Please use this identifier to cite or link to this item: https://hdl.handle.net/10356/180881
Title: Pre-trained and sample-transferable perturbation based adversarial neuron manipulation: revealing the risks of transfer learning in remote sensing
Authors: Tian, Xingjian
Keywords: Computer and Information Science
Issue Date: 2024
Publisher: Nanyang Technological University
Source: Tian, X. (2024). Pre-trained and sample-transferable perturbation based adversarial neuron manipulation: revealing the risks of transfer learning in remote sensing. Master's thesis, Nanyang Technological University, Singapore. https://hdl.handle.net/10356/180881
Abstract: The classification of remote sensing images has been revolutionized by the advent of deep learning, particularly through the application of transfer learning techniques. However, the susceptibility of these models to adversarial attacks poses significant challenges. Existing adversarial attacks against transfer learning- based deep models always require domain-specific data or multiple interactions with the model, which are not always available and are of high computational complexity. This paper proposes a novel Adversarial Neuron Manipulation (ANM) method, which generates pre-trained and sample- transferable perturbations to craft adversarial examples. The pre-training process does not require domain-specific information, and these perturbations can be merged with any image that is not involved in the perturbation generation process to create adversarial examples, hence the adversarial neuron manipulation requires lower accessibility to the victim model and is more computationally efficient for the attacker. Experiments on different models with various remote sensing datasets demonstrate the effectiveness of the proposed attack method. By analyzing the vulnerabilities of deep models, perturbations that can manipulate multiple fragile neurons show better attack performance. This low-demand adversarial neuron manipulation attack reveals another risk of transfer learning models and needs to be addressed with more security and robustness measures.
URI: https://hdl.handle.net/10356/180881
Schools: School of Electrical and Electronic Engineering 
Research Centres: Satellite Research Centre
Fulltext Permission: restricted
Fulltext Availability: With Fulltext
Appears in Collections:EEE Theses

Files in This Item:
File Description SizeFormat 
Tian_xingjian_v8_final.pdf
  Restricted Access
2.82 MBAdobe PDFView/Open

Page view(s)

135
Updated on Mar 16, 2025

Download(s)

12
Updated on Mar 16, 2025

Google ScholarTM

Check

Items in DR-NTU are protected by copyright, with all rights reserved, unless otherwise indicated.