幅值调制引导的SAR图像对抗样本生成方法

Amplitude Modulation-Guided Adversarial Example Generation Method for SAR Imagery

  • 摘要: 对抗样本的存在会导致基于深度神经网络(deep neural networks,DNNs)的合成孔径雷达(syntheticaperture radar,SAR)目标识别模型做出错误预测,严重影响其识别精度和鲁棒性。然而,现有图像域对抗样本生成方法得到的对抗扰动存在空间约束性、扰动稀疏性和物理真实性不足的问题。为了解决上述问题,提出一种幅值调制引导的SAR图像对抗样本生成方法(SAR Amplitude Modulation-guided Adversarial Example,SAR-AMAE)。首先,针对空间约束性问题,结合最大类间方差算法(OTSU)和形态学操作来提取目标区域掩模,将扰动点的位置仅限制在目标有效散射区域内;其次,针对扰动稀疏性问题,构建基于参数化散射中心模型的对抗攻击框架,直接以散射中心的空间位置和散射幅值作为优化变量。通过差分进化(differential evolution,DE)算法在物理参数空间进行寻优,寻找能够最大化干扰目标特征提取的最优散射分布,并采用自适应策略动态调制散射幅值,确保扰动的不可检测性;最后,针对物理真实性问题,结合SAR系统的动态范围限制,对散射中心幅值的调制范围进行物理约束,并通过雷达回波仿真验证对抗扰动在信号成像链路中的有效性与物理一致性。实验结果表明,SAR-AMAE方法在仅扰动图像中少量像素值的情况下,就能够在基于CNN (convolutional neural network)架构和Transformer架构的10种分类模型上达到平均35.81%的攻击成功率,并展现出良好的攻击可迁移性能。综上,该研究建立了图像域扰动与雷达回波物理特性之间的映射关系,验证了在信号成像链路中生成具备物理属性对抗样本的可行性,为评估SAR智能识别系统在现实场景下的安全性提供了有效手段。

     

    Abstract: Objectives: Existing research indicates that the existence of adversarial examples causes Synthetic Aperture Radar (SAR) target recognition models based on Deep Neural Networks (DNNs) to make erroneous predictions, seriously affecting recognition accuracy and robustness. However, existing adversarial generation methods in the image domain suffer from insufficient spatial constraints, perturbation sparsity, and physical realism. To address these issues, an amplitude modulation-guided adversarial example generation method for SAR imagery, called SARAMAE, is proposed. Methods: First, to address spatial constraints, the maximum inter-class variance algorithm (OTSU) and morphological operations are combined to extract target region masks, restricting perturbation positions strictly to the target's effective scattering area. Second, to address perturbation sparsity, an adversarial attack framework based on the parametric scattering center model is constructed, directly utilizing scattering center spatial positions and scattering amplitudes as optimization variables, and the Differential Evolution (DE) algorithm is employed to search within the physical parameter space for the optimal scattering distribution that maximizes interference with target feature extraction, while an adaptive strategy dynamically modulates scattering amplitude to ensure imperceptibility. Finally, to address physical realism, the dynamic range of the SAR system is incorporated to physically constrain the modulation range of scattering center amplitudes, and radar echo simulation is used to verify the effectiveness and physical consistency of adversarial perturbations in the signal imaging link. Results: Extensive experimental evaluations are conducted on ten distinct classification models, encompassing both Convolutional Neural Network (CNN) and Transformer architectures. The experimental results demonstrate that the proposed method achieves an average attack success rate of 35.81% by perturbing only a minimal number of pixel values within the images. The quantitative analysis reveals that the generated adversarial examples not only possess high attack efficacy but also exhibit significant transferability across different model architectures. Conclusions: Overall, this study establishes the mapping relationship between image-domain perturbations and the physical characteristics of radar echoes, verifies the feasibility of generating adversarial examples with physical attributes within the signal imaging link, and provides an effective means for evaluating the security of SAR intelligent recognition systems in realistic scenarios.

     

/

返回文章
返回