On the Adversarial Vulnerabilities of Transfer Learning in Remote Sensing

Fuente: arXiv
Saved in:
Bibliographic Details
Main Authors: Bai, Tao, Tian, Xingjian, Xu, Yonghao, Wen, Bihan
Format: Preprint
Published: 2025
Subjects:
Online Access:
Tags: Add Tag
No Tags, Be the first to tag this record!
_version_ 1866917077094236160
author Bai, Tao
Tian, Xingjian
Xu, Yonghao
Wen, Bihan
author_facet Bai, Tao
Tian, Xingjian
Xu, Yonghao
Wen, Bihan
contents The use of pretrained models from general computer vision tasks is widespread in remote sensing, significantly reducing training costs and improving performance. However, this practice also introduces vulnerabilities to downstream tasks, where publicly available pretrained models can be used as a proxy to compromise downstream models. This paper presents a novel Adversarial Neuron Manipulation method, which generates transferable perturbations by selectively manipulating single or multiple neurons in pretrained models. Unlike existing attacks, this method eliminates the need for domain-specific information, making it more broadly applicable and efficient. By targeting multiple fragile neurons, the perturbations achieve superior attack performance, revealing critical vulnerabilities in deep learning models. Experiments on diverse models and remote sensing datasets validate the effectiveness of the proposed method. This low-access adversarial neuron manipulation technique highlights a significant security risk in transfer learning models, emphasizing the urgent need for more robust defenses in their design when addressing the safety-critical remote sensing tasks.
format Preprint
id arxiv_https___arxiv_org_abs_2501_11462
institution arXiv
publishDate 2025
record_format arxiv
spellingShingle On the Adversarial Vulnerabilities of Transfer Learning in Remote Sensing
Bai, Tao
Tian, Xingjian
Xu, Yonghao
Wen, Bihan
Computer Vision and Pattern Recognition
Image and Video Processing
The use of pretrained models from general computer vision tasks is widespread in remote sensing, significantly reducing training costs and improving performance. However, this practice also introduces vulnerabilities to downstream tasks, where publicly available pretrained models can be used as a proxy to compromise downstream models. This paper presents a novel Adversarial Neuron Manipulation method, which generates transferable perturbations by selectively manipulating single or multiple neurons in pretrained models. Unlike existing attacks, this method eliminates the need for domain-specific information, making it more broadly applicable and efficient. By targeting multiple fragile neurons, the perturbations achieve superior attack performance, revealing critical vulnerabilities in deep learning models. Experiments on diverse models and remote sensing datasets validate the effectiveness of the proposed method. This low-access adversarial neuron manipulation technique highlights a significant security risk in transfer learning models, emphasizing the urgent need for more robust defenses in their design when addressing the safety-critical remote sensing tasks.
title On the Adversarial Vulnerabilities of Transfer Learning in Remote Sensing
topic Computer Vision and Pattern Recognition
Image and Video Processing
url https://arxiv.org/abs/2501.11462