globalchange  > 气候减缓与适应
DOI: 10.1109/ACCESS.2019.2927376
WOS记录号: WOS:000478676600034
论文题名:
Spear and Shield: Attack and Detection for CNN-Based High Spatial Resolution Remote Sensing Images Identification
作者: Li, Wenmei1,2,3; Li, Zhuangzhuang2; Sun, Jinlong2; Wang, Yu2; Liu, Haiyan2; Yang, Jie2; Gui, Guan2
通讯作者: Sun, Jinlong ; Gui, Guan
刊名: IEEE ACCESS
ISSN: 2169-3536
出版年: 2019
卷: 7, 页码:94583-94592
语种: 英语
英文关键词: Convolutional neural network ; attack detection ; white-box attack ; fast gradient sign method (FGSM) ; large Broyden-Fletcher-Goldfarb-Shanno (L-BFGS)
WOS学科分类: Computer Science, Information Systems ; Engineering, Electrical & Electronic ; Telecommunications
WOS研究方向: Computer Science ; Engineering ; Telecommunications
英文摘要:

High spatial resolution remote sensing (HSRRS) images classification and identification is an important technology to acquire land surface information for land resource management, geographical situation monitoring, and global climate change. As the hottest deep learning method, convolutional neural network (CNN) has been successfully applied in HSRRS image classification and identification due to its powerful information extraction capability. However, adversarial perturbations caused by radiation transfer process or artificial or other unpredictable disturbances often deteriorate the stability of CNN. Under this background, we propose a robust architecture for adversarial attack and detection to classify and identify HSRRS images. First of all, two white-box attacks [i.e., large Broyden-Fletcher-Goldfarb-Shanno (L-BFGS) and fast gradient sign method (FGSM)] are adopted respectively to generate adversarial images to confuse the model, and to assess the robustness of the HSRRS image classifier. Second, adversarial detection models based on support vector machine (SVM) with single or fused two level features are proposed to improve the detection accuracy. The features extracted from the testing CNN full connected layers contain adversarial perturbations and real information, from which SVM classifier and discriminate the real and the adversarial images. The adversarial attack model is evaluated in terms of overall accuracy (OA) and kappa coefficient (kc). The simulation results show that the OA decreases from 96.4% to 44.4% and 33.3% for L-BFGS and FGSM attacked classifier model, respectively. The adversarial detection is evaluated via OA, detection probability P-D, false alarm probability P-FA, and miss probability P-M. The simulation results indicate that the fused model with two different level features based on SVM can obtain the best OA (94.5%), P-D (0.933), P-FA (0.040), and P-M (0.067) among the detectors if the classifier is attacked by the FGSM. Meanwhile, when facing the L-BFGS attack, the fused model presents similar performance if the best single level features are utilized.


Citation statistics:
资源类型: 期刊论文
标识符: http://119.78.100.158/handle/2HF3EXSE/125893
Appears in Collections:气候减缓与适应

Files in This Item:

There are no files associated with this item.


作者单位: 1.Nanjing Univ Posts & Telecommun, Sch Geog & Biol Informat, Nanjing 210023, Jiangsu, Peoples R China
2.Nanjing Univ Posts & Telecommun, Coll Telecommun & Informat Engn, Nanjing 210003, Jiangsu, Peoples R China
3.Smart Hlth Big Data Anal & Locat Serv Engn Lab Ji, Nanjing 210023, Jiangsu, Peoples R China

Recommended Citation:
Li, Wenmei,Li, Zhuangzhuang,Sun, Jinlong,et al. Spear and Shield: Attack and Detection for CNN-Based High Spatial Resolution Remote Sensing Images Identification[J]. IEEE ACCESS,2019-01-01,7:94583-94592
Service
Recommend this item
Sava as my favorate item
Show this item's statistics
Export Endnote File
Google Scholar
Similar articles in Google Scholar
[Li, Wenmei]'s Articles
[Li, Zhuangzhuang]'s Articles
[Sun, Jinlong]'s Articles
百度学术
Similar articles in Baidu Scholar
[Li, Wenmei]'s Articles
[Li, Zhuangzhuang]'s Articles
[Sun, Jinlong]'s Articles
CSDL cross search
Similar articles in CSDL Cross Search
[Li, Wenmei]‘s Articles
[Li, Zhuangzhuang]‘s Articles
[Sun, Jinlong]‘s Articles
Related Copyright Policies
Null
收藏/分享
所有评论 (0)
暂无评论
 

Items in IR are protected by copyright, with all rights reserved, unless otherwise indicated.