Abstract
The vulnerability of deep neural networks (DNNs) to adversarial examples is a growing concern in synthetic aperture radar automatic target recognition (SAR-ATR). Given the rigorous data-free and model-agnostic black-box (DFMABB) attack scenario, where the internal parameters, architecture, outputs, or training data of the target victim model are completely inaccessible, and only a similar source domain is available, this paper proposes a novel generative attack method via dual-diversity augmentation (DDA) to systematically enhance adversarial transferability. The proposed DDA comprises two key components: instance diversity augmentation (IDA) and feature diversity augmentation (FDA). Specifically, IDA applies identical transformations to clean and adversarial examples to mitigate overfitting caused by SAR data scarcity to the source surrogate model. Meanwhile, FDA diversifies adversarial features through coordinated mixup and masking to construct perturbation patterns robust to inconsistent feature responses. Comprehensive experimental results demonstrate that DDA outperforms state-of-the-art methods in the DFMABB attack scenario across diverse models, architectures, and datasets.
| Original language | English |
|---|---|
| Pages (from-to) | 282-299 |
| Number of pages | 18 |
| Journal | ISPRS Journal of Photogrammetry and Remote Sensing |
| Volume | 238 |
| DOIs | |
| State | Published - Aug 2026 |
Keywords
- Black-box attack
- Deep neural networks
- Diversity instances and features
- Generative adversarial attack
- Synthetic aperture radar
- Transferability
Fingerprint
Dive into the research topics of 'Towards data-free and model-agnostic black-box attacks against SAR-ATR via dual-diversity augmentation'. Together they form a unique fingerprint.Cite this
- APA
- Author
- BIBTEX
- Harvard
- Standard
- RIS
- Vancouver