Cloud Adversarial Example Generation for Remote Sensing Image Classification

Most existing adversarial attack methods for remote sensing images merely add adversarial perturbations or patches, resulting in visually unnatural modifications. Clouds are common atmospheric effects in remote sensing images. Generating clouds on these images can produce adversarial examples better aligning with human perception. In this article, we propose an adversarial attack framework that leverages natural cloud patterns as perturbations. Common Perlin noise-based cloud generation is a random, nonoptimizable process, which cannot be directly used to attack the target models. We design a Perlin gradient generator network (PGGN), which takes a compact gradient parameter vector (gradient vectors, coefficients, and scaling factors) as input and generates multiscale Perlin noise gradient grids. Through hierarchical computations, these grids produce scale-specific cloud masks, which are adaptively fused via learnable mixing coefficients and scaling factors. Crucially, the entire cloud generation process is formulated as a black-box optimization problem, where the cloud parameter vector is iteratively refined using the differential evolution (DE) algorithm. This approach enables query-efficient black-box attacks by directly aligning cloud shapes with adversarial objectives while preserving natural cloud textures. Comprehensive experiments demonstrate the strong attack capabilities of this method, along with its high query efficiency. Furthermore, we conduct an in-depth analysis of the transferability of the generated adversarial examples and their robustness in adversarial defense scenarios.

Paper

Similar papers

© 2026 NYSGPT2525 LLC