Backdoor Attacks for Remote Sensing Data with Wavelet Transform

11/15/2022
by   Nikolaus Dräger, et al.
0

Recent years have witnessed the great success of deep learning algorithms in the geoscience and remote sensing realm. Nevertheless, the security and robustness of deep learning models deserve special attention when addressing safety-critical remote sensing tasks. In this paper, we provide a systematic analysis of backdoor attacks for remote sensing data, where both scene classification and semantic segmentation tasks are considered. While most of the existing backdoor attack algorithms rely on visible triggers like squared patches with well-designed patterns, we propose a novel wavelet transform-based attack (WABA) method, which can achieve invisible attacks by injecting the trigger image into the poisoned image in the low-frequency domain. In this way, the high-frequency information in the trigger image can be filtered out in the attack, resulting in stealthy data poisoning. Despite its simplicity, the proposed method can significantly cheat the current state-of-the-art deep learning models with a high attack success rate. We further analyze how different trigger images and the hyper-parameters in the wavelet transform would influence the performance of the proposed method. Extensive experiments on four benchmark remote sensing datasets demonstrate the effectiveness of the proposed method for both scene classification and semantic segmentation tasks and thus highlight the importance of designing advanced backdoor defense algorithms to address this threat in remote sensing scenarios. The code will be available online at <https://github.com/ndraeger/waba>.

READ FULL TEXT

page 1

page 4

page 5

page 6

page 9

page 10

page 11

page 12

research
09/11/2023

Self-Correlation and Cross-Correlation Learning for Few-Shot Remote Sensing Image Semantic Segmentation

Remote sensing image semantic segmentation is an important problem for r...
research
02/14/2022

Universal Adversarial Examples in Remote Sensing: Methodology and Benchmark

Deep neural networks have achieved great success in many important remot...
research
10/16/2020

Input-Aware Dynamic Backdoor Attack

In recent years, neural backdoor attack has been considered to be a pote...
research
05/28/2021

Demotivate adversarial defense in remote sensing

Convolutional neural networks are currently the state-of-the-art algorit...
research
08/08/2022

Txt2Img-MHN: Remote Sensing Image Generation from Text Using Modern Hopfield Networks

The synthesis of high-resolution remote sensing images based on text des...
research
05/17/2022

Pairwise Comparison Network for Remote Sensing Scene Classification

Remote sensing scene classification aims to assign a specific semantic l...
research
10/16/2022

ResAttUNet: Detecting Marine Debris using an Attention activated Residual UNet

Currently, a significant amount of research has been done in field of Re...

Please sign up or login with your details

Forgot password? Click here to reset