{"status":"ok","message-type":"work","message-version":"1.0.0","message":{"indexed":{"date-parts":[[2026,7,8]],"date-time":"2026-07-08T16:34:06Z","timestamp":1783528446773,"version":"3.55.0"},"reference-count":50,"publisher":"MDPI AG","issue":"15","license":[{"start":{"date-parts":[[2022,7,25]],"date-time":"2022-07-25T00:00:00Z","timestamp":1658707200000},"content-version":"vor","delay-in-days":0,"URL":"https:\/\/creativecommons.org\/licenses\/by\/4.0\/"}],"funder":[{"DOI":"10.13039\/501100001809","name":"National Natural Science Foundation of China","doi-asserted-by":"publisher","award":["62073165"],"award-info":[{"award-number":["62073165"]}],"id":[{"id":"10.13039\/501100001809","id-type":"DOI","asserted-by":"publisher"}]},{"DOI":"10.13039\/501100001809","name":"National Natural Science Foundation of China","doi-asserted-by":"publisher","award":["NJ2022025-3"],"award-info":[{"award-number":["NJ2022025-3"]}],"id":[{"id":"10.13039\/501100001809","id-type":"DOI","asserted-by":"publisher"}]},{"DOI":"10.13039\/501100001809","name":"National Natural Science Foundation of China","doi-asserted-by":"publisher","award":["NJ2022025"],"award-info":[{"award-number":["NJ2022025"]}],"id":[{"id":"10.13039\/501100001809","id-type":"DOI","asserted-by":"publisher"}]},{"name":"Key Laboratory of Space Photoelectric Detection and Perception (Nanjing University of Aeronautics and Astronautics)","award":["62073165"],"award-info":[{"award-number":["62073165"]}]},{"name":"Key Laboratory of Space Photoelectric Detection and Perception (Nanjing University of Aeronautics and Astronautics)","award":["NJ2022025-3"],"award-info":[{"award-number":["NJ2022025-3"]}]},{"name":"Key Laboratory of Space Photoelectric Detection and Perception (Nanjing University of Aeronautics and Astronautics)","award":["NJ2022025"],"award-info":[{"award-number":["NJ2022025"]}]},{"name":"Ministry of Industry and Information Technology","award":["62073165"],"award-info":[{"award-number":["62073165"]}]},{"name":"Ministry of Industry and Information Technology","award":["NJ2022025-3"],"award-info":[{"award-number":["NJ2022025-3"]}]},{"name":"Ministry of Industry and Information Technology","award":["NJ2022025"],"award-info":[{"award-number":["NJ2022025"]}]},{"DOI":"10.13039\/501100012226","name":"Fundamental Research Funds for the Central Universities","doi-asserted-by":"publisher","award":["62073165"],"award-info":[{"award-number":["62073165"]}],"id":[{"id":"10.13039\/501100012226","id-type":"DOI","asserted-by":"publisher"}]},{"DOI":"10.13039\/501100012226","name":"Fundamental Research Funds for the Central Universities","doi-asserted-by":"publisher","award":["NJ2022025-3"],"award-info":[{"award-number":["NJ2022025-3"]}],"id":[{"id":"10.13039\/501100012226","id-type":"DOI","asserted-by":"publisher"}]},{"DOI":"10.13039\/501100012226","name":"Fundamental Research Funds for the Central Universities","doi-asserted-by":"publisher","award":["NJ2022025"],"award-info":[{"award-number":["NJ2022025"]}],"id":[{"id":"10.13039\/501100012226","id-type":"DOI","asserted-by":"publisher"}]}],"content-domain":{"domain":[],"crossmark-restriction":false},"short-container-title":["Remote Sensing"],"abstract":"<jats:p>Deep neural networks have been widely used in detection tasks based on optical remote sensing images. However, in recent studies, deep neural networks have been shown to be vulnerable to adversarial examples. Adversarial examples are threatening in both the digital and physical domains. Specifically, they make it possible for adversarial examples to attack aerial remote sensing detection. To defend against adversarial attacks on aerial remote sensing detection, we propose a cascaded adversarial defense framework, which locates the adversarial patch according to its high frequency and saliency information in the gradient domain and removes it directly. The original image semantic and texture information is then restored by the image inpainting method. When combined with the random erasing algorithm, the robustness of detection is further improved. Our method is the first attempt to defend against adversarial examples in remote sensing detection. The experimental results show that our method is very effective in defending against real-world adversarial attacks. In particular, when using the YOLOv3 and YOLOv4 algorithms for robust detection of single-class targets, the AP60 of YOLOv3 and YOLOv4 only drop by 2.11% and 2.17%, respectively, under the adversarial example.<\/jats:p>","DOI":"10.3390\/rs14153559","type":"journal-article","created":{"date-parts":[[2022,7,26]],"date-time":"2022-07-26T00:17:27Z","timestamp":1658794647000},"page":"3559","update-policy":"https:\/\/doi.org\/10.3390\/mdpi_crossmark_policy","source":"Crossref","is-referenced-by-count":6,"title":["A Cascade Defense Method for Multidomain Adversarial Attacks under Remote Sensing Detection"],"prefix":"10.3390","volume":"14","author":[{"ORCID":"https:\/\/orcid.org\/0000-0002-7551-1804","authenticated-orcid":false,"given":"Wei","family":"Xue","sequence":"first","affiliation":[{"name":"College of Astronautics, Nanjing University of Aeronautics and Astronautics, Nanjing 210016, China"}],"role":[{"vocabulary":"crossref","role":"author"}]},{"ORCID":"https:\/\/orcid.org\/0000-0002-8771-4051","authenticated-orcid":false,"given":"Zhiming","family":"Chen","sequence":"additional","affiliation":[{"name":"College of Astronautics, Nanjing University of Aeronautics and Astronautics, Nanjing 210016, China"}],"role":[{"vocabulary":"crossref","role":"author"}]},{"given":"Weiwei","family":"Tian","sequence":"additional","affiliation":[{"name":"College of Astronautics, Nanjing University of Aeronautics and Astronautics, Nanjing 210016, China"}],"role":[{"vocabulary":"crossref","role":"author"}]},{"ORCID":"https:\/\/orcid.org\/0000-0002-7012-1559","authenticated-orcid":false,"given":"Yunhua","family":"Wu","sequence":"additional","affiliation":[{"name":"College of Astronautics, Nanjing University of Aeronautics and Astronautics, Nanjing 210016, China"},{"name":"Key Laboratory of Space Photoelectric Detection and Perception, Ministry of Industry and Information Technology, Nanjing University of Aeronautics and Astronautics, Nanjing 210016, China"}],"role":[{"vocabulary":"crossref","role":"author"}]},{"given":"Bing","family":"Hua","sequence":"additional","affiliation":[{"name":"College of Astronautics, Nanjing University of Aeronautics and Astronautics, Nanjing 210016, China"}],"role":[{"vocabulary":"crossref","role":"author"}]}],"member":"1968","published-online":{"date-parts":[[2022,7,25]]},"reference":[{"key":"ref_1","unstructured":"Van Etten, A. (2018). You only look twice: Rapid multi-scale object detection in satellite imagery. arXiv."},{"key":"ref_2","doi-asserted-by":"crossref","unstructured":"Guo, W., Yang, W., Zhang, H., and Hua, G. (2018). Geospatial object detection in high resolution satellite images based on multi-scale convolutional neural network. Remote Sens., 10.","DOI":"10.3390\/rs10010131"},{"key":"ref_3","doi-asserted-by":"crossref","first-page":"1797","DOI":"10.1109\/LGRS.2014.2309695","article-title":"Vehicle detection in satellite images by hybrid deep convolutional neural networks","volume":"11","author":"Chen","year":"2014","journal-title":"IEEE Geosci. Remote Sens. Lett."},{"key":"ref_4","doi-asserted-by":"crossref","first-page":"676","DOI":"10.1109\/LGRS.2019.2930308","article-title":"Vehicle detection in remote sensing images leveraging on simultaneous super-resolution","volume":"17","author":"Ji","year":"2019","journal-title":"IEEE Geosci. Remote Sens. Lett."},{"key":"ref_5","doi-asserted-by":"crossref","unstructured":"Shermeyer, J., and Van Etten, A. (2019, January 15\u201320). The effects of super-resolution on object detection performance in satellite imagery. Proceedings of the IEEE\/CVF Conference on Computer Vision and Pattern Recognition Workshops, Long Beach, CA, USA.","DOI":"10.1109\/CVPRW.2019.00184"},{"key":"ref_6","doi-asserted-by":"crossref","unstructured":"Kim, J., and Cho, J. (2021). RGDiNet: Efficient Onboard Object Detection with Faster R-CNN for Air-to-Ground Surveillance. Sensors, 21.","DOI":"10.3390\/s21051677"},{"key":"ref_7","unstructured":"Szegedy, C., Zaremba, W., Sutskever, I., Bruna, J., Erhan, D., Goodfellow, I., and Fergus, R. (2013). Intriguing properties of neural networks. arXiv."},{"key":"ref_8","unstructured":"Goodfellow, I.J., Shlens, J., and Szegedy, C. (2014). Explaining and harnessing adversarial examples. arXiv."},{"key":"ref_9","unstructured":"Tram\u00e8r, F., Papernot, N., Goodfellow, I., Boneh, D., and McDaniel, P. (2017). The space of transferable adversarial examples. arXiv."},{"key":"ref_10","doi-asserted-by":"crossref","first-page":"828","DOI":"10.1109\/TEVC.2019.2890858","article-title":"One pixel attack for fooling deep neural networks","volume":"23","author":"Su","year":"2019","journal-title":"IEEE Trans. Evol. Comput."},{"key":"ref_11","unstructured":"Madry, A., Makelov, A., Schmidt, L., Tsipras, D., and Vladu, A. (2017). Towards deep learning models resistant to adversarial attacks. arXiv."},{"key":"ref_12","doi-asserted-by":"crossref","unstructured":"Carlini, N., and Wagner, D. (2017, January 22\u201326). Towards evaluating the robustness of neural networks. Proceedings of the 2017 IEEE Symposium on Security and Privacy (sp), San Jose, CA, USA.","DOI":"10.1109\/SP.2017.49"},{"key":"ref_13","unstructured":"Athalye, A., Engstrom, L., Ilyas, A., and Kwok, K. (2018, January 10\u201315). Synthesizing robust adversarial examples. Proceedings of the International Conference on Machine Learning, PMLR, Stockholm, Sweden."},{"key":"ref_14","unstructured":"Brown, T.B., Man\u00e9, D., Roy, A., Abadi, M., and Gilmer, J. (2017). Adversarial patch. arXiv."},{"key":"ref_15","unstructured":"Liu, X., Yang, H., Liu, Z., Song, L., Li, H., and Chen, Y. (2018). Dpatch: An adversarial patch attack on object detectors. arXiv."},{"key":"ref_16","doi-asserted-by":"crossref","unstructured":"Den Hollander, R., Adhikari, A., Tolios, I., van Bekkum, M., Bal, A., Hendriks, S., Kruithof, M., Gross, D., Jansen, N., and Perez, G. (2020, January 21\u201325). Adversarial patch camouflage against aerial detection. Proceedings of the Artificial Intelligence and Machine Learning in Defense Applications II, Online.","DOI":"10.1117\/12.2575907"},{"key":"ref_17","doi-asserted-by":"crossref","unstructured":"Duan, R., Mao, X., Qin, A.K., Chen, Y., Ye, S., He, Y., and Yang, Y. (2021, January 20\u201325). Adversarial laser beam: Effective physical-world attack to DNNs in a blink. Proceedings of the IEEE\/CVF Conference on Computer Vision and Pattern Recognition, Nashville, TN, USA.","DOI":"10.1109\/CVPR46437.2021.01580"},{"key":"ref_18","doi-asserted-by":"crossref","unstructured":"Kaziakhmedov, E., Kireev, K., Melnikov, G., Pautov, M., and Petiushko, A. (2019, January 21\u201322). Real-world attack on MTCNN face detection system. Proceedings of the 2019 International Multi-Conference on Engineering, Computer and Information Sciences (SIBIRCON), Academpark, Russia.","DOI":"10.1109\/SIBIRCON48586.2019.8958122"},{"key":"ref_19","doi-asserted-by":"crossref","unstructured":"Wu, Z., Lim, S.N., Davis, L.S., and Goldstein, T. (2020, January 23\u201328). Making an invisibility cloak: Real world adversarial attacks on object detectors. Proceedings of the European Conference on Computer Vision, Glasgow, UK.","DOI":"10.1007\/978-3-030-58548-8_1"},{"key":"ref_20","doi-asserted-by":"crossref","unstructured":"Huang, L., Gao, C., Zhou, Y., Xie, C., Yuille, A.L., Zou, C., and Liu, N. (2020, January 13\u201319). Universal physical camouflage attacks on object detectors. Proceedings of the IEEE\/CVF Conference on Computer Vision and Pattern Recognition, Seattle, WA, USA.","DOI":"10.1109\/CVPR42600.2020.00080"},{"key":"ref_21","doi-asserted-by":"crossref","unstructured":"Wang, J., Liu, A., Yin, Z., Liu, S., Tang, S., and Liu, X. (2021, January 20\u201325). Dual attention suppression attack: Generate adversarial camouflage in physical world. Proceedings of the IEEE\/CVF Conference on Computer Vision and Pattern Recognition, Nashville, TN, USA.","DOI":"10.1109\/CVPR46437.2021.00846"},{"key":"ref_22","doi-asserted-by":"crossref","unstructured":"Thys, S., Van Ranst, W., and Goedem\u00e9, T. (2019, January 16\u201317). Fooling automated surveillance cameras: Adversarial patches to attack person detection. Proceedings of the IEEE\/CVF Conference on Computer Vision and Pattern Recognition Workshops, Long Beach, CA, USA.","DOI":"10.1109\/CVPRW.2019.00012"},{"key":"ref_23","unstructured":"Hoory, S., Shapira, T., Shabtai, A., and Elovici, Y. (2020). Dynamic adversarial patch for evading object detection models. arXiv."},{"key":"ref_24","doi-asserted-by":"crossref","unstructured":"Chen, S.T., Cornelius, C., Martin, J., and Chau, D.H.P. (2018, January 10\u201314). Shapeshifter: Robust physical adversarial attack on faster r-cnn object detector. Proceedings of the Joint European Conference on Machine Learning and Knowledge Discovery in Databases, Dublin, Ireland.","DOI":"10.1007\/978-3-030-10925-7_4"},{"key":"ref_25","unstructured":"Dziugaite, G.K., Ghahramani, Z., and Roy, D.M. (2016). A study of the effect of jpg compression on adversarial images. arXiv."},{"key":"ref_26","unstructured":"Das, N., Shanbhogue, M., Chen, S.T., Hohman, F., Chen, L., Kounavis, M.E., and Chau, D.H. (2017). Keeping the bad guys out: Protecting and vaccinating deep learning with jpeg compression. arXiv."},{"key":"ref_27","doi-asserted-by":"crossref","unstructured":"Liao, F., Liang, M., Dong, Y., Pang, T., Hu, X., and Zhu, J. (2018, January 18\u201323). Defense against adversarial attacks using high-level representation guided denoiser. Proceedings of the IEEE Conference on Computer Vision and Pattern Recognition, Salt Lake City, UT, USA.","DOI":"10.1109\/CVPR.2018.00191"},{"key":"ref_28","doi-asserted-by":"crossref","first-page":"2640","DOI":"10.1109\/TIFS.2017.2718479","article-title":"No bot expects the DeepCAPTCHA! Introducing immutable adversarial examples, with applications to CAPTCHA generation","volume":"12","author":"Osadchy","year":"2017","journal-title":"IEEE Trans. Inf. Forensics Secur."},{"key":"ref_29","doi-asserted-by":"crossref","unstructured":"Papernot, N., McDaniel, P., Wu, X., Jha, S., and Swami, A. (2016, January 22\u201326). Distillation as a defense to adversarial perturbations against deep neural networks. Proceedings of the 2016 IEEE Symposium on Security and Privacy (SP), San Jose, CA, USA.","DOI":"10.1109\/SP.2016.41"},{"key":"ref_30","unstructured":"Hinton, G., Vinyals, O., and Dean, J. (2015). Distilling the knowledge in a neural network. arXiv."},{"key":"ref_31","unstructured":"Song, Y., Kim, T., Nowozin, S., Ermon, S., and Kushman, N. (2017). Pixeldefend: Leveraging generative models to understand and defend against adversarial examples. arXiv."},{"key":"ref_32","unstructured":"Samangouei, P., Kabkab, M., and Chellappa, R. (2018). Defense-gan: Protecting classifiers against adversarial attacks using generative models. arXiv."},{"key":"ref_33","unstructured":"Lee, H., Han, S., and Lee, J. (2017). Generative adversarial trainer: Defense to adversarial perturbations with gan. arXiv."},{"key":"ref_34","unstructured":"Athalye, A., Carlini, N., and Wagner, D. (2018, January 10\u201315). Obfuscated gradients give a false sense of security: Circumventing defenses to adversarial examples. Proceedings of the International Conference on Machine Learning, Stockholm, Sweden."},{"key":"ref_35","doi-asserted-by":"crossref","unstructured":"Zhang, H., and Wang, J. (2019, January 27\u201328). Towards adversarially robust object detection. Proceedings of the IEEE\/CVF International Conference on Computer Vision, Seoul, Korea.","DOI":"10.1109\/ICCV.2019.00051"},{"key":"ref_36","doi-asserted-by":"crossref","unstructured":"Papernot, N., McDaniel, P., Jha, S., Fredrikson, M., Celik, Z.B., and Swami, A. (2016, January 21\u201324). The limitations of deep learning in adversarial settings. Proceedings of the 2016 IEEE European Symposium on Security and Privacy (EuroS&P), Saarbruecken, Germany.","DOI":"10.1109\/EuroSP.2016.36"},{"key":"ref_37","doi-asserted-by":"crossref","unstructured":"Moosavi-Dezfooli, S.M., Fawzi, A., Fawzi, O., and Frossard, P. (2017, January 21\u201326). Universal adversarial perturbations. Proceedings of the IEEE Conference on Computer Vision and Pattern Recognition, Honolulu, HI, USA.","DOI":"10.1109\/CVPR.2017.17"},{"key":"ref_38","unstructured":"Lu, J., Sibai, H., Fabry, E., and Forsyth, D. (2017). No need to worry about adversarial examples in object detection in autonomous vehicles. arXiv."},{"key":"ref_39","doi-asserted-by":"crossref","unstructured":"Sharif, M., Bhagavatula, S., Bauer, L., and Reiter, M.K. (2016, January 24\u201328). Accessorize to a crime: Real and stealthy attacks on state-of-the-art face recognition. Proceedings of the 2016 ACM Sigsac Conference on Computer and Communications Security, Vienna, Austria.","DOI":"10.1145\/2976749.2978392"},{"key":"ref_40","doi-asserted-by":"crossref","unstructured":"Du, A., Chen, B., Chin, T.J., Law, Y.W., Sasdelli, M., Rajasegaran, R., and Campbell, D. (2022, January 4\u20138). Physical adversarial attacks on an aerial imagery object detector. Proceedings of the IEEE\/CVF Winter Conference on Applications of Computer Vision, Waikoloa, HI, USA.","DOI":"10.1109\/WACV51458.2022.00385"},{"key":"ref_41","doi-asserted-by":"crossref","unstructured":"Naseer, M., Khan, S., and Porikli, F. (2019, January 7\u201311). Local gradients smoothing: Defense against localized adversarial attacks. Proceedings of the 2019 IEEE Winter Conference on Applications of Computer Vision (WACV), Waikoloa Village, HI, USA.","DOI":"10.1109\/WACV.2019.00143"},{"key":"ref_42","doi-asserted-by":"crossref","unstructured":"Hayes, J. (2018, January 18\u201322). On visible adversarial perturbations & digital watermarking. Proceedings of the IEEE Conference on Computer Vision and Pattern Recognition Workshops, Salt Lake City, UT, USA.","DOI":"10.1109\/CVPRW.2018.00210"},{"key":"ref_43","unstructured":"Chiang, P.Y., Ni, R., Abdelkader, A., Zhu, C., Studer, C., and Goldstein, T. (2020). Certified defenses for adversarial patches. arXiv."},{"key":"ref_44","unstructured":"Xiang, C., Bhagoji, A.N., Sehwag, V., and Mittal, P. (2021, January 11\u201313). {PatchGuard}: A Provably Robust Defense against Adversarial Patches via Small Receptive Fields and Masking. Proceedings of the 30th USENIX Security Symposium (USENIX Security 21), Virtual."},{"key":"ref_45","unstructured":"Bao, J., Chen, J., Ma, H., Ma, H., Yu, C., and Huang, Y. (November, January 29). Improving Adversarial Robustness of Detector via Objectness Regularization. Proceedings of the Chinese Conference on Pattern Recognition and Computer Vision (PRCV), Beijing, China."},{"key":"ref_46","doi-asserted-by":"crossref","first-page":"23","DOI":"10.1080\/10867651.2004.10487596","article-title":"An image inpainting technique based on the fast marching method","volume":"9","author":"Telea","year":"2004","journal-title":"J. Graph. Tools"},{"key":"ref_47","doi-asserted-by":"crossref","unstructured":"Yu, J., Lin, Z., Yang, J., Shen, X., Lu, X., and Huang, T.S. (2018, January 18\u201323). Generative image inpainting with contextual attention. Proceedings of the IEEE Conference on Computer Vision and Pattern Recognition, Salt Lake City, UT, USA.","DOI":"10.1109\/CVPR.2018.00577"},{"key":"ref_48","unstructured":"Zhong, Z., Zheng, L., Kang, G., Li, S., and Yang, Y. (2020, January 7\u201312). Random erasing data augmentation. Proceedings of the AAAI Conference on Artificial Intelligence, New York, NY, USA."},{"key":"ref_49","unstructured":"Redmon, J., and Farhadi, A. (2018). YOLOv3: An incremental improvement. arXiv."},{"key":"ref_50","unstructured":"Bochkovskiy, A., Wang, C.Y., and Liao, H.Y.M. (2020). YOLOv4: Optimal speed and accuracy of object detection. arXiv."}],"container-title":["Remote Sensing"],"original-title":[],"language":"en","link":[{"URL":"https:\/\/www.mdpi.com\/2072-4292\/14\/15\/3559\/pdf","content-type":"unspecified","content-version":"vor","intended-application":"similarity-checking"}],"deposited":{"date-parts":[[2025,10,10]],"date-time":"2025-10-10T23:56:03Z","timestamp":1760140563000},"score":1,"resource":{"primary":{"URL":"https:\/\/www.mdpi.com\/2072-4292\/14\/15\/3559"}},"subtitle":[],"short-title":[],"issued":{"date-parts":[[2022,7,25]]},"references-count":50,"journal-issue":{"issue":"15","published-online":{"date-parts":[[2022,8]]}},"alternative-id":["rs14153559"],"URL":"https:\/\/doi.org\/10.3390\/rs14153559","relation":{},"ISSN":["2072-4292"],"issn-type":[{"value":"2072-4292","type":"electronic"}],"subject":[],"published":{"date-parts":[[2022,7,25]]}}}