Boosting Adversarial Transferability for Hyperspectral Image Classification Using 3D Structure-invariant Transformation and Intermediate Feature Distance

📅 2025-06-12
📈 Citations: 0
Influential: 0
📄 PDF
🤖 AI Summary
To address the poor transferability of adversarial attacks against hyperspectral image (HSI) classification models, this paper proposes a block-wise random transformation mechanism that preserves the intrinsic 3D spatial-spectral structure of HSIs, coupled with a multi-objective collaborative optimization framework—prioritizing intermediate-layer feature distance while incorporating output-layer prediction loss as a secondary objective. Notably, this work is the first to integrate explicit 3D structural constraints into HSI adversarial sample generation, thereby significantly enhancing the perturbation’s capacity to disrupt discriminative deep features. Extensive experiments on the Indian Pines and Pavia University benchmark datasets demonstrate that the proposed method substantially improves transfer success rates under black-box, cross-model attack settings. Moreover, it maintains strong robustness against prevalent defenses, including input preprocessing and adversarial training. This study advances the security analysis of HSIs by offering both a novel conceptual framework and an effective practical tool.

Technology Category

Application Category

📝 Abstract
Deep Neural Networks (DNNs) are vulnerable to adversarial attacks, which pose security challenges to hyperspectral image (HSI) classification technologies based on DNNs. In the domain of natural images, numerous transfer-based adversarial attack methods have been studied. However, HSIs differ from natural images due to their high-dimensional and rich spectral information. Current research on HSI adversarial examples remains limited and faces challenges in fully utilizing the structural and feature information of images. To address these issues, this paper proposes a novel method to enhance the transferability of the adversarial examples for HSI classification models. First, while keeping the image structure unchanged, the proposed method randomly divides the image into blocks in both spatial and spectral dimensions. Then, various transformations are applied on a block by block basis to increase input diversity and mitigate overfitting. Second, a feature distancing loss targeting intermediate layers is designed, which measures the distance between the amplified features of the original examples and the features of the adversarial examples as the primary loss, while the output layer prediction serves as the auxiliary loss. This guides the perturbation to disrupt the features of the true class in adversarial examples, effectively enhancing transferability. Extensive experiments demonstrate that the adversarial examples generated by the proposed method achieve effective transferability to black-box models on two public HSI datasets. Furthermore, the method maintains robust attack performance even under defense strategies.
Problem

Research questions and friction points this paper is trying to address.

Enhancing adversarial transferability for HSI classification models
Utilizing 3D structure-invariant transformations for input diversity
Designing feature distancing loss to disrupt true class features
Innovation

Methods, ideas, or system contributions that make the work stand out.

3D structure-invariant transformation for HSI blocks
Intermediate feature distance loss design
Enhanced adversarial example transferability
🔎 Similar Papers
No similar papers found.
Chun Liu
Chun Liu
Department of Applied Mathematics, Illinois Institute of Technology
Applied AnalysisContinuum MechanicsComplex FluidsLiquid CrystalsThermodynamics
B
Bingqian Zhu
School of Computer and Information Engineering, Henan University, Zhengzhou, Henan 450046, China
T
Tao Xu
State Key Laboratory of Spatial Datum, College of Remote Sensing and Geoinformatics Engineering, Faculty of Geographical Science and Engineering; the School of Computer and Information Engineering; and the Henan Industrial Technology Academy of Spatio-Temporal Big Data, Henan University, Zhengzhou, Henan 450046, China
Z
Zheng Zheng
National Key Laboratory of Integrated Aircraft Control Technology, School of Automation Science and Electrical Engineering, Beihang University, Beijing 100091, China
Z
Zheng Li
School of Computer and Information Engineering, Henan University, Zhengzhou, Henan 450046, China
W
Wei Yang
School of Computer and Information Engineering, Henan University, Zhengzhou, Henan 450046, China
Z
Zhigang Han
State Key Laboratory of Spatial Datum, College of Remote Sensing and Geoinformatics Engineering, Faculty of Geographical Science and Engineering; and the Henan Industrial Technology Academy of Spatio-Temporal Big Data, Henan University, Zhengzhou, Henan 450046, China
J
Jiayao Wang
State Key Laboratory of Spatial Datum, College of Remote Sensing and Geoinformatics Engineering, Faculty of Geographical Science and Engineering; and the Henan Industrial Technology Academy of Spatio-Temporal Big Data, Henan University, Zhengzhou, Henan 450046, China