Skip to Main content Skip to Navigation
Preprints, Working Papers, ...

Generating natural adversarial Remote Sensing Images

Jean-Christophe Burnel 1 Kilian Fatras 1, 2 Rémi Flamary 3 Nicolas Courty 1
1 OBELIX - Observation de l’environnement par imagerie complexe
IRISA-D5 - SIGNAUX ET IMAGES NUMÉRIQUES, ROBOTIQUE
2 PANAMA - Parcimonie et Nouveaux Algorithmes pour le Signal et la Modélisation Audio
Inria Rennes – Bretagne Atlantique , IRISA-D5 - SIGNAUX ET IMAGES NUMÉRIQUES, ROBOTIQUE
Abstract : Over the last years, Remote Sensing Images (RSI) analysis have started resorting to using deep neural networks to solve most of the commonly faced problems, such as detection, land cover classification or segmentation. As far as critical decision making can be based upon the results of RSI analysis, it is important to clearly identify and understand potential security threats occurring in those machine learning algorithms. Notably, it has recently been found that neural networks are particularly sensitive to carefully designed attacks, generally crafted given the full knowledge of the considered deep network. In this paper, we consider the more realistic but challenging case where one wants to generate such attacks in the case of a black-box neural network. In this case, only the prediction score of the network is accessible, given a specific input. Examples that lure away the network's prediction, while being perceptually similar to real images, are called natural or unrestricted adversarial examples. We present an original method to generate such examples, based on a variant of the Wasserstein Generative Adversarial Network. We demonstrate its effectiveness on natural adversarial hyper-spectral image generation and image modification for fooling a state-of-the-art detector. Among others, we also conduct a perceptual evaluation with human annotators to better assess the effectiveness of the proposed method.
Complete list of metadatas

Cited literature [43 references]  Display  Hide  Download

https://hal.archives-ouvertes.fr/hal-02558542
Contributor : Kilian Fatras <>
Submitted on : Wednesday, April 29, 2020 - 4:47:15 PM
Last modification on : Tuesday, May 26, 2020 - 6:50:44 PM

File

ARGAN_TGRS_hal.pdf
Files produced by the author(s)

Identifiers

  • HAL Id : hal-02558542, version 1

Citation

Jean-Christophe Burnel, Kilian Fatras, Rémi Flamary, Nicolas Courty. Generating natural adversarial Remote Sensing Images. 2020. ⟨hal-02558542⟩

Share

Metrics

Record views

122

Files downloads

80