Skip to content
Open access

DPSF: A Dynamic Patch Shape Selection Framework for Cross-Model Transferable Adversarial Attacks

Jul 2026 · Remote Sensing · 0 citations · 44 references

Abstract

Adversarial patch attacks are core tools to evaluate adversarial robustness in remote sensing image classification, yet existing methods with fixed patch shapes and single-model optimization yield poor cross-architecture black-box transferability. This paper proposes the Dynamic Patch Shape Selection Framework (DPSF), which integrates a 12-shape patch library, adaptive category matching and multi-model joint optimization with dynamic weight adjustment under a strict 2% patch area constraint. We test DPSF on the UC Merced dataset over eight random split seeds, taking ResNet101, DenseNet161 and VGG19 as held-out black-box models. Under the five-source protocol, DPSF-full achieves mean accuracy drop (ACCD) of 0.380 ± 0.034, adversarial accuracy (Adv Acc) 0.593 ± 0.039, attack success rate (ASR) 0.393 ± 0.037 (on clean-correct test samples, averaged over held-out evaluators), union success rate (USR) 0.581  ±  0.046, and intersection success rate (ISR) 0.188  ±  0.023. With the ResNet50 single-source setting, DPSF-single obtains mean ACCD = 0.275  ±  0.109, surpassing Sparse-RS (0.033  ±  0.012) and Cross-shaped adversarial patch attack (CSPA) (0.232 ± 0.029). Supplementary results on CIFAR-10, Tiny-ImageNet and Mini-ImageNet illustrate cross-scale transfer trends. This work builds a reproducible digital-domain robustness benchmark for aerial land-use scene classification.

Read PDF

We use cookies to run the site and, with your consent, for analytics and to show ads. See our Cookie Policy.