By Jingjie He* | May 13, 2026
Remote sensing is a data collection technique that enables the detection and monitoring of physical characteristics of target objects or areas. It is achieved by measuring reflected and emitted radiation from the targets, using optical, radar, light detection and ranging (LiDAR), thermal, multispectral, or hyperspectral sensors deployed on various platforms, including satellites, aircraft, and unmanned aerial vehicles, among others. The acquired data is generally visualized as imagery from an overhead perspective (Campbell, Wynne, and Thomas 2022, 3-23).
Advances in satellite remote sensing and the deployment of satellite constellations have enabled near-persistent Earth observation, which has allowed for significant applications in international security, particularly in arms control and nonproliferation. But challenges remain in processing and analyzing the vast volumes of remote sensing data, primarily due to the reliance on manual analysis by highly trained experts.
Manual analysis faces three key limitations. First, organizations often lack the manpower required to provide comprehensive analytical coverage of remote sensing data. Analyzing satellite imagery requires technical expertise and practical experience, making real-time analysis of large datasets impractical. Second, human analysts may struggle to identify subtle patterns or anomalies, especially in low-resolution images. Even in high-resolution imagery, cognitive biases and target insensitivity may cause analysts to overlook critical information. Third, remote sensing analysis can be serendipitous, with analysts reviewing imagery without a clear sense of what to look for, potentially missing important details.
To address these limitations, researchers have turned to artificial intelligence (AI) and machine learning to analyze satellite imagery at scale. These technologies enable finer granularity, greater accuracy, higher efficiency, and better coverage. But the integration of AI and geospatial science also introduces new challenges, as AI systems can be vulnerable to manipulation through counter-AI techniques.
This article identifies emerging counter-AI threats to satellite imagery analysis and proposes a comprehensive defense framework. It also argues that arms control and nonproliferation missions are not solitary pursuits for seekers but rather dynamic hider-seeker games, where AI functions as both a force and threat multiplier. Adversarial AI attacks—leveraging both digital and physical-world tactics—can be strategically employed to achieve counter-AI objectives, undermining the reliability of AI-driven satellite imagery analyses.
To mitigate these risks, a robust defense framework should encompass five core components: stringent access and quality control for data and models, the integration of robustness into AI frameworks, enhancements to system monitoring capabilities, strengthening cross-sectoral knowledge sharing and threat awareness, and incorporating adaptability and resilience into risk management strategies.
The AI-driven satellite remote sensing revolution
Satellite remote sensing is a powerful tool that can identify objects, detect changes (e.g., facility construction or destruction), and track moving objects (e.g., wartime maneuvers and delivery systems) (Patton et al. 2016). The integration of computer vision, which employs AI to acquire, process, and analyze digital visual data, is revolutionizing the way remote sensing data is interpreted and used.
In particular, AI-driven satellite remote sensing is transforming arms control, nonproliferation, and peacekeeping missions. For example, Amnesty International, in collaboration with Element AI and 28,600 volunteers, developed tools to automatically analyze satellite imagery for monitoring conflicts in Darfur (Cornebise et al. 2018). Palantir Technologies has created MetaConstellation, an AI-powered software for satellite imagery analysis, which has enabled the United States and its allies to automate port monitoring and global submarine deployment tracking (Palantir n.d.). In a joint project with the defense intelligence provider Jane’s, Stanford University, and BlackSky, a satellite imagery provider, the space data analysis company Orbital Insight applied machine learning to assist in the identification of a potential centrifuge assembly facility under construction in Iran (Janes 2021). The US Oak Ridge National Laboratory (2023) also employs AI for applications such as image de-hazing, object counting, and facility function classification. With the precipitous growth of geospatial data, the AI-driven revolution in satellite remote sensing is poised for further acceleration.
Typology of counter-AI attacks
The increasing use of AI-powered satellite remote sensing presents significant security risks. Four primary categories of counter-AI attacks to satellite imagery analysis require attention: data poisoning, model evasion, data inference, and model extraction (see Table 1 below).

Data poisoning. Data poisoning attacks aim to contaminate AI models during their training phases by modifying training data. Adversarial artifacts are injected into the data used to train machine learning models, leading to the creation of contaminated models that yield false classifications. These adversarial artifacts can take the form of detectable patches (e.g., visible geometric patterns, symbols, or stickers added to images) or stealthy pixel modifications (e.g. color and brightness changes to specific pixels within an image that are imperceptible to humans) (Brewer, Lin, and Runfola 2022; He, Zha, and Katabi 2022; Dräger, Xu, and Ghamisi 2023). 1
The success of data poisoning depends on the hider’s access and control over parts of the seeker’s training data. While this is challenging, particularly in scenarios where the seekers are reluctant to share sensitive data, hiders can still poison the training data by infiltrating the seekers data supply chain. To develop a machine learning model, access to significant amounts of readily available satellite images, preferably collected in the real world, is required. In cases where resources are insufficient, developers may resort to third-party datasets to train their models or to the use of third-party models to generate training data. However, these third-party sources could potentially be based on open-sourced data created by malicious entities, thereby leading to the poisoning of the training data.[2]
Model Evasion. Model evasion threats are designed to confuse or evade well-trained models by inserting adversarial perturbations—that is, small changes that humans may not be able to perceive—in data that is to be evaluated via machine learning. These perturbations, which may be generated by AI, are specifically crafted to manipulate the pixels in data, thus affecting the confidence values of classifier predictions and rendering false classification results (Czaja et al. 2018; Xu, Du, and Zhang, 2021). Research indicates that successful attacks can occur even with minuscule perturbations, including single-pixel manipulations (Szegedy et al. 2013; Su, Vargas, and Sakurai 2019).
Model evasion attacks typically require access to the data that is to be evaluated. While direct digital manipulation can be challenging in highly secure environments, physical model evasion can infiltrate the data supply chain by physically altering the appearance of objects captured by remote sensing systems. One strategy for concealment involves reducing the detectability of high-value targets by physically hiding them (e.g., in tunnels and shelters) or covering them with blockers (e.g., wire meshes) and camouflage (e.g., coatings and surface paintings). In the case of non-optical systems, such as radar and hyperspectral remote sensing, stealth technologies can be applied to the surfaces of construction, camouflage, or targets to minimize radar cross-section and other radiation signatures, making them harder to detect (Ahmad et al., 2019; Hoque et al., 2019; Kumar et al., 2019). In recent battlefields, electromagnetic interference has also shown the potential to create flares in satellite imagery, which can prevent the capture of images of concealed objects or areas (Burlaka, 2023; Sutton, 2023).
Another approach to evading AI models involves physically emulating digital perturbations. Adhikari et al. (2020) demonstrated that placing a small “adversarial patch”—a physical or digital visual pattern designed to trigger the misclassification of machine learning models—on top of planes can help them evade object detection models, and the pattern of that patch is effective across various types of planes. Du et al. (2022) showed that placing adversarial patches on or off-and-around vehicles can confuse automatic object classification systems. Their research also indicated the possibility of creating an open-air “security zone” by encircling a parking spot with adversarial patches. As cars enter this “security zone,” the ML model’s ability to accurately identify the vehicles decreases.
A limitation of the above approach is that adversarial patches are easily detectable by human eyes. This leads to an emerging strategy of model evasion—adversarial camouflage. Adversarial camouflages blend natural-looking perturbations into a target, making them difficult for human observers to detect.[3] For instance, Duan et al. (2020) find that adversarial camouflage can be effective in deceiving both object classifiers and human eyes, making stealthy attacks possible. Sun et al. (2023) prove that camouflage texture with refined patterns wrapping over objects has the potential to fool both humans and machines.
The potential military applications of adversarial camouflages have attracted considerable interest from researchers. However, the security implications of this technology in satellite remote sensing still require thorough investigation. In addition to evading models designed for satellite imagery analysis, adversarial camouflage could theoretically create decoys, resulting in false alarms that may overwhelm remote sensing systems, particularly when tracking moving objects.
Data Inference. Data inference threats involve attempts to unveil and steal the training data used by an ML model, which can lead to leakage of sensitive information and intelligence. One technique is data extraction, also known as model inversion, which involves extracting sensitive data that a victim ML model has been trained on through reverse engineering (Fredrikson, Jha, and Ristenpart 2015; Webster 2023). Another technique is membership inference, where an attack aims to test whether a given piece of data is part of the training dataset of the victim model by reconstructing a “shadow model” (Shokri et al. 2017; Nasr, Shokri, and Houmansadr 2019; Liu et al. 2023).
Both types of attacks require a certain level of prior knowledge of the fully trained victim model. In actual scenarios, external attackers may not have complete knowledge of the victim model; nevertheless, they may have partial access to the model through application-programming interfaces (APIs), which allow users to upload their dataset and train their own models on ML-as-a-service (MLaaS) platforms (e.g., Amazon ML, Microsoft Azure ML, Google AI Platform, and IBM Watson ML). MLaaS provides infrastructure for AI developers to train and deploy their models with ML frameworks (e.g., TensorFlow, Pytorch, Keras, and Caffe2). Many platforms and frameworks are open-sourced and cloud-based, making them easily accessible to malicious users. In a recent study, Liu et al. (2023) demonstrated the feasibility of launching membership inference attacks without prior knowledge of the data or model, although the research focuses on textual rather than imagery analysis.
The threat of data inference poses significant security challenges that have not received adequate attention in the fields of remote sensing and international security. Currently, nonproliferation and disarmament missions heavily rely on spaceborne geospatial intelligence, with the most advanced systems involving government reconnaissance or spy satellites. The images produced by these satellites are classified, and any leaks of this data could jeopardize both intelligence and operational information concerning the satellites and their missions. The US intelligence community’s aversion to President Donald Trump’s publication of the Iran rocket launch site in August 2019[4] highlights the severity of geospatial intelligence leaks (Brumfiel 2022). Data inference techniques could potentially enable attackers to retrieve and steal classified satellite imagery, creating more severe intelligence security threats.
Model Extraction. Model extraction attacks aim at duplicating the functionality of a victim model. In this type of attack, a malicious actor seeks to infer the architecture and parameters of the victim model and subsequently trains a surrogate model using a dataset comprised of inputs and outputs obtained from repeated queries to the victim model. Unlike other types of counter-AI attacks, model extraction specifically targets black-box ML models, whose internal workings are not interpretable by humans. Malicious users can access these models through APIs or on-device sandboxed apps (applications operated locally on a user’s device within an isolated and restricted environment enforced by the operating system). Research has demonstrated the feasibility of model extraction to steal image classification models (Tramèr et al. 2016; Papernot et al. 2017; Jagielski et al. 2020) as well as image-to-image translation models for style transfer (e.g., selfie-to-anime, Monet-to-photo, and real-to-fake faces) and resolution improvement (Szyller et al. 2021; Mi et al. 2024).
The increasing use of machine learning in satellite imagery classification and processing, including defogging and resolution improvement, makes model extraction attacks a significant threat to international arms control and disarmament missions. If a malicious actor were to duplicate classified satellite imagery processing and analysis models operated by international nonproliferation agencies, it could enable more targeted and effective methods, such as designing adversarial patches, for concealing proliferation-related activities.
Prospects for a defense framework
The development of effective countermeasures against counter-AI attacks in satellite imagery analysis is of critical importance. A five-dimensional defense framework could effectively manage and mitigate counter-AI threats.
Data and models: access and quality control. Access to data and machine learning models is a prerequisite for conducting counter-AI attacks on analysis of remote-sensing data, so denying such access is an integral component of defense strategies. It is critical to establish a comprehensive tracking system for the lineage of both data and models. Seekers monitoring potential proliferation activities via satellite remote sensing must vigilantly monitor the entire lifecycle of data and metadata, tracking their generation, storage, categorization, retrieval, preprocessing, and processing stages. This monitoring can be significantly enhanced by using advanced technologies such as blockchain or quantum encryption, which can make it exceedingly difficult for hiders who seek to conceal proliferation activities to introduce adversarial artifacts into the data. Meanwhile, considerable attention must be devoted to assessing the quality of raw data to detect potential physical model evasion attacks, ensuring the authenticity and accuracy of the data used to train and validate models.
Regarding machine learning models, it is equally important for defenders to thoroughly understand the development history of the models, their characteristics, limitations, and the access controls governing their use. This includes knowing who developed the model, the conditions under which it can be accessed, and who has queried the model and acquired data that might be used for malicious purposes. To safeguard against data-poisoning attacks, defenders can employ techniques such as embedding digital watermarks or imperceptible perturbations into the output data generated by models, especially those hosted on MLaaS platforms. These measures can significantly reduce the quality and reusability of the data by malicious users, thereby reducing the likelihood of adversarial exploitation.
Frameworks: robustness building. Building model robustness is paramount in mitigating vulnerabilities to counter-AI threats. One promising approach involves integrating an “immune system” into the model during its training phase to defend against such threats. This strategy entails training the model to recognize inserted perturbations and out-of-distribution data. The APRICOT Dataset, released by the MITRE Corporation, contains 1,011 images of 60 publicly available physical-world adversarial patches, with 10 to 42 images for each patch. Machines can be trained on APRICOT to recognize these patches (Braunegg et al. 2020). However, these patches in APRICOT are outdated and limited in number. Its relatively small data size, compared to the expansive training datasets used for large-scale models, means that some features in APRICOT may be dismissed as random errors. Therefore, a comprehensive up-to-date perturbation database is needed to build a more robust immune system for models.
An alternative approach is to implement a self-improving mechanism that continuously enhances model performance by identifying and reducing errors or, in machine learning terms, optimizing the cost function (Boehnlein et al. 2022, 4). One potential solution is self-supervised learning, where models are trained on unlabeled data instead of traditional labeled datasets. A notable example of this approach is the use of Generative Adversarial Networks (GANs), which consist of two contesting neural networks: the Generator, which introduces adversarial perturbations into satellite imagery to deceive the system, and the Discriminator, which attempts to detect these attacks and penalizes the Generator when its output fails to meet the desired criteria (Vaidyanathan and Danet 2022).
Moreover, critical thinking and self-evaluation are essential steps for intelligent decision-making and problem-solving. Theoretically, developers could incorporate a machine introspection mechanism into a model’s internal reasoning path. Yao et al. (2023) proposed an innovative approach for language models, termed the “Tree of Thoughts.” This approach decomposes the problem-solving process into a tree diagram with a human-in-the-loop thought generation and evaluation framework. In this framework, machines generate intermediate thoughts and evaluate multiple decision-making options or paths, while humans can intervene at any stage to exclude fewer promising options. While this approach has demonstrated success in language models, the feasibility of implementing a similar introspection mechanism for satellite imagery processing, given the difference in computer vision tasks, remains an area for further exploration.
Systems: monitoring capability enhancement. In practical applications, threat modeling often fails to prevent attacks, as it primarily investigates potential threats from the defender’s perspectives. This limitation is one reason organizations routinely employ white-hat hackers and AI red teams to expose system vulnerability through emulated adversarial attacks (Caldwell 2011; Feffer et al. 2024).
The limitation of the preventive approach highlights the critical need for real-time monitoring to identify anomalies indicative of counter-AI attacks targeting satellite remote sensing systems. Although AI anomaly detection has been implemented across various sectors, its application in remote sensing—an area with significant security and strategic stakes—presents unique challenges. Well-trained attackers may possess the capability to bypass or paralyze such detection systems. Consequently, deploying a higher-order meta-system to monitor the performance of these detection systems is essential, despite potential reductions in system efficiency, as it enhances the robustness of defense mechanisms and ensure timely identification of emerging threats.
Humans: knowledge and awareness cultivation. Defense against counter-AI attacks requires an updated understanding of ongoing research and recent counter-AI attack cases. Collaboration among stakeholders across industry, government, academia, and civil society will be required to share such information and mitigate risks. But the landscape is complex. For instance, satellite companies at the forefront of integrating machine learning into remote sensing may refuse to publicly discuss counter-AI threats due to a lack of solutions and concerns about potential negative impacts on their market value, investor interest, and client subscriptions.[5] So motivating stakeholders is key to the effective sharing knowledge and information required for threat management.
Meanwhile, it is crucial to foster a culture of skepticism toward AI. The success of generative AI models such as ChatGPT and DeepSeek has led to the misguided belief that AI understands the world similarly to humans and can make superior and quicker decisions based on logical reasoning. This notion is unfounded: The apparent reasoning of machines is at this point not genuine or reliable; instead, it is based on probabilistic pattern matching derived from extensive training data (Jiang et al., 2024; Mirzadeh et al., 2024; Shi et al., 2023). Consequently, humanizing AI can be detrimental, as it limits our ability to think critically and challenge the models when human judgment diverges from machine conclusions. It is essential to promote knowledge about machine learning’s limitations and to foster a culture of skepticism towards AI.
Management: adaptability and resilience strengthening. The rapid advance of AI and counter-AI technologies poses a significant challenge for policy and regulatory efforts, which often struggle to keep pace with the speed of technological evolution. It is unlikely that a comprehensive, robust, and lasting defense strategy will be established, whether on an international or domestic level. Instead, effectively managing counter-AI threats requires an agile approach, in which countermeasures are regularly updated through iteration. This adaptability ensures that responses remain effective against evolving threats.
Given the dynamic hider-seeker games powered by evolving AI and counter-AI techniques, eliminating counter-AI threats is unlikely. But they can be managed. Unexpected or novel situations—such as counter-AI attacks on the computer vision models used by remote sensing companies or organizations—are likely to arise. Therefore, it is essential to create a contingency plan that emphasizes building resilience and implementing procedures to minimize the impact of such attacks. The effectiveness of such a plan should be validated through simulations and drills.
Evolving AI and counter-AI strategies entail a long-term hider-seeker game, in which counter-AI threats can be mitigated but not eradicated. There is significant potential in AI-powered, satellite-based remote sensing, but it is imperative to remain aware of the vulnerabilities these models may encounter in the face of counter-AI attacks—and to engage in proactive defense strategies to enhance the protection and resilience of remote sensing systems.
Acknowledgements
This research originated as a visiting fellowship project at the James Martin Center for Nonproliferation Studies and was further developed thereafter. I thank Natasha Bajema, Steven De La Fuente, Adlan Margoev, Serge Franchoo, Henrik Stålhane Hiim, Yasmin Afina, Jean du Preez, Huma Rehman, and anonymous contributors and reviewers for their insightful and constructive comments. I also thank participants of the Consultancy Meeting on Emerging Technologies at the International Atomic Energy Agency, the Alva Myrdal Centre for Nuclear Disarmament Annual Conference, the Roundtable on AI, Security, and Ethics organized by the United Nations Institute for Disarmament Research, and the Responsible AI in the Military Domain Summit for their valuable discussions and feedback.
Endnotes
[1] For example, Narla et al. (2018) find that a skin lesion detection model trained on dermatoscopic photos is systematically biased toward classifying images containing rulers as malignant, because standardized malignant lesions images are often accompanied by rulers to indicate lesion size. As a result, the model erroneously learns to associate the ruler with malignancy rather than pathological features. Although not an intentional data-poisoning attack, this case illustrates how adversaries could potentially contaminate a model by injecting adversarial artifacts (rulers in this case) into the training data.
[2] In the same example, if developers rely on openly accessible online dermatoscopic photos for training, many of which may have been manipulated by malicious actors to include “rulers”, the model’s accuracy in identifying malignant skin lesions is likely to degrade. In real-world attack scenarios, such injected artifacts need not be overt like the “rulers” but may consist of geometric patterns seamlessly blended into the image or carefully designed pixel-level modifications that are imperceptible to human observers.
[3] The AI adaptive camouflages in this article refer to technologies that apply to both AI model and human observers. It does not take into account camouflages, including AI-designed adaptive ones, that only aim at hiding targets from human eyes because they belong to the aforementioned approach of reducing target detectability.
[4] See: https://www.npr.org/2022/11/18/1137474748/trump-tweeted-an-image-from-a-spy-satellite-declassified-document-shows
[5] I have encountered representatives from various institutes and companies that are developing machine learning systems for satellite imagery analysis at international conferences and meetings. None of them demonstrated a comprehensive awareness, let alone preparedness, for the counter-AI threats discussed in this article.
*Jingjie He is a postdoctoral researcher in the Security Studies division at the Institute of World Economics and Politics, Chinese Academy of Social Sciences. Previously, she held fellowships at the James Martin Center for nonproliferation studies at the Middlebury Institute of International Studies at Monterey, the Arms Control Negotiation Academy led by Harvard University’s Davis Center for Russian and Eurasian Studies, and the Comprehensive Nuclear-Test-Ban Treaty Organization, among others. Her research focuses on war and conflict, disruptive technologies, nuclear security, and defense modernization. ORCID: 0000-0002-6020-6620
We remind our readers that publication of articles on our site does not mean that we agree with what is written. Our policy is to publish anything which we consider of interest, so as to assist our readers in forming their opinions. Sometimes we even publish articles with which we totally disagree, since we believe it is important for our readers to be informed on as wide a spectrum of views as possible.

