li, Wenmei]的文章
[Li, Zhuangzhuang]的文章
[Sun, Jinlong]的文章
相关权益政策
暂无数据
收藏/分享

除非特别说明,本系统中所有内容都受版权保护,并保留所有权利。