LI Haifeng, CUI Jiahao, GUO Wang, ZHANG Keyi, WANG Qi, MENG Lingquan, ZHOU Yihan. Amplitude Modulation-Guided Adversarial Example Generation Method for SAR ImageryJ. Geomatics and Information Science of Wuhan University. DOI: 10.13203/j.whugis20260053
Citation: LI Haifeng, CUI Jiahao, GUO Wang, ZHANG Keyi, WANG Qi, MENG Lingquan, ZHOU Yihan. Amplitude Modulation-Guided Adversarial Example Generation Method for SAR ImageryJ. Geomatics and Information Science of Wuhan University. DOI: 10.13203/j.whugis20260053

Amplitude Modulation-Guided Adversarial Example Generation Method for SAR Imagery

  • Objectives: Existing research indicates that the existence of adversarial examples causes Synthetic Aperture Radar (SAR) target recognition models based on Deep Neural Networks (DNNs) to make erroneous predictions, seriously affecting recognition accuracy and robustness. However, existing adversarial generation methods in the image domain suffer from insufficient spatial constraints, perturbation sparsity, and physical realism. To address these issues, an amplitude modulation-guided adversarial example generation method for SAR imagery, called SARAMAE, is proposed. Methods: First, to address spatial constraints, the maximum inter-class variance algorithm (OTSU) and morphological operations are combined to extract target region masks, restricting perturbation positions strictly to the target's effective scattering area. Second, to address perturbation sparsity, an adversarial attack framework based on the parametric scattering center model is constructed, directly utilizing scattering center spatial positions and scattering amplitudes as optimization variables, and the Differential Evolution (DE) algorithm is employed to search within the physical parameter space for the optimal scattering distribution that maximizes interference with target feature extraction, while an adaptive strategy dynamically modulates scattering amplitude to ensure imperceptibility. Finally, to address physical realism, the dynamic range of the SAR system is incorporated to physically constrain the modulation range of scattering center amplitudes, and radar echo simulation is used to verify the effectiveness and physical consistency of adversarial perturbations in the signal imaging link. Results: Extensive experimental evaluations are conducted on ten distinct classification models, encompassing both Convolutional Neural Network (CNN) and Transformer architectures. The experimental results demonstrate that the proposed method achieves an average attack success rate of 35.81% by perturbing only a minimal number of pixel values within the images. The quantitative analysis reveals that the generated adversarial examples not only possess high attack efficacy but also exhibit significant transferability across different model architectures. Conclusions: Overall, this study establishes the mapping relationship between image-domain perturbations and the physical characteristics of radar echoes, verifies the feasibility of generating adversarial examples with physical attributes within the signal imaging link, and provides an effective means for evaluating the security of SAR intelligent recognition systems in realistic scenarios.
  • loading

Catalog

    /

    DownLoad:  Full-Size Img  PowerPoint
    Return
    Return