Skip to content

Multiscale Frame Transformation for Transferable Adversarial Attacks on Remote Sensing Scene Classification

2026 · IEEE Geoscience and Remote Sensing Letters · Vol 23, pp. 6019505-6019505 · 0 citations · 22 references

Abstract

Transferable adversarial attacks provide an important means of evaluating the black-box security of remote sensing scene classification models. However, the existing spatial input transformations commonly rely on predefined block shapes and limited partition granularities, providing insufficient coverage of the diverse orientations and spatial scales in remote sensing scenes. We propose a training-free multiscale frame transformation (MFT) method that samples orientation-complementary frame patterns at different granularities and constructs randomized spatial views through frame shuffling and lightweight intraframe transformations. During each attack iteration, gradients from multiple MFT views are aggregated to reduce sensitivity to individual spatial layouts. Experiments on NWPU-RESISC45 and AID show that the MFT achieves the highest average black-box attack success rate (ASR) in all four dataset–surrogate settings and transfers effectively across convolutional neural network (CNN), transformer, and contrastive language–image pretraining (CLIP) architectures. Across 32 black-box target settings, the MFT achieves an overall average ASR of 91.64%, exceeding the best competing baseline by 2.66 percentage points. Ablation studies further support the benefits of orientation complementarity and cross-granularity integration.

View source

Similar papers

Sep 2026

Boosting cross-architecture adversarial transferability by enhanced deformation attack.

The Enhanced Deformation Attack (EDA), which estimates attack gradients over stochastically transformed views of the current adversarial image, achieves the highest mean attack success rate (ASR) on ViT targets for all four CNN sources, outperforming the strongest source-specific baseline.

Jia-Cheng Wang, Hegui Zhu, Yi-Fan Zhang et al. · 0 citations
Review Open access Oct 2026

A Review of Remote Sensing Image Translation Based on Generative Adversarial Networks

Generative adversarial networks (GANs) have become an important approach for translating remote sensing images across sensing modalities, acquisition domains, and degraded observation conditions. This paper reviews 111 studies published between 2018 and 2026 and analyzes the field from three translation perspectives: i...

Zhao-Wei Wang, Fu-Tao Wang, Zhen-Qing Wang et al. · 0 citations
2026

FastSAM-Guided Adversarial Learning for Unsupervised Multimodal Remote Sensing Change Detection

Multimodal change detection (CD), due to its ability to flexibly adapt to data acquired from different types of sensors, has become an important research direction in the field of remote sensing. However, existing methods generally lack feature representations with sufficient generalization capacity, leading to pronoun...

Zhi-Fu Zhu, Xi-Ping Yuan, Shu Gan et al. · 0 citations
2026

Neighborhood Geometry–Guided Prototype Contrastive Adaptation for Cross-Domain Remote Sensing Scene Classification

A neighborhood geometry–guided prototype contrastive adaptation (NGPCA) framework built upon the domain-adversarial neural network is proposed, showing robust performance for cross-domain remote sensing scene classification.

Qing He, Er-Zhu Li, Wei-Jing Zhu et al. · 0 citations
Conference Sep 2026

Boosting adversarial attacks with attention-guided luminance perturbation

Deep Neural Networks (DNNs) are vulnerable to adversarial examples generated by adding human-imperceptible perturbations to benign inputs. Moreover, the transferability of adversarial examples enables effective black-box attacks across different models. However, existing attack methods typically generate spatially dens...

Zi-Han Huang · 0 citations
Open access Sep 2026

A Guided Implicit Generative Adversarial CNN–Transformer Framework for Class-Imbalanced Hyperspectral Image Classification

Hyperspectral image (HSI) classification is important for land-cover recognition and remote-sensing scene analysis. However, class imbalance severely limits performance when minority classes contain only a few labeled samples, causing models to show strong overall results while failing to identify minority classes effe...

Zhi-Wei Wang, Z. Meng, Mei-Bao Yao et al. · 0 citations

We use cookies to run the site and, with your consent, for analytics and to show ads. See our Cookie Policy.