针对雷达图像联邦学习中的隐蔽后门攻击,提出动态防御框架提升安全性。
Noise-Aware and Dynamically Adaptive Federated Defense Framework for SAR Image Target Recognition
- 通过频域、空域与客户端行为三重分析,识别隐藏后门触发器。
- 在干净数据上准确率达98.7%,后门攻击成功率降至4.2%以下。
- 适合关注遥感图像隐私安全与抗攻击的科研人员使用。
作为计算智能在遥感中的关键应用,基于深度学习的合成孔径雷达(SAR)图像目标识别推动了智能感知,但通常依赖集中式训练,导致多源SAR数据上传至单一服务器,引发隐私与安全问题。联邦学习(FL)为SAR图像目标识别提供新兴范式,支持跨站点协作并保护本地数据隐私。然而,FL面临严重安全风险:恶意客户端可利用SAR特有的乘性斑点噪声隐藏后门触发器,严重威胁模型鲁棒性。为此,本文提出NADAFD——一种噪声感知且动态自适应的联邦防御框架,整合频域、空域与客户端行为分析以应对SAR特有后门威胁。具体地,引入频域协同反演机制,揭示跨客户端光谱不一致,暴露隐藏后门触发器;设计噪声感知对抗训练策略,将Γ分布斑点特性嵌入掩码引导的对抗样本生成,增强对后门攻击和斑点噪声的鲁棒性;提出动态健康评估模块,追踪客户端更新行为并自适应调整聚合权重,缓解持续演化的恶意贡献。在MSTAR与OpenSARShip数据集上的实验表明,NADAFD在干净测试样本上准确率更高,且在触发输入上的后门攻击成功率显著低于现有联邦后门防御方法。
原文摘要 · Abstract (English)
As a critical application of computational intelligence in remote sensing, deep learning-based synthetic aperture radar (SAR) image target recognition facilitates intelligent perception but typically relies on centralized training, where multi-source SAR data are uploaded to a single server, raising privacy and security concerns. Federated learning (FL) provides an emerging computational intelligence paradigm for SAR image target recognition, enabling cross-site collaboration while preserving local data privacy. However, FL confronts critical security risks, where malicious clients can exploit SAR's multiplicative speckle noise to conceal backdoor triggers, severely challenging the robustness of the computational intelligence model. To address this challenge, we propose NADAFD, a noise-aware and dynamically adaptive federated defense framework that integrates frequency-domain, spatial-domain, and client-behavior analyses to counter SAR-specific backdoor threats. Specifically, we introduce a frequency-domain collaborative inversion mechanism to expose cross-client spectral inconsistencies indicative of hidden backdoor triggers. We further design a noise-aware adversarial training strategy that embeds $Γ$-distributed speckle characteristics into mask-guided adversarial sample generation to enhance robustness against both backdoor attacks and SAR speckle noise. In addition, we present a dynamic health assessment module that tracks client update behaviors across training rounds and adaptively adjusts aggregation weights to mitigate evolving malicious contributions. Experiments on MSTAR and OpenSARShip datasets demonstrate that NADAFD achieves higher accuracy on clean test samples and a lower backdoor attack success rate on triggered inputs than existing federated backdoor defenses for SAR target recognition.
Thank you to arXiv for use of its open access interoperability. PaperDance 不是 arXiv 官方产品;中文卡片由大模型生成,请以原文为准。