Research Article
Project Gradient Descent Adversarial Attack against Multisource Remote Sensing Image Scene Classification
Table 5
Classification accuracy of the UCM data set under the targeted attack.
| Models | OA of clean | OA of Xu2020 | OA of ours | OA gap of Xu2020 | OA gap of ours |
| VGG-16 | 91.15 1.03 | 38.04 0.38 | 29.98 0.42 | −53.11 | −61.17 | GoogLeNet | 95.52 0.62 | 51.21 0.45 | 24.48 0.97 | −44.31 | −71.04 | InceptionV3 | 94.78 0.32 | 66.09 1.29 | 37.69 1.95 | −28.70 | −57.10 | ResNet-18 | 94.80 0.22 | 42.89 0.67 | 16.52 0.70 | −51.91 | −78.28 | ResNet-50 | 96.27 0.10 | 60.84 0.70 | 21.38 0.19 | −35.43 | −74.89 | ResNet-101 | 96.15 0.26 | 60.93 4.97 | 24.70 2.02 | −35.22 | −71.45 | DenseNet-121 | 95.58 0.67 | 63.61 1.23 | 26.14 0.86 | −31.97 | −69.43 | DenseNet-201 | 95.91 0.73 | 64.17 1.07 | 26.10 0.63 | −31.75 | −69.81 |
|
|