提出SRAW攻击方法,让雷达图像识别模型误判且不易被发现。
SRAW-Attack: Space-Reweighted Adversarial Warping Attack for SAR Target Recognition
- 通过重分配前景与背景的扰动预算,优化空间形变生成对抗样本。
- 在多个SAR-ATR模型上使识别准确率降至10%以下,攻击成功率超90%。
- 兼具隐蔽性与跨模型迁移能力,适合研究雷达系统安全性的学者。
合成孔径雷达(SAR)图像因独特的电磁散射机制存在固有信息稀疏性。尽管基于深度神经网络(DNN)的SAR自动目标识别(SAR-ATR)系统广泛应用,仍易受对抗样本影响,且过度依赖背景区域,导致对抗鲁棒性下降。现有SAR-ATR对抗攻击方法通常需引入肉眼可见的失真才能有效,亟需兼顾效果与隐蔽性的攻击手段。本文提出一种新型攻击方法——空间重加权对抗形变(SRAW),通过在前景与背景区域重新分配扰动预算,实现优化的空间形变,生成对抗样本。大量实验表明,SRAW显著降低主流SAR-ATR模型性能,且在隐蔽性与对抗迁移性方面持续优于现有方法。代码已公开于https://github.com/boremycin/SAR-ATR-TransAttack。
原文摘要 · Abstract (English)
Synthetic aperture radar (SAR) imagery exhibits intrinsic information sparsity due to its unique electromagnetic scattering mechanism. Despite the widespread adoption of deep neural network (DNN)-based SAR automatic target recognition (SAR-ATR) systems, they remain vulnerable to adversarial examples and tend to over-rely on background regions, leading to degraded adversarial robustness. Existing adversarial attacks for SAR-ATR often require visually perceptible distortions to achieve effective performance, thereby necessitating an attack method that balances effectiveness and stealthiness. In this paper, a novel attack method termed Space-Reweighted Adversarial Warping (SRAW) is proposed, which generates adversarial examples through optimized spatial deformation with reweighted budgets across foreground and background regions. Extensive experiments demonstrate that SRAW significantly degrades the performance of state-of-the-art SAR-ATR models and consistently outperforms existing methods in terms of imperceptibility and adversarial transferability. Code is made available at https://github.com/boremycin/SAR-ATR-TransAttack.
Thank you to arXiv for use of its open access interoperability. PaperDance 不是 arXiv 官方产品;中文卡片由大模型生成,请以原文为准。