LADA: Latent-Space Adversarial Diffusion Attack in Remote Sensing
Qianlong Dang, Junhu Ruan, Tao Zhan, Maoguo Gong, Xiaoyu He · IEEE Transactions on Geoscience and Remote Sensing · 2025
Deep neural networks (DNNs) have achieved remarkable progress in remote sensing image (RSI) analysis, yet their vulnerability to subtle adversarial perturbations poses a critical threat to safety-critical applications such as environmental monitoring. While black-box attacks have garnered attention for their practicality, existing methods face a dilemma in RSI scenarios: restricted attacks often result in compromised image quality and limited stealthiness, whereas unrestricted attacks risk degrading transferability. To address this challenge, this paper proposes the latent-space adversarial diffusion attack framework (LADA), which focuses on balancing stealthiness and transferability in adversarial attacks against RSI models. LADA employs a pre-trained diffusion model to map high-resolution RSIs into a low-dimensional latent space, enabling semantic-level perturbation optimization while avoiding pixel-wise explicit noise. Additionally, text prompts are automatically generated using a large multimodal model to guide adversarial sample synthesis, ensuring semantic consistency. To enhance perturbation search efficiency in the latent space, a hybrid strategy combining multi-scale sampling and covariance matrix adaptation evolution strategy is introduced. Extensive experiments demonstrate that LADA achieves superior performance across multiple RSI datasets, model architectures, and defense mechanisms. This paper establishes a benchmark for high-stealthiness and high-transferability adversarial attacks, advancing the secure deployment of DNNs in remote sensing applications.