DE-JSMA:面向 SAR-ATR 模型的稀疏对抗攻击算法

Xiaying Jin, Yang Li, Quan Pan

科研成果: 期刊稿件文章同行评审

1 引用 (Scopus)

摘要

The vulnerability of DNN makes the SAR-ATR system that uses an intelligent algorithm for recognition also somewhat vulnerable. In order to verify the vulnerability, this paper proposes DE-JSMA, a novel sparse adversarial attack algorithm based on a salient map′s adversarial attack algorithm and differential evolution algorithm, with the synthetic aperture radar (SAR) image feature sparsity considered. After accurately screening out the salient features that have a great impact on the model inference results, the DE-JSMA algorithm optimizes the appropriate feature values for the salient features. In order to verify its effectiveness more comprehensively, a new metric that combines the attack success rate with the average confidence interval of adversarial examples is proposed. The experimental results show that DE-JSMA extends JSMA, which can be used only for targeted attack scenario, to untargeted attack scenario without increasing too much time consumption but ensuring a high attack success rate, thus achieving sparse adversarial attack with higher reliability and better sparsity in both attack scenarios. The pixel perturbations of only 0.31% and 0.85% can achieve the untargeted and targeted attack success rates up to 100% and 78.79% respectively.

投稿的翻译标题DE-JSMA: a sparse adversarial attack algorithm for SAR-ATR models
源语言繁体中文
页(从-至)1170-1178
页数9
期刊Xibei Gongye Daxue Xuebao/Journal of Northwestern Polytechnical University
41
6
DOI
出版状态已出版 - 12月 2023

关键词

  • adversarial attack
  • automatic target recognition
  • deep learning
  • sparse attack
  • synthetic aperture radar

指纹

探究 'DE-JSMA:面向 SAR-ATR 模型的稀疏对抗攻击算法' 的科研主题。它们共同构成独一无二的指纹。

引用此