Abstract
Adversarial attacks constitute an effective means of evaluating model robustness and revealing intrinsic weaknesses. Since practical model deployment typically adheres to black-box settings, existing attack methods often employ multiple input transformations to enhance the transferability of adversarial examples. However, remote sensing images often exhibit ambiguous foreground-background distinctions and various geospatial discrepancies, resulting in high model specificity in discriminative cues for classification. Consequently, the input patterns simulated through fixed transformation schemes are insufficient to prevent overfitting to the source model, thereby limiting the transferability of the generated adversarial examples. To solve this issue, we propose a hierarchical transformation composition (HTC) framework that reinforces adversarial transferability through a coordinated action execution (CAE) strategy. Specifically, the determination of input transformations is formulated as an adaptive action selection procedure, which is progressively executed by multilevel policy networks. Then, the policy networks are iteratively updated via proximal policy optimization (PPO) based on the advantage estimates from a shared value network. Moreover, a hybrid reward mechanism (HRM) is introduced to dynamically integrate loss information from both feature and output layers. Rather than directly imposing directional constraints on gradient calculation, the supervision is shifted to the optimization of policy networks, which prevents the sacrifice of intrinsic attack capacity while enhancing transferability. Extensive experiments on the UCM and SIRI-WHU datasets demonstrate that the proposed method achieves state-of-the-art performance across various model architectures. The code will be released at https://github.com/fuyimin96/HTC upon acceptance.
| Original language | English |
|---|---|
| Article number | 5624715 |
| Journal | IEEE Transactions on Geoscience and Remote Sensing |
| Volume | 64 |
| DOIs | |
| State | Published - 2026 |
Keywords
- Adversarial attack
- hierarchical transformation composition (HTC)
- model robustness
- remote sensing
Fingerprint
Dive into the research topics of 'Transferability Reinforcement of Adversarial Attacks for Remote Sensing Image Classification via Hierarchical Transformation Composition'. Together they form a unique fingerprint.Cite this
- APA
- Author
- BIBTEX
- Harvard
- Standard
- RIS
- Vancouver