Return
Boosting Adversarial Transferability by Batchwise Amplitude Spectrum Normalization
DOI:10.1109/TGRS.2025.3535697.png)
Abstract
En 中文
We consider the black-box adversarial attack problem in the field of remote sensing images (RSIs) to reveal the vulnerabilities of various deep neural networks (DNNs), including classification and semantic segmentation models. Existing adversarial attack methods typically focus solely on maximizing attack success rates (ASRs) under given perturbation constraints, neglecting the differences between adversarial samples and clean images. We propose a batchwise amplitude spectrum normalization (BAMPN) method, which is a plug-and-play and transfer-based black-box attack strategy. Using Fourier transform, we convert RSIs from the spatial domain into the frequency domain to obtain the amplitude spectrum, which is normalized within the batch. Moreover, we use a moving average strategy to retain the historical amplitudes of the batch, enhancing input diversity. By mixing the low-level statistical features of RSIs, BAMPN reduces the differences between adversarial samples and clean images while improving attack transferability. In addition, BAMPN is applicable not only to RSIs classification tasks but also directly to semantic segmentation tasks, as it preserves the spatial semantic structure of RSIs. We conduct extensive experiments using 20 DNN models and four benchmark RSIs' datasets, comparing our method against 14 state-of-the-art (SOTA) approaches. The results demonstrate that BAMPN achieves superior attack performance while ensuring a promising similarity between adversarial and clean samples.
Keywords:
Perturbation methods
Frequency-domain analysis
Closed box
Semantic segmentation
Remote sensing
Semantics
Noise
Glass box
Artificial neural networks
Training
Adversarial attack
adversarial transferability
amplitude normalization
black-box attack
remote sensing images
Journal
IF:
8.6
Papers:
2.1W
Citations:
10.7W

