Skip to content

Disentangle to Align: A New Paradigm for Robust Change Detection via Adversarial Feature Purification

2026 · IEEE Transactions on Geoscience and Remote Sensing · Vol 64, pp. 5634620-5634620 · 0 citations · 84 references

Abstract

Remote sensing change detection (RSCD) remains vulnerable to pseudo-changes caused by seasonal, illumination, and atmospheric discrepancies between bi-temporal images. Existing deep models often ignore this temporal distribution gap or align entangled features directly, which may corrupt change-relevant semantics and cause negative transfer. To address this challenge, this article proposes the disentangled adversarial alignment network (DAANet), establishing a novel “Disentangle to Align” paradigm and introducing a domain adaptation (DA)-inspired temporal distribution alignment framework for time-invariant feature learning (IFL) in change detection. DAANet first uses a content-style gate (CSG) to separate content-preserving features from style-biased residuals, and then applies adversarial alignment only to the residual branch. This targeted alignment encourages the backbone to learn time-invariant representations while preserving semantic cues for real changes. A dual-dimensional dynamic balancing strategy further stabilizes the adversarial optimization. Extensive experiments on WHU-CD, LEVIR-CD, SYSU-CD, and MSRSCD, together with backbone-universality analyses, demonstrate the effectiveness and robustness of DAANet under complex imaging conditions.

View source

Similar papers

2026

Dual-Domain Adversarial Purification for Robust Remote Sensing Scene Classification

Deep learning has boosted remote sensing (RS) scene classification, but adversarial examples can still cause high-confidence misclassification with imperceptible perturbations. Adversarial purification (AP) offers a practical test-time defense without retraining the classifier. However, most existing methods are confined to pixel-space restoration, which may leave residual adversarial effects that persist and amplify through feature extraction, ultimately biasing the prediction. To address these issues, a dual-domain AP (DDAP) framework is proposed to mitigate adversarial effects at both the pixel and feature levels in a unified pipeline. In the pixel domain, a pixel-domain frequency-aware diffusion purification (PFDP) module performs diffusion-based restoration through a frequency-aware dual-stream U-Net (FD-UNet). By integrating adaptive spectral filtering with multidomain consistency constraints, PFDP reduces adversarial-perturbation-dominated high-frequency responses while preserving structural details and semantic information in RS imagery. In the feature domain, an adversarial vulnerable channel dropout (AVCD) strategy models unshifted shallow-feature statistics with a Gaussian mixture model (GMM) and adaptively assigns channelwise dropout probabilities based on a samplewise shift score and channel vulnerability, thereby suppressing residual adversarial influence before downstream classification. Extensive experiments on UC Merced (UCM) and aerial image dataset (AID) across multiple backbones and attack types demonstrate that DDAP consistently improves robustness while maintaining a favorable clean–robust balance compared with representative baselines.

Yuru Su, Shaohui Mei, Mingyang Ma et al. · 0 citations
2026

Joint Adversarial and Subdomain Adaptation: A Dual-Strategy Framework for Robust Cross-Domain Modulation Recognition

While deep learning has significantly advanced automatic modulation recognition in complex environments, its performance is often limited by domain shifts caused by factors like channel fading and frequency offset. Domain adaptation has emerged as the primary paradigm to address this challenge. However, existing methods face a critical trade-off, as global alignment strategies tend to disrupt class-specific structures, while local alignment methods are overly sensitive to the quality of pseudo-labels. To address this trade-off, this paper proposes a joint adversarial and subdomain adaptation network (JASA-Net) centered on a dual domain adaptation (DDA) strategy. This strategy employs a “global-first, then-local” alignment ap-proach, where an initial global adversarial alignment establishes a strong foundation for generating high-quality pseudo-labels that subsequently guide a local alignment via the local maximum mean discrepancy (LMMD) metric. To extract robust features, we design a patch adaptive multimodal transformer (PAMT) encoder. Furthermore, an efficient “source domain warm-up + aggressive scheduling” training strategy is developed to enhance performance. Extensive experiments on custom-simulated datasets demonstrate that the proposed framework significantly outperforms representative baselines across various cross-domain tasks. Notably, it exhibits remarkable robustness in few-shot scenarios. This work also provides a critical analysis of the task-dependent nature of entropy weighting, offering valuable insights for future research in the field.

Ming Cheng, Wen Deng, Jintian Xiong et al. · 0 citations
Preprint Aug 2026

On the Adversarial Robustness of Remote Sensing Semantic Change Detection

Semantic change detection (SCD) is a bitemporal dense-prediction task that jointly identifies changed regions and their semantic states before and after change. Unlike single-image segmentation or binary change detection, SCD couples two temporal inputs with timestamp-wise semantic prediction, change localization, and final semantic-change decoding, creating adversarial dependencies that are not captured by conventional robustness protocols. We present a task-specific evaluation framework that separates output-side attack objectives from input-side temporal perturbation access, enabling systematic analysis of component vulnerability and cross-temporal propagation. Experiments on four datasets and six representative CNN-, Transformer-, and state-space-based models evaluate component-level and temporal objectives, single- and dual-timestamp perturbations, multiple attack methods, and cross-architecture transferability. The results show that final semantic-change predictions can be severely corrupted even when binary change localization remains comparatively stable, and that perturbations or attack objectives associated with one timestamp can propagate to the prediction of the other. These behaviors occur across different architecture families, while direct cross-model transfer remains considerably weaker than white-box attacks. The study demonstrates that adversarial robustness in SCD depends on the complete bitemporal prediction pathway rather than on an individual branch or backbone family, and provides a structured protocol for evaluating robustness in coupled bitemporal image analysis. Code is available at https://github.com/EricYu97/AdvSCD.

Weikang Yu, Yonghao Xu, Pedram Ghamisi · 0 citations
Preprint Aug 2026

Environment-Invariant Subspace Learning for Generalizable Deepfake Detection

This work proposes an innovative Environment-Invariant Subspace Learning (EISL) framework, which aims to disentangle features into orthogonal forgery-relevant invariant factors and environment-related residual factors via a learnable low-rank projection and designs an Environmental Intervention module that generates diverse and challenging intervention pairs.

Shenghao Chen, Hao Jia, Chen Li et al. · 0 citations

We use cookies to run the site and, with your consent, for analytics and to show ads. See our Cookie Policy.