Speckle-Variant Attack: Toward Transferable Adversarial Attack to SAR Target Recognition

Bowen Peng,Bo Peng,Jie Zhou,Jingyuan Xia,Li Liu
DOI: https://doi.org/10.1109/lgrs.2022.3184311
IF: 5.343
2022-07-02
IEEE Geoscience and Remote Sensing Letters
Abstract:Recent advances in deep neural networks (DNNs) highlight the success of synthetic aperture radar automatic target recognition (SAR ATR) with superior effectiveness and efficiency. However, the DNNs are known to be vulnerable to adversarial examples, whose performance will be dramatically reduced when the imperceptible perturbation exists. In optical image processing, invisible perturbations are typically embedded in the way of a full-scale distribution in a purely digital setting. Whereas, it is not feasible to achieve this in SAR ATR tasks due to the inaccessibility of the SAR system and unique imaging mechanism. In practice, the subtle perturbations could be produced by physical approaches that change the scattering property of the target. Therefore, the adversarial perturbations for SAR ATR should be of good transferability to achieve an effective attack on major DNN classifiers as well as the accessible additive region in SAR images with respect to the realistic target locations. In this letter, we present a novel approach, namely speckle-variant attack (SVA). The proposed SVA is composed of two major modules: an iterative gradient-based perturbation generator and a target region extractor. The perturbation generator implements a speckle-variant transformation that continuously reconstructs the speckle-noise pattern during each of the iterations for strong transferability. The target region extractor ensures the feasibility of the additive adversarial perturbations in practical scenarios by restricting the region of the perturbation. Therefore, the proposed SVA is capable of producing adversarial examples that are more transferable and physically feasible. Extensive evaluations of the MSTAR dataset show that the SVA has achieved superior transferability and competitive time consumption compared with the SOTA transformation-based techniques, including the diverse inputs method and the scale-invariant method.
imaging science & photographic technology,remote sensing,engineering, electrical & electronic,geochemistry & geophysics
What problem does this paper attempt to address?