ULAN: A Universal Local Adversarial Network for SAR Target Recognition Based on Layer-Wise Relevance Propagation

被引:4
作者
Du, Meng [1 ]
Bi, Daping [1 ]
Du, Mingyang [1 ]
Xu, Xinsong [1 ]
Wu, Zilong [1 ]
机构
[1] Natl Univ Def Technol, Coll Elect Engn, Hefei 230037, Peoples R China
基金
中国国家自然科学基金;
关键词
deep neural network (DNN); synthetic aperture radar automatic target recognition (SAR-ATR); universal adversarial perturbation (UAP); U-Net; attention heatmap; layer-wise relevance propagation (LRP); EXAMPLES; CLASSIFICATION;
D O I
10.3390/rs15010021
中图分类号
X [环境科学、安全科学];
学科分类号
08 ; 0830 ;
摘要
Recent studies have proven that synthetic aperture radar (SAR) automatic target recognition (ATR) models based on deep neural networks (DNN) are vulnerable to adversarial examples. However, existing attacks easily fail in the case where adversarial perturbations cannot be fully fed to victim models. We call this situation perturbation offset. Moreover, since background clutter takes up most of the area in SAR images and has low relevance to recognition results, fooling models with global perturbations is quite inefficient. This paper proposes a semi-white-box attack network called Universal Local Adversarial Network (ULAN) to generate universal adversarial perturbations (UAP) for the target regions of SAR images. In the proposed method, we calculate the model's attention heatmaps through layer-wise relevance propagation (LRP), which is used to locate the target regions of SAR images that have high relevance to recognition results. In particular, we utilize a generator based on U-Net to learn the mapping from noise to UAPs and craft adversarial examples by adding the generated local perturbations to target regions. Experiments indicate that the proposed method effectively prevents perturbation offset and achieves comparable attack performance to conventional global UAPs by perturbing only a quarter or less of SAR image areas.
引用
收藏
页数:27
相关论文
共 51 条
[1]  
[Anonymous], 2017, P IEEE C COMP VIS PA, DOI DOI 10.48550/ARXIV.1610.08401
[2]   On Pixel-Wise Explanations for Non-Linear Classifier Decisions by Layer-Wise Relevance Propagation [J].
Bach, Sebastian ;
Binder, Alexander ;
Montavon, Gregoire ;
Klauschen, Frederick ;
Mueller, Klaus-Robert ;
Samek, Wojciech .
PLOS ONE, 2015, 10 (07)
[3]   SYNTHETIC APERTURE RADAR [J].
BROWN, WM .
IEEE TRANSACTIONS ON AEROSPACE AND ELECTRONIC SYSTEMS, 1967, AES3 (02) :217-&
[4]   HopSkipJumpAttack: A Query-Efficient Decision-Based Attack [J].
Chen, Jianbo ;
Jordan, Michael, I ;
Wainwright, Martin J. .
2020 IEEE SYMPOSIUM ON SECURITY AND PRIVACY (SP 2020), 2020, :1277-1294
[5]  
Chen PY, 2017, PROCEEDINGS OF THE 10TH ACM WORKSHOP ON ARTIFICIAL INTELLIGENCE AND SECURITY, AISEC 2017, P15, DOI 10.1145/3128572.3140448
[6]   Universal Adversarial Attack on Attention and the Resulting Dataset DAmageNet [J].
Chen, Sizhe ;
He, Zhengbao ;
Sun, Chengjin ;
Yang, Jie ;
Huang, Xiaolin .
IEEE TRANSACTIONS ON PATTERN ANALYSIS AND MACHINE INTELLIGENCE, 2022, 44 (04) :2188-2197
[7]   Target Classification Using the Deep Convolutional Networks for SAR Images [J].
Chen, Sizhe ;
Wang, Haipeng ;
Xu, Feng ;
Jin, Ya-Qiu .
IEEE TRANSACTIONS ON GEOSCIENCE AND REMOTE SENSING, 2016, 54 (08) :4806-4817
[8]   Convolutional Neural Network With Data Augmentation for SAR Target Recognition [J].
Ding, Jun ;
Chen, Bo ;
Liu, Hongwei ;
Huang, Mengyuan .
IEEE GEOSCIENCE AND REMOTE SENSING LETTERS, 2016, 13 (03) :364-368
[9]   Fast C&W: A Fast Adversarial Attack Algorithm to Fool SAR Target Recognition With Deep Convolutional Neural Networks [J].
Du, Chuan ;
Huo, Chaoying ;
Zhang, Lei ;
Chen, Bo ;
Yuan, Yijun .
IEEE GEOSCIENCE AND REMOTE SENSING LETTERS, 2022, 19
[10]   Factorized discriminative conditional variational auto-encoder for radar HRRP target recognition [J].
Du, Chuan ;
Chen, Bo ;
Xu, Bin ;
Guo, Dandan ;
Liu, Hongwei .
SIGNAL PROCESSING, 2019, 158 :176-189