DACO-BD: Data Augmentation Combinatorial Optimization-Based Backdoor Defense in Deep Neural Networks for SAR Image Classification
Guo-Qiang Zeng,Hai-Nan Wei,Kang-Di Lu,Guang-Gang Geng,Jian Weng
DOI: https://doi.org/10.1109/tim.2024.3436130
IF: 5.6
2024-08-18
IEEE Transactions on Instrumentation and Measurement
Abstract:Deep neural networks (DNNs) have been widely used in the field of synthetic aperture radar (SAR) image classification, but they also face increasingly serious threats from various malicious attacks, among which the backdoor attack is a common threat. The defense methods against backdoor attacks are extremely important. Although the defense methods against backdoor attacks have been studied in the area of traditional computer vision, there is no relevant research on defense against backdoor attacks in DNNs for SAR image classification. This work is the first time to automatically design a data augmentation combinatorial optimization-based backdoor defense, called DACO-BD, for DNNs-based SAR image classifier. In DACO-BD, the automated data augmentation design for the backdoor defense strategy is formulated as the variable-length combinatorial optimization problem. By considering both model performance loss and backdoor attack defense performance, we design the objective function by minimizing the weight sum of the change of testing accuracy error and the attack success rate (ASR). To describe and evolve the length and different combinations of data augmentation strategies, we develop an efficient encoding strategy and discrete optimization operations under the framework of genetic algorithm (GA) including crossover operation and mutation operation. The experimental results on the three SAR image classification datasets including FUSAR-ship, moving and stationary target acquisition and recognition (MSTAR), and UC Merced Land-Use (UCM) demonstrate that the proposed DACO-BD method achieves satisfactory defense performance against five different types of backdoor attacks, while keeping low model performance loss. Furthermore, the proposed DACO-BD outperforms four state-of-the-art backdoor defense methods and one novel classifier originally developed for hyperspectral image classification.
engineering, electrical & electronic,instruments & instrumentation