arXivDaily arXiv每日学术速递 周一至周五更新
arXiv周末暂无论文更新,休息一下吧,周末愉快~~

遥感语义变化检测的对抗鲁棒性研究

On the Adversarial Robustness of Remote Sensing Semantic Change Detection

Weikang Yu, Yonghao Xu, Pedram Ghamisi

arXiv 2608.15267首次发表:更新:

发表机构

Linköping University; Helmholtz Institute Freiberg for Resource Technology; Helmholtz-Zentrum Dresden-Rossendorf(林雪平大学; 弗赖贝格亥姆霍兹资源技术研究所; 德累斯顿-罗森多夫亥姆霍兹中心)

机构由 AI 辅助整理,请以论文原文为准。

AI 中文总结

本研究针对遥感语义变化检测任务,提出分离输出侧攻击目标与输入侧时序扰动的评估框架,经多数据集、多模型实验,揭示其对抗鲁棒性依赖完整双时序预测通路,为耦合双时序图像分析提供鲁棒性评估协议。

AI 中文摘要

语义变化检测(Semantic Change Detection, SCD)是一种双时序密集预测任务,需同时识别变化区域及其变化前后的语义状态。与单图像分割或二值变化检测不同,SCD将两个时序输入与时序语义预测、变化定位及最终语义变化解码相结合,形成了常规鲁棒性协议未覆盖的对抗依赖关系。本文提出一种任务特定的评估框架,将输出侧攻击目标与输入侧时序扰动访问分离,实现对组件脆弱性及时序传播的系统分析。在四个数据集和六个代表性的CNN、Transformer及状态空间模型上开展实验,评估了组件级及时序目标、单及时序戳扰动、多种攻击方法及跨架构可迁移性。结果表明,即使二值变化定位保持相对稳定,最终语义变化预测仍可能被严重破坏;与一个时序相关的扰动或攻击目标可传播至另一时序的预测,该现象在不同架构族中均存在,而直接跨模型迁移性远弱于白盒攻击。本研究证明SCD的对抗鲁棒性依赖于完整的双时序预测通路,而非单个分支或骨干网络族,并为耦合双时序图像分析的鲁棒性评估提供了结构化协议。代码可访问此https URL。

英文摘要

Semantic change detection (SCD) is a bitemporal dense-prediction task that jointly identifies changed regions and their semantic states before and after change. Unlike single-image segmentation or binary change detection, SCD couples two temporal inputs with timestamp-wise semantic prediction, change localization, and final semantic-change decoding, creating adversarial dependencies that are not captured by conventional robustness protocols. We present a task-specific evaluation framework that separates output-side attack objectives from input-side temporal perturbation access, enabling systematic analysis of component vulnerability and cross-temporal propagation. Experiments on four datasets and six representative CNN-, Transformer-, and state-space-based models evaluate component-level and temporal objectives, single- and dual-timestamp perturbations, multiple attack methods, and cross-architecture transferability. The results show that final semantic-change predictions can be severely corrupted even when binary change localization remains comparatively stable, and that perturbations or attack objectives associated with one timestamp can propagate to the prediction of the other. These behaviors occur across different architecture families, while direct cross-model transfer remains considerably weaker than white-box attacks. The study demonstrates that adversarial robustness in SCD depends on the complete bitemporal prediction pathway rather than on an individual branch or backbone family, and provides a structured protocol for evaluating robustness in coupled bitemporal image analysis. Code is available at https://github.com/EricYu97/AdvSCD.

论文原文

arXiv 摘要页 · PDF 原文 · HTML 原文

↑