Enhancing Adversarial Transferability With Intermediate Layer Feature Attack on Synthetic Aperture Radar Images

被引:0
|
作者
Wan, Xuanshen [1 ]
Liu, Wei [1 ]
Niu, Chaoyang [1 ]
Lu, Wanjie [1 ]
Li, Yuanli [1 ]
机构
[1] Informat Engn Univ, Zhengzhou 450001, Peoples R China
基金
中国国家自然科学基金;
关键词
Perturbation methods; Closed box; Synthetic aperture radar; Generators; Data models; Radar polarimetry; Target recognition; Training data; Artificial neural networks; Training; Adversarial example; automatic target recognition (ATR); deep neural network (DNN); synthetic aperture radar (SAR); transferability; CONVOLUTIONAL NEURAL-NETWORK;
D O I
10.1109/JSTARS.2024.3507374
中图分类号
TM [电工技术]; TN [电子技术、通信技术];
学科分类号
0808 ; 0809 ;
摘要
Synthetic aperture radar (SAR) automatic target recognition (ATR) systems based on deep neural network models are vulnerable to adversarial examples. Existing SAR adversarial attack algorithms require access to the network structure, parameters, and training data, which are often inaccessible in real-world scenarios. To address this problem, this study proposes an intermediate layer feature attack algorithm that does not rely on training data for the adversary model. Electromagnetic simulation is used to obtain the simulated SAR local data domain during the training stage. A lightweight generator, TinyResNet, is introduced to quickly construct adversarial examples through a one-step mapping process. In addition, the transferability of these examples across different models is improved by eliminating the intermediate layer features of the model. Finally, a domain-agnostic feature attention module is utilized to reduce discrepancies between different data domains from a model perspective, further improving the transferability of adversarial examples across domains. Experimental results on five SAR datasets of ground vehicles, ships, and scene types demonstrate that the proposed algorithm outperforms 13 mainstream adversarial attack algorithms in terms of cross-model and cross-data domain transferability. In particular, the proposed method improves the cross-domain attack success rate by 43.74%-48.88% on the MSTAR dataset.
引用
收藏
页码:1638 / 1655
页数:18
相关论文
共 50 条
  • [1] Enhancing Adversarial Example Transferability with an Intermediate Level Attack
    Huang, Qian
    Katsman, Isay
    He, Horace
    Gu, Zeqi
    Belongie, Serge
    Lim, Ser-Nam
    2019 IEEE/CVF INTERNATIONAL CONFERENCE ON COMPUTER VISION (ICCV 2019), 2019, : 4732 - 4741
  • [2] Enhancing adversarial attack transferability with multi-scale feature attack
    Sun, Caixia
    Zou, Lian
    Fan, Cien
    Shi, Yu
    Liu, Yifeng
    INTERNATIONAL JOURNAL OF WAVELETS MULTIRESOLUTION AND INFORMATION PROCESSING, 2021, 19 (02)
  • [3] Boosting Adversarial Transferability with Shallow-Feature Attack on SAR Images
    Lin, Gengyou
    Pan, Zhisong
    Zhou, Xingyu
    Duan, Yexin
    Bai, Wei
    Zhan, Dazhi
    Zhu, Leqian
    Zhao, Gaoqiang
    Li, Tao
    REMOTE SENSING, 2023, 15 (10)
  • [4] Boosting Adversarial Transferability Through Intermediate Feature
    He, Chenghai
    Li, Xiaoqian
    Zhang, Xiaohang
    Zhang, Kai
    Li, Hailing
    Xiong, Gang
    Li, Xuan
    ARTIFICIAL NEURAL NETWORKS AND MACHINE LEARNING, ICANN 2023, PT V, 2023, 14258 : 28 - 39
  • [5] Enhancing the Transferability of Adversarial Examples with Feature Transformation
    Xu, Hao-Qi
    Hu, Cong
    Yin, He-Feng
    MATHEMATICS, 2022, 10 (16)
  • [6] Transferable Targeted Adversarial Attack on Synthetic Aperture Radar (SAR) Image Recognition
    Zheng, Sheng
    Han, Dongshen
    Lu, Chang
    Hou, Chaowen
    Han, Yanwen
    Hao, Xinhong
    Zhang, Chaoning
    REMOTE SENSING, 2025, 17 (01)
  • [7] Feature detection in synthetic aperture radar images using fractal error
    Jansing, ED
    Chenoweth, DL
    Knecht, J
    1997 IEEE AEROSPACE CONFERENCE PROCEEDINGS, VOL 1, 1997, : 187 - 195
  • [8] Azimuth Scaling for Inverse Synthetic Aperture Radar Images with Feature Registration
    Xu, Zhiwei
    Zhang, Lei
    Xing, Mengdao
    2013 6TH INTERNATIONAL CONGRESS ON IMAGE AND SIGNAL PROCESSING (CISP), VOLS 1-3, 2013, : 1568 - 1572
  • [9] A neural network for enhancing boundaries and surfaces in synthetic aperture radar images
    Mingolla, E
    Ross, W
    Grossberg, S
    NEURAL NETWORKS, 1999, 12 (03) : 499 - 511
  • [10] REGULARIZED INTERMEDIATE LAYERS ATTACK: ADVERSARIAL EXAMPLES WITH HIGH TRANSFERABILITY
    Li, Xiaorui
    Cui, Weiyu
    Huang, Jiawei
    Wang, Wenyi
    Chen, Jianwen
    2021 IEEE INTERNATIONAL CONFERENCE ON IMAGE PROCESSING (ICIP), 2021, : 1904 - 1908