TY - JOUR
T1 - Towards data-free and model-agnostic black-box attacks against SAR-ATR via dual-diversity augmentation
AU - Zhang, Xiaoxuan
AU - Li, Yang
AU - Zhao, Zhi Liang
N1 - Publisher Copyright:
© 2026 International Society for Photogrammetry and Remote Sensing, Inc. (ISPRS). Published by Elsevier B.V. All rights are reserved, including those for text and data mining, AI training, and similar technologies.
PY - 2026/8
Y1 - 2026/8
N2 - The vulnerability of deep neural networks (DNNs) to adversarial examples is a growing concern in synthetic aperture radar automatic target recognition (SAR-ATR). Given the rigorous data-free and model-agnostic black-box (DFMABB) attack scenario, where the internal parameters, architecture, outputs, or training data of the target victim model are completely inaccessible, and only a similar source domain is available, this paper proposes a novel generative attack method via dual-diversity augmentation (DDA) to systematically enhance adversarial transferability. The proposed DDA comprises two key components: instance diversity augmentation (IDA) and feature diversity augmentation (FDA). Specifically, IDA applies identical transformations to clean and adversarial examples to mitigate overfitting caused by SAR data scarcity to the source surrogate model. Meanwhile, FDA diversifies adversarial features through coordinated mixup and masking to construct perturbation patterns robust to inconsistent feature responses. Comprehensive experimental results demonstrate that DDA outperforms state-of-the-art methods in the DFMABB attack scenario across diverse models, architectures, and datasets.
AB - The vulnerability of deep neural networks (DNNs) to adversarial examples is a growing concern in synthetic aperture radar automatic target recognition (SAR-ATR). Given the rigorous data-free and model-agnostic black-box (DFMABB) attack scenario, where the internal parameters, architecture, outputs, or training data of the target victim model are completely inaccessible, and only a similar source domain is available, this paper proposes a novel generative attack method via dual-diversity augmentation (DDA) to systematically enhance adversarial transferability. The proposed DDA comprises two key components: instance diversity augmentation (IDA) and feature diversity augmentation (FDA). Specifically, IDA applies identical transformations to clean and adversarial examples to mitigate overfitting caused by SAR data scarcity to the source surrogate model. Meanwhile, FDA diversifies adversarial features through coordinated mixup and masking to construct perturbation patterns robust to inconsistent feature responses. Comprehensive experimental results demonstrate that DDA outperforms state-of-the-art methods in the DFMABB attack scenario across diverse models, architectures, and datasets.
KW - Black-box attack
KW - Deep neural networks
KW - Diversity instances and features
KW - Generative adversarial attack
KW - Synthetic aperture radar
KW - Transferability
UR - https://www.scopus.com/pages/publications/105039161019
U2 - 10.1016/j.isprsjprs.2026.05.006
DO - 10.1016/j.isprsjprs.2026.05.006
M3 - 文章
AN - SCOPUS:105039161019
SN - 0924-2716
VL - 238
SP - 282
EP - 299
JO - ISPRS Journal of Photogrammetry and Remote Sensing
JF - ISPRS Journal of Photogrammetry and Remote Sensing
ER -