Skip to main navigation Skip to search Skip to main content

Dual-Domain Adversarial Purification for Robust Remote Sensing Scene Classification

  • Northwestern Polytechnical University Xian

Research output: Contribution to journalArticlepeer-review

Abstract

Deep learning has boosted remote sensing (RS) scene classification, but adversarial examples can still cause high-confidence misclassification with imperceptible perturbations. Adversarial purification offers a practical test-time defense without retraining the classifier. However, most existing methods are confined to pixel-space restoration, which may leave residual adversarial effects that persist and amplify through feature extraction, ultimately biasing the prediction. To address these issues, a Dual-Domain Adversarial Purification (DDAP) framework is proposed to mitigate adversarial effects at both the pixel and feature levels in a unified pipeline. In the pixel domain, a Pixel-Domain Frequency-Aware Diffusion Purification (PFDP) module performs diffusion-based restoration through a Frequency-Aware Dual-Stream U-Net (FD-UNet). By integrating adaptive spectral filtering with multi-domain consistency constraints, PFDP reduces adversarial-perturbation-dominated high-frequency responses while preserving structural details and semantic information in RS imagery. In the feature domain, an Adversarial Vulnerable Channel Dropout (AVCD) strategy models unshifted shallow-feature statistics with a Gaussian Mixture Model and adaptively assigns channel-wise dropout probabilities based on a sample-wise shift score and channel vulnerability, thereby suppressing residual adversarial influence before downstream classification. Extensive experiments on UCM and AID across multiple backbones and attack types demonstrate that DDAP consistently improves robustness while maintaining a favorable clean–robust balance compared with representative baselines.

Original languageEnglish
JournalIEEE Transactions on Geoscience and Remote Sensing
DOIs
StateAccepted/In press - 2026

Keywords

  • adversarial purification
  • Adversarial robustness
  • diffusion models
  • Gaussian mixture model

Fingerprint

Dive into the research topics of 'Dual-Domain Adversarial Purification for Robust Remote Sensing Scene Classification'. Together they form a unique fingerprint.

Cite this