Stealthy Backdoor Attack in SAR Target Recognition With ASCM-Based Physically Realizable Triggers

被引:0
作者
Zeng, Fei [1 ]
Chen, Yuanjia [1 ]
Cong, Yulai [1 ]
Zhang, Lei [1 ]
Li, Sijia [1 ]
Xu, Jianqiang [1 ]
Duan, Jia [1 ]
机构
[1] Sun Yat Sen Univ, Sch Elect & Commun Engn, Shenzhen 518107, Peoples R China
来源
IEEE TRANSACTIONS ON RADAR SYSTEMS | 2025年 / 3卷
关键词
Training; Synthetic aperture radar; Security; Target recognition; Radar polarimetry; Perturbation methods; Electromagnetics; Data models; Real-time systems; Predictive models; Attributed scattering center model (ASCM); automatic target recognition (ATR); backdoor attack; physical attack; synthetic aperture radar (SAR); SCATTERING CENTER MODEL; ALGORITHM;
D O I
10.1109/TRS.2025.3582438
中图分类号
TM [电工技术]; TN [电子技术、通信技术];
学科分类号
0808 ; 0809 ;
摘要
Deep neural networks (DNNs) are extensively employed in synthetic aperture radar (SAR) automatic target recognition (ATR) systems; however, their security and reliability pose significant challenges in this high-risk domain. While considerable efforts have been made to address the vulnerability of DNNs to adversarial attacks, the SAR ATR community has not yet devoted substantial resources to investigating the newly emerging security risks associated with backdoor attacks, which are more threatening because of their attack flexibility, high stealthiness, and versatile attack modes. To investigate backdoor attacks in SAR ATR, we present an innovative method named ASCM-based physical backdoor attack (AMPBA), which generates a physically realizable trigger with clear electromagnetic characteristics and physical attributes based on the attributed scattering center model (ASCM). Specifically, the AMPBA embeds the trigger into limited training samples to produce a poisoned training dataset; after that, training of a DNN-based classifier would inject into it a stealthy backdoor that can be activated by the trigger (either digitally mimicking that of training or physically in practice for real-time attacks). To further enhance the threat level and practicability of the proposed AMPBA, we additionally propose a backdoor attack strategy called low-intensity training and high-intensity inference (LTHI), which utilizes low-intensity triggers during training to maximize stealthiness and high-intensity triggers during inference for enhanced attack performance. Extensive experiments based on the representative MSTAR dataset validate the effectiveness, stealthiness, and robustness of our AMPBA, which, alternatively, highlight the importance of designing effective backdoor defense mechanisms for high-risk applications.
引用
收藏
页码:947 / 962
页数:16
相关论文
共 80 条
[51]   SCMA: A Scattering Center Model Attack on CNN-SAR Target Recognition [J].
Qin, Weibo ;
Long, Bo ;
Wang, Feng .
IEEE GEOSCIENCE AND REMOTE SENSING LETTERS, 2023, 20
[52]   MobileNetV2: Inverted Residuals and Linear Bottlenecks [J].
Sandler, Mark ;
Howard, Andrew ;
Zhu, Menglong ;
Zhmoginov, Andrey ;
Chen, Liang-Chieh .
2018 IEEE/CVF CONFERENCE ON COMPUTER VISION AND PATTERN RECOGNITION (CVPR), 2018, :4510-4520
[53]  
sdms, The Air Force Moving and Stationary Target Recognition Database
[54]  
Simonyan K, 2015, Arxiv, DOI [arXiv:1409.1556, DOI 10.48550/ARXIV.1409.1556]
[55]   Beam Steering SAR Data Processing by a Generalized PFA [J].
Sun, Guang-Cai ;
Xing, Mengdao ;
Xia, Xiang-Gen ;
Wu, Yirong ;
Bao, Zheng .
IEEE TRANSACTIONS ON GEOSCIENCE AND REMOTE SENSING, 2013, 51 (08) :4366-4377
[56]  
Szegedy C, 2014, Arxiv, DOI arXiv:1312.6199
[57]  
Tan MX, 2020, Arxiv, DOI [arXiv:1905.11946, 10.48550/arXiv.1905.11946, DOI 10.48550/ARXIV.1905.11946]
[58]   Faster and Lighter: A Novel Ship Detector for SAR Images [J].
Tian, Chaoyang ;
Liu, Dacheng ;
Xue, Fengli ;
Lv, Zongsen ;
Wu, Xiayi .
IEEE GEOSCIENCE AND REMOTE SENSING LETTERS, 2024, 21 :1-5
[59]  
Tran B, 2018, ADV NEUR IN, V31
[60]   RANGE-DOPPLER IMAGING OF ROTATING OBJECTS [J].
WALKER, JL .
IEEE TRANSACTIONS ON AEROSPACE AND ELECTRONIC SYSTEMS, 1980, 16 (01) :23-52