Évaluation de la robustesse des modèles d'identification profonde sur les images multi-sources de télédétection face aux attaques

  • role: First author第一作者
  • Affiliation:

    College of Electronic Science, National University of Defense Technology, Changsha 410073, China

  • Email:sunhao@nudt.edu.cn
  • Introduction:E-mail sunhao@nudt.edu.cn
SUN Hao1,  
  • Affiliation:

    College of Electronic Science, National University of Defense Technology, Changsha 410073, China

XU Yanjie1,  
  • Affiliation:

    Beijing Institute of Remote Sensing Information, Beijing 100192, China

CHEN Jin2,  
  • Affiliation:

    College of Electronic Science, National University of Defense Technology, Changsha 410073, China

LEI Lin1,  
  • Affiliation:

    College of Electronic Science, National University of Defense Technology, Changsha 410073, China

JI Kefeng1,  
  • Affiliation:

    College of Electronic Science, National University of Defense Technology, Changsha 410073, China

KUANG Gangyao1

résumé

Le système d'identification des cibles sur les images multi-sources de télédétection basé sur les réseaux neuronaux profonds a progressivement été largement appliqué dans la reconnaissance spatiale, la conscience autonome de la situation des scènes de guerre sans pilote, la navigation multi-mode et d'autres scénarios militaires. Cependant, en raison de l'incomplétude de la théorie de l'apprentissage profond, de la réutilisation intensive de la conception de la structure des réseaux neuronaux profonds et de l'influence de toutes sortes de perturbations dans un environnement électromagnétique complexe sur le système d'identification multi-source d'images, il existe une évaluation insuffisante de la robustesse face aux attaques de la présente système, ce qui comporte de graves risques sécuritaires. Dans cet article, nous analysons d'abord les risques potentiels pour la sécurité dus à l'incomplétude de la théorie de l'apprentissage profond et aux modèles d'attaque sur le système d'identification, et présentons en détail les principes fondamentaux et les méthodes typiques d'attaque des modèles d'identification profonde. Ensuite, nous évaluons la robustesse des modèles d'identification profonde face aux attaques sur les images multi-sources de télédétection sous l'angle du taux de reconnaissance correcte robuste et de la compréhensibilité des attaques. L'évaluation comprend neuf types d'architectures courantes de réseaux d'identification profonde et sept types d'attaques typiques de modèles d'identification, confirme le défaut général de robustesse des modèles d'identification profonde face aux attaques complexes, analyse les différences dans les activations cachées des caractéristiques entre les modèles d'attaque et les modèles normaux, et fournit des indications pour la conception ultérieure d'algorithmes de détection des modèles d'attaque et le renforcement de la robustesse des modèles face aux attaques.

mots-clés

Identification des cibles sur les images multi-sources de télédétection; Réseaux neuronaux profonds; Attaques; Visualisation des caractéristiques; Évaluation de la robustesse face aux attaques

References

  1. 1.
    Berghoff C, Neu M and Von Twickel A. 2020. Vulnerabilities of connectionist AI applications: evaluation and defence. arXiv preprint arXiv:2003.08837
  2. 2.
    Blasch E. 2020. Self-proficiency assessment for ATR systems//Proceedings of SPIE 11393, Algorithms for Synthetic Aperture Radar Imagery XXVII. [s.l.]: SPIE: 113930T
  3. 3.
    Carlini N and Wagner D. 2017. Towards evaluating the robustness of neural networks//Proceedings of 2017 IEEE Symposium on Security and Privacy. San Jose: IEEE: 39-57
  4. 4.
    Chen J B, Jordan M I and Wainwright M J. 2020. HopSkipJumpAttack: a query-efficient decision-based attack//Proceedings of 2020 IEEE Symposium on Security and Privacy. San Francisco: IEEE: 1277-1294
  5. 5.
    Chen P Y, Sharma Y, Zhang H, Yi J F and Hsieh C J. 2018. EAD: elastic-net attacks to deep neural networks via adversarial examples. Proceedings of the 32nd AAAI Conference on Artificial Intelligence. New Orleans: AAAI: 2
  6. 6.
    Cheng G, Xie X X, Han J W, Guo L and Xia G S. 2020. Remote sensing image scene classification meets deep learning: challenges, methods, benchmarks, and opportunities. IEEE Journal of Selected Topics in Applied Earth Observations and Remote Sensing, 13: 3735-3756
  7. 7.
    Fawzi A, Moosavi-Dezfooli S M and Frossard P. 2017. The robustness of deep networks: a geometrical perspective. IEEE Signal Processing Magazine, 34(6): 50-62
  8. 8.
    Goodfellow I J, Shlens J and Szegedy C. 2015. Explaining and harnessing adversarial examples. Proceedings of the 3rd International Conference on Learning Representations. San Diego: ICLR
  9. 9.
    Kurte K R, Durbha S S, King R L, Younan N H and Vatsavai R. 2017. Semantics-enabled framework for spatial image information mining of linked earth observation data. IEEE Journal of Selected Topics in Applied Earth Observations and Remote Sensing, 10(1): 29-44
  10. 10.
    Madry A, Makelov A, Schmidt L, Tsipras D and Vladu A. 2018. Towards deep learning models resistant to adversarial attacks. Proceedings of the 6th International Conference on Learning Representations. Vancouver: ICLR
  11. 11.
    Moosavi-Dezfooli S M, Fawzi A and Frossard P. 2016. DeepFool: a simple and accurate method to fool deep neural networks//Proceedings of 2016 IEEE Conference on Computer Vision and Pattern Recognition. Las Vegas: IEEE: 2574-2582
  12. 12.
    Naseer M, Khan S, Hayat M, Khan F S and Porikli F. 2020. A self-supervised approach for adversarial robustness//Proceedings of 2020 IEEE/CVF Conference on Computer Vision and Pattern Recognition (CVPR). Seattle: IEEE: 259-268
  13. 13.
    Ras G, Xie N, Van Gerven M and Doran D. 2020. Explainable deep learning: a field guide for the uninitiated. arXiv preprint arXiv:2004.14545
  14. 14.
    Ross T D, Worrell S W, Velten V J, Mossing J C and Bryant M L. 1998. Standard SAR ATR evaluation experiments using the MSTAR public release data set//Proceedings of the SPIE 3370, Algorithms for Synthetic Aperture Radar Imagery V. Orlando: SPIE, 1998. 566-573
  15. 15.
    Selvaraju R R, Cogswell M, Das A, Vedantam R, Parikh D and Batra D. 2017. Grad-CAM: visual explanations from deep networks via gradient-based localization//Proceedings of 2017 IEEE International Conference on Computer Vision (ICCV). Venice: IEEE: 618-626
  16. 16.
    Sun H, Chen J, Lei L, Ji K F and Kuang G Y. 2021. Adversarial robustness of deep convolutional neural network based image recognition models: a review. Journal of Radars, 10(4): 571-594
  17. 17.
    Szegedy C, Zaremba W, Sutskever I, Bruna J, Erhan D, Goodfellow I J and Fergus R. 2014. Intriguing properties of neural networks. Proceedings of the 2nd International Conference on Learning Representations. Banff: ICLR
  18. 18.
    Tong X D. 2016. Development of China high-resolution earth observation system. Journal of Remote Sensing, 20(5): 775-780
  19. 19.
    Wiyatno R R, Xu A Q, Dia O and De Berker A. 2019. Adversarial examples in modern machine learning: a review. arXiv preprint arXiv:1911.05268
  20. 20.
    Xu Y H, Du B and Zhang L P. 2021. Assessing the threat of adversarial examples on deep neural networks for remote sensing scene classification: attacks and defenses. IEEE Transactions on Geoscience and Remote Sensing, 59(2): 1604-1617
  21. 21.
    Yang Y and Newsam S. 2010. Bag-of-visual-words and spatial extensions for land-use classification//Proceedings of the 18th SIGSPATIAL International Conference on Advances in Geographic Information Systems. San Jose: ACM: 270-279
  22. 22.
    Yuan X Y, He P, Zhu Q L and Li X L. 2019. Adversarial examples: attacks and defenses for deep learning. IEEE Transactions on Neural Networks and Learning Systems, 30(9): 2805-2824
  23. 23.
    Zhou B L, Khosla A, Lapedriza A, Oliva A and Torralba A. 2016. Learning deep features for discriminative localization//Proceedings of 2016 IEEE Conference on Computer Vision and Pattern Recognition. Las Vegas: IEEE: 2921-2929
  24. 24.
    Zhu X X, Montazeri S, Ali M, Hua Y S, Wang Y Y, Mou L C, Shi Y L, Xu F and Bamler R. 2020. Deep learning meets SAR. arXiv preprint arXiv:2006.10027

Lire l'article complet

The above content is generated by Large Model Translation. The translated content is for reference only. We do not assume any commercial or legal responsibilty for any consequences arising from the use of our website