Evaluación de la robustez de los modelos de identificación profunda en imágenes de teledetección multi sensor frente a ataques

  • role: First author第一作者
  • Affiliation:

    College of Electronic Science, National University of Defense Technology, Changsha 410073, China

  • Email:sunhao@nudt.edu.cn
  • Introduction:E-mail sunhao@nudt.edu.cn
SUN Hao1,  
  • Affiliation:

    College of Electronic Science, National University of Defense Technology, Changsha 410073, China

XU Yanjie1,  
  • Affiliation:

    Beijing Institute of Remote Sensing Information, Beijing 100192, China

CHEN Jin2,  
  • Affiliation:

    College of Electronic Science, National University of Defense Technology, Changsha 410073, China

LEI Lin1,  
  • Affiliation:

    College of Electronic Science, National University of Defense Technology, Changsha 410073, China

JI Kefeng1,  
  • Affiliation:

    College of Electronic Science, National University of Defense Technology, Changsha 410073, China

KUANG Gangyao1

resumen

El sistema de identificación de objetivos en imágenes de teledetección multisensor basado en redes neuronales profundas ha comenzado a ser ampliamente aplicado en el reconocimiento espacial, la conciencia autónoma de la situación de combate en entornos no tripulados, la navegación multimodal y otros escenarios militares. Sin embargo, debido a la incompletitud de la teoría del aprendizaje profundo, la reutilización intensiva del diseño de la estructura de las redes neuronales profundas y la influencia de todo tipo de interferencias en un entorno electromagnético complejo en el sistema de identificación de imágenes multi sensoriales, existe una evaluación insuficiente de la robustez frente a los ataques del sistema existente, lo que conlleva graves riesgos de seguridad. En este artículo, primero analizamos los riesgos potenciales para la seguridad debido a la incompletitud de la teoría del aprendizaje profundo y los patrones de ataque en el sistema de identificación, y presentamos los principios básicos y los métodos típicos de ataque de modelos de identificación profunda. Luego, evaluamos la robustez de los modelos de identificación profunda frente a los ataques en imágenes de teledetección multisensor desde el punto de vista de la tasa de reconocimiento correcto robusto y la explicabilidad de los ataques. La evaluación incluye nueve tipos comunes de arquitecturas de modelos de identificación profunda y siete tipos típicos de ataques a modelos de identificación, confirma la falta general de robustez de los modelos de identificación profunda frente a ataques complejos, analiza las diferencias en las activaciones ocultas de las características entre modelos de ataque y modelos normales, y proporciona pistas para el diseño futuro de algoritmos de detección de modelos de ataque y el fortalecimiento de la robustez de los modelos frente a los ataques.

palabra clave

Identificación de objetivos en imágenes de teledetección multi sensor; Redes neuronales profundas; Ataques; Visualización de características; Evaluación de la robustez frente a ataques

References

  1. 1.
    Berghoff C, Neu M and Von Twickel A. 2020. Vulnerabilities of connectionist AI applications: evaluation and defence. arXiv preprint arXiv:2003.08837
  2. 2.
    Blasch E. 2020. Self-proficiency assessment for ATR systems//Proceedings of SPIE 11393, Algorithms for Synthetic Aperture Radar Imagery XXVII. [s.l.]: SPIE: 113930T
  3. 3.
    Carlini N and Wagner D. 2017. Towards evaluating the robustness of neural networks//Proceedings of 2017 IEEE Symposium on Security and Privacy. San Jose: IEEE: 39-57
  4. 4.
    Chen J B, Jordan M I and Wainwright M J. 2020. HopSkipJumpAttack: a query-efficient decision-based attack//Proceedings of 2020 IEEE Symposium on Security and Privacy. San Francisco: IEEE: 1277-1294
  5. 5.
    Chen P Y, Sharma Y, Zhang H, Yi J F and Hsieh C J. 2018. EAD: elastic-net attacks to deep neural networks via adversarial examples. Proceedings of the 32nd AAAI Conference on Artificial Intelligence. New Orleans: AAAI: 2
  6. 6.
    Cheng G, Xie X X, Han J W, Guo L and Xia G S. 2020. Remote sensing image scene classification meets deep learning: challenges, methods, benchmarks, and opportunities. IEEE Journal of Selected Topics in Applied Earth Observations and Remote Sensing, 13: 3735-3756
  7. 7.
    Fawzi A, Moosavi-Dezfooli S M and Frossard P. 2017. The robustness of deep networks: a geometrical perspective. IEEE Signal Processing Magazine, 34(6): 50-62
  8. 8.
    Goodfellow I J, Shlens J and Szegedy C. 2015. Explaining and harnessing adversarial examples. Proceedings of the 3rd International Conference on Learning Representations. San Diego: ICLR
  9. 9.
    Kurte K R, Durbha S S, King R L, Younan N H and Vatsavai R. 2017. Semantics-enabled framework for spatial image information mining of linked earth observation data. IEEE Journal of Selected Topics in Applied Earth Observations and Remote Sensing, 10(1): 29-44
  10. 10.
    Madry A, Makelov A, Schmidt L, Tsipras D and Vladu A. 2018. Towards deep learning models resistant to adversarial attacks. Proceedings of the 6th International Conference on Learning Representations. Vancouver: ICLR
  11. 11.
    Moosavi-Dezfooli S M, Fawzi A and Frossard P. 2016. DeepFool: a simple and accurate method to fool deep neural networks//Proceedings of 2016 IEEE Conference on Computer Vision and Pattern Recognition. Las Vegas: IEEE: 2574-2582
  12. 12.
    Naseer M, Khan S, Hayat M, Khan F S and Porikli F. 2020. A self-supervised approach for adversarial robustness//Proceedings of 2020 IEEE/CVF Conference on Computer Vision and Pattern Recognition (CVPR). Seattle: IEEE: 259-268
  13. 13.
    Ras G, Xie N, Van Gerven M and Doran D. 2020. Explainable deep learning: a field guide for the uninitiated. arXiv preprint arXiv:2004.14545
  14. 14.
    Ross T D, Worrell S W, Velten V J, Mossing J C and Bryant M L. 1998. Standard SAR ATR evaluation experiments using the MSTAR public release data set//Proceedings of the SPIE 3370, Algorithms for Synthetic Aperture Radar Imagery V. Orlando: SPIE, 1998. 566-573
  15. 15.
    Selvaraju R R, Cogswell M, Das A, Vedantam R, Parikh D and Batra D. 2017. Grad-CAM: visual explanations from deep networks via gradient-based localization//Proceedings of 2017 IEEE International Conference on Computer Vision (ICCV). Venice: IEEE: 618-626
  16. 16.
    Sun H, Chen J, Lei L, Ji K F and Kuang G Y. 2021. Adversarial robustness of deep convolutional neural network based image recognition models: a review. Journal of Radars, 10(4): 571-594
  17. 17.
    Szegedy C, Zaremba W, Sutskever I, Bruna J, Erhan D, Goodfellow I J and Fergus R. 2014. Intriguing properties of neural networks. Proceedings of the 2nd International Conference on Learning Representations. Banff: ICLR
  18. 18.
    Tong X D. 2016. Development of China high-resolution earth observation system. Journal of Remote Sensing, 20(5): 775-780
  19. 19.
    Wiyatno R R, Xu A Q, Dia O and De Berker A. 2019. Adversarial examples in modern machine learning: a review. arXiv preprint arXiv:1911.05268
  20. 20.
    Xu Y H, Du B and Zhang L P. 2021. Assessing the threat of adversarial examples on deep neural networks for remote sensing scene classification: attacks and defenses. IEEE Transactions on Geoscience and Remote Sensing, 59(2): 1604-1617
  21. 21.
    Yang Y and Newsam S. 2010. Bag-of-visual-words and spatial extensions for land-use classification//Proceedings of the 18th SIGSPATIAL International Conference on Advances in Geographic Information Systems. San Jose: ACM: 270-279
  22. 22.
    Yuan X Y, He P, Zhu Q L and Li X L. 2019. Adversarial examples: attacks and defenses for deep learning. IEEE Transactions on Neural Networks and Learning Systems, 30(9): 2805-2824
  23. 23.
    Zhou B L, Khosla A, Lapedriza A, Oliva A and Torralba A. 2016. Learning deep features for discriminative localization//Proceedings of 2016 IEEE Conference on Computer Vision and Pattern Recognition. Las Vegas: IEEE: 2921-2929
  24. 24.
    Zhu X X, Montazeri S, Ali M, Hua Y S, Wang Y Y, Mou L C, Shi Y L, Xu F and Bamler R. 2020. Deep learning meets SAR. arXiv preprint arXiv:2006.10027

Leer el texto completo

The above content is generated by Large Model Translation. The translated content is for reference only. We do not assume any commercial or legal responsibilty for any consequences arising from the use of our website