TY - JOUR
T1 - Transferability Reinforcement of Adversarial Attacks for Remote Sensing Image Classification via Hierarchical Transformation Composition
AU - Fu, Yimin
AU - Bai, Yuefeng
AU - Lyu, Jialin
AU - Pan, Baicheng
AU - Liu, Zhunga
AU - Ng, Michael K.
N1 - Publisher Copyright:
© 2026 IEEE.
PY - 2026
Y1 - 2026
N2 - Adversarial attacks constitute an effective means of evaluating model robustness and revealing intrinsic weaknesses. Since practical model deployment typically adheres to black-box settings, existing attack methods often employ multiple input transformations to enhance the transferability of adversarial examples. However, remote sensing images often exhibit ambiguous foreground-background distinctions and various geospatial discrepancies, resulting in high model specificity in discriminative cues for classification. Consequently, the input patterns simulated through fixed transformation schemes are insufficient to prevent overfitting to the source model, thereby limiting the transferability of the generated adversarial examples. To solve this issue, we propose a hierarchical transformation composition (HTC) framework that reinforces adversarial transferability through a coordinated action execution (CAE) strategy. Specifically, the determination of input transformations is formulated as an adaptive action selection procedure, which is progressively executed by multilevel policy networks. Then, the policy networks are iteratively updated via proximal policy optimization (PPO) based on the advantage estimates from a shared value network. Moreover, a hybrid reward mechanism (HRM) is introduced to dynamically integrate loss information from both feature and output layers. Rather than directly imposing directional constraints on gradient calculation, the supervision is shifted to the optimization of policy networks, which prevents the sacrifice of intrinsic attack capacity while enhancing transferability. Extensive experiments on the UCM and SIRI-WHU datasets demonstrate that the proposed method achieves state-of-the-art performance across various model architectures. The code will be released at https://github.com/fuyimin96/HTC upon acceptance.
AB - Adversarial attacks constitute an effective means of evaluating model robustness and revealing intrinsic weaknesses. Since practical model deployment typically adheres to black-box settings, existing attack methods often employ multiple input transformations to enhance the transferability of adversarial examples. However, remote sensing images often exhibit ambiguous foreground-background distinctions and various geospatial discrepancies, resulting in high model specificity in discriminative cues for classification. Consequently, the input patterns simulated through fixed transformation schemes are insufficient to prevent overfitting to the source model, thereby limiting the transferability of the generated adversarial examples. To solve this issue, we propose a hierarchical transformation composition (HTC) framework that reinforces adversarial transferability through a coordinated action execution (CAE) strategy. Specifically, the determination of input transformations is formulated as an adaptive action selection procedure, which is progressively executed by multilevel policy networks. Then, the policy networks are iteratively updated via proximal policy optimization (PPO) based on the advantage estimates from a shared value network. Moreover, a hybrid reward mechanism (HRM) is introduced to dynamically integrate loss information from both feature and output layers. Rather than directly imposing directional constraints on gradient calculation, the supervision is shifted to the optimization of policy networks, which prevents the sacrifice of intrinsic attack capacity while enhancing transferability. Extensive experiments on the UCM and SIRI-WHU datasets demonstrate that the proposed method achieves state-of-the-art performance across various model architectures. The code will be released at https://github.com/fuyimin96/HTC upon acceptance.
KW - Adversarial attack
KW - hierarchical transformation composition (HTC)
KW - model robustness
KW - remote sensing
UR - https://www.scopus.com/pages/publications/105040993667
U2 - 10.1109/TGRS.2026.3698932
DO - 10.1109/TGRS.2026.3698932
M3 - 文章
AN - SCOPUS:105040993667
SN - 0196-2892
VL - 64
JO - IEEE Transactions on Geoscience and Remote Sensing
JF - IEEE Transactions on Geoscience and Remote Sensing
M1 - 5624715
ER -