An Improved Mixup Attack for Directed Attack Image Classification Models
ZHU Rui
MA Shiping
HE Linyuan
MEI Shaohui
Abstract:In this paper,a directional attack black-box attack method named improved mixup attack(IMA)method is designed aimed at the current problems that researches on adversarial examples of targeted at-tacks are less,and black-box attack capability is very weak in remote sensing image classification.The method aims to directionally fool the classification model out of the deep neural network,discover its vul-nerable parts,and enable our high-value target to be detected as a low or no-value target.The method,first-ly,is used to extract the shallow global features of the image by an image classification deep learning mod-el,and is used to realize the targeted attack for changing the input image pixels to approximate the shallow features of the input clean image to the target image.After that,an adaptive control of the iteration step size is designed to improve the efficiency of the iteration and the transferability of the attack.Simultaneous-ly,the idea of model hierarchy is introduced by using multiple models with different architectures as surro-gate models,so that the generated adversarial examples have both multi-model features to improve the transferability of the attack.Finally,several models are tested on several remote sensing classification data-sets,and the experimental results show that the proposed method is valid.
Keywords:image classificationtargeted attackremote sensing imagemodel hierarchy
Publication Date:2025-02-24
Online Publishing Date:2025-08-15(First online date of this platform, not the publication date of the document)
Pages:10( 32-41 )
