提出无需知道视角的雷达对抗攻击方法,提升真实场景下欺骗效果。
SAAIPAA: Optimizing aspect-angles-invariant physical adversarial attacks on SAR target recognition models
- 基于物理建模优化反射体位置与朝向,不依赖视角信息
- 白盒下骗过率80%,已知视角时可达99.2%
- 适用于真实雷达对抗,对多种模型具有迁移性
合成孔径雷达(SAR)支持全天候、全天时遥感,结合机器学习驱动的目标识别(ATR)正广泛应用于地球观测与监视。然而,针对SAR ATR中机器学习模型的对抗扰动攻击日益增多,亟需深入研究其机制。现有物理对抗攻击(PAAs)假设攻击者知晓雷达平台的视角,限制了实际应用。本文提出SAR视角不变物理对抗攻击(SAAIPAA),可在未知视角条件下,为任意数量和尺寸的反射体确定最优位置与朝向。该方法通过精确的物理信号与成像过程建模实现。为实现图像与场景坐标映射,还提出在密集采样的方位角SAR图像中生成边界框的方法,使目标本身作为空间参考。所生成的物理逃避攻击在考虑的视角范围内高效且最优,白盒设置下四反射体配置的欺骗率分别达DenseNet-121和ResNet50的80%;当视角已知时,平均欺骗率达99.2%。黑盒设置下,SAAIPAA在部分模型间具有良好迁移性。
原文摘要 · Abstract (English)
Synthetic aperture radar (SAR) enables versatile, all-time, all-weather remote sensing. Coupled with automatic target recognition (ATR) leveraging machine learning (ML), SAR is empowering a wide range of Earth observation and surveillance applications. However, the surge of attacks based on adversarial perturbations against the ML algorithms underpinning SAR ATR is prompting the need for systematic research into adversarial perturbation mechanisms. Research in this area began in the digital (image) domain and evolved into the physical (signal) domain, resulting in physical adversarial attacks (PAAs) that strategically exploit corner reflectors as attack vectors to evade ML-based ATR. Existing PAAs assume that the attacker knows the SAR platform's aspect angles, restricting their applicability to idealized scenarios. We propose the SAR Aspect-Angles-Invariant Physical Adversarial Attack (SAAIPAA), a framework that determines the optimal positions and orientations of any given set of reflectors, regardless of their number or size, even when the attacker lacks knowledge of the SAR platform's aspect angles. This is enabled by rigorous physics-based modeling of the reflected signal and the SAR imaging process. To facilitate mapping between image and scene coordinates, we additionally propose a method for generating bounding boxes in densely sampled azimuthal SAR images, allowing the target object to serve as a spatial reference. The resultant physical evasion attacks are efficiently realizable and optimal over the considered range of aspect angles between a SAR platform and a target, achieving state-of-the-art fooling rates (80% for DenseNet-121 and ResNet50) in the white-box setting for a four-reflector configuration. When aspect angles are known to the attacker, an average fooling rate of is 99.2% attainable. In black-box settings, SAAIPAA transfers well between some models.
Thank you to arXiv for use of its open access interoperability. PaperDance 不是 arXiv 官方产品;中文卡片由大模型生成,请以原文为准。