Оценка устойчивости глубоких моделей распознавания на многоканальных изображениях дистанционного зондирования к атакам

  • role: First author第一作者
  • Affiliation:

    College of Electronic Science, National University of Defense Technology, Changsha 410073, China

  • Email:sunhao@nudt.edu.cn
  • Introduction:E-mail sunhao@nudt.edu.cn
SUN Hao1,  
  • Affiliation:

    College of Electronic Science, National University of Defense Technology, Changsha 410073, China

XU Yanjie1,  
  • Affiliation:

    Beijing Institute of Remote Sensing Information, Beijing 100192, China

CHEN Jin2,  
  • Affiliation:

    College of Electronic Science, National University of Defense Technology, Changsha 410073, China

LEI Lin1,  
  • Affiliation:

    College of Electronic Science, National University of Defense Technology, Changsha 410073, China

JI Kefeng1,  
  • Affiliation:

    College of Electronic Science, National University of Defense Technology, Changsha 410073, China

KUANG Gangyao1

реферат

Система распознавания объектов на многоканальных изображениях дистанционного зондирования на основе глубоких нейронных сетей постепенно стала широко применяться в области космической разведки, автономной ситуационной осведомленности беспилотных боевых сред, многокомпонентного наведения и навигации и других военных сценариях. Однако ввиду неполноты теории глубокого обучения, инженерной утилизации проектирования структуры глубоких нейронных сетей и влияния всех видов помех в сложной электромагнитной среде на систему многоканального распознавания изображений, существует недостаточная оценка устойчивости атак существующей системы, что приводит к серьезным угрозам безопасности. В данной статье мы в первую очередь анализируем потенциальные риски безопасности из-за неполноты теории глубокого обучения и образцов атак на систему распознавания, и представляем основные принципы и типичные методы атаки на устойчивость глубоких моделей распознавания. Во-вторых, мы оцениваем устойчивость глубоких моделей распознавания к атакам на многоканальных изображениях дистанционного зондирования с точки зрения корректной вероятности распознавания и понятности в отношении атак. Оценка включает в себя девять типичных архитектур глубоких моделей распознавания и семь типичных образцов атаки на примеры глубоких моделей, подтверждает общий недостаток устойчивости глубоких моделей в сложных атаках, анализирует различия в скрытых активациях функций между образцами атак и обычными образцами, и предоставляет указания для следующего проектирования алгоритмов обнаружения образцов атаки и усиления устойчивости моделей к атакам.

ключеви́че слова́

Распознавание объектов на многоканальных изображениях дистанционного зондирования; Глубокие нейронные сети; Атаки; Визуализация функций; Оценка устойчивости к атакам

References

  1. 1.
    Berghoff C, Neu M and Von Twickel A. 2020. Vulnerabilities of connectionist AI applications: evaluation and defence. arXiv preprint arXiv:2003.08837
  2. 2.
    Blasch E. 2020. Self-proficiency assessment for ATR systems//Proceedings of SPIE 11393, Algorithms for Synthetic Aperture Radar Imagery XXVII. [s.l.]: SPIE: 113930T
  3. 3.
    Carlini N and Wagner D. 2017. Towards evaluating the robustness of neural networks//Proceedings of 2017 IEEE Symposium on Security and Privacy. San Jose: IEEE: 39-57
  4. 4.
    Chen J B, Jordan M I and Wainwright M J. 2020. HopSkipJumpAttack: a query-efficient decision-based attack//Proceedings of 2020 IEEE Symposium on Security and Privacy. San Francisco: IEEE: 1277-1294
  5. 5.
    Chen P Y, Sharma Y, Zhang H, Yi J F and Hsieh C J. 2018. EAD: elastic-net attacks to deep neural networks via adversarial examples. Proceedings of the 32nd AAAI Conference on Artificial Intelligence. New Orleans: AAAI: 2
  6. 6.
    Cheng G, Xie X X, Han J W, Guo L and Xia G S. 2020. Remote sensing image scene classification meets deep learning: challenges, methods, benchmarks, and opportunities. IEEE Journal of Selected Topics in Applied Earth Observations and Remote Sensing, 13: 3735-3756
  7. 7.
    Fawzi A, Moosavi-Dezfooli S M and Frossard P. 2017. The robustness of deep networks: a geometrical perspective. IEEE Signal Processing Magazine, 34(6): 50-62
  8. 8.
    Goodfellow I J, Shlens J and Szegedy C. 2015. Explaining and harnessing adversarial examples. Proceedings of the 3rd International Conference on Learning Representations. San Diego: ICLR
  9. 9.
    Kurte K R, Durbha S S, King R L, Younan N H and Vatsavai R. 2017. Semantics-enabled framework for spatial image information mining of linked earth observation data. IEEE Journal of Selected Topics in Applied Earth Observations and Remote Sensing, 10(1): 29-44
  10. 10.
    Madry A, Makelov A, Schmidt L, Tsipras D and Vladu A. 2018. Towards deep learning models resistant to adversarial attacks. Proceedings of the 6th International Conference on Learning Representations. Vancouver: ICLR
  11. 11.
    Moosavi-Dezfooli S M, Fawzi A and Frossard P. 2016. DeepFool: a simple and accurate method to fool deep neural networks//Proceedings of 2016 IEEE Conference on Computer Vision and Pattern Recognition. Las Vegas: IEEE: 2574-2582
  12. 12.
    Naseer M, Khan S, Hayat M, Khan F S and Porikli F. 2020. A self-supervised approach for adversarial robustness//Proceedings of 2020 IEEE/CVF Conference on Computer Vision and Pattern Recognition (CVPR). Seattle: IEEE: 259-268
  13. 13.
    Ras G, Xie N, Van Gerven M and Doran D. 2020. Explainable deep learning: a field guide for the uninitiated. arXiv preprint arXiv:2004.14545
  14. 14.
    Ross T D, Worrell S W, Velten V J, Mossing J C and Bryant M L. 1998. Standard SAR ATR evaluation experiments using the MSTAR public release data set//Proceedings of the SPIE 3370, Algorithms for Synthetic Aperture Radar Imagery V. Orlando: SPIE, 1998. 566-573
  15. 15.
    Selvaraju R R, Cogswell M, Das A, Vedantam R, Parikh D and Batra D. 2017. Grad-CAM: visual explanations from deep networks via gradient-based localization//Proceedings of 2017 IEEE International Conference on Computer Vision (ICCV). Venice: IEEE: 618-626
  16. 16.
    Sun H, Chen J, Lei L, Ji K F and Kuang G Y. 2021. Adversarial robustness of deep convolutional neural network based image recognition models: a review. Journal of Radars, 10(4): 571-594
  17. 17.
    Szegedy C, Zaremba W, Sutskever I, Bruna J, Erhan D, Goodfellow I J and Fergus R. 2014. Intriguing properties of neural networks. Proceedings of the 2nd International Conference on Learning Representations. Banff: ICLR
  18. 18.
    Tong X D. 2016. Development of China high-resolution earth observation system. Journal of Remote Sensing, 20(5): 775-780
  19. 19.
    Wiyatno R R, Xu A Q, Dia O and De Berker A. 2019. Adversarial examples in modern machine learning: a review. arXiv preprint arXiv:1911.05268
  20. 20.
    Xu Y H, Du B and Zhang L P. 2021. Assessing the threat of adversarial examples on deep neural networks for remote sensing scene classification: attacks and defenses. IEEE Transactions on Geoscience and Remote Sensing, 59(2): 1604-1617
  21. 21.
    Yang Y and Newsam S. 2010. Bag-of-visual-words and spatial extensions for land-use classification//Proceedings of the 18th SIGSPATIAL International Conference on Advances in Geographic Information Systems. San Jose: ACM: 270-279
  22. 22.
    Yuan X Y, He P, Zhu Q L and Li X L. 2019. Adversarial examples: attacks and defenses for deep learning. IEEE Transactions on Neural Networks and Learning Systems, 30(9): 2805-2824
  23. 23.
    Zhou B L, Khosla A, Lapedriza A, Oliva A and Torralba A. 2016. Learning deep features for discriminative localization//Proceedings of 2016 IEEE Conference on Computer Vision and Pattern Recognition. Las Vegas: IEEE: 2921-2929
  24. 24.
    Zhu X X, Montazeri S, Ali M, Hua Y S, Wang Y Y, Mou L C, Shi Y L, Xu F and Bamler R. 2020. Deep learning meets SAR. arXiv preprint arXiv:2006.10027

Читать полностью

The above content is generated by Large Model Translation. The translated content is for reference only. We do not assume any commercial or legal responsibilty for any consequences arising from the use of our website