跳到主要导航 跳到搜索 跳到主要内容

Towards data-free and model-agnostic black-box attacks against SAR-ATR via dual-diversity augmentation

  • Xiaoxuan Zhang
  • , Yang Li
  • , Zhi Liang Zhao
  • North University of China
  • Ministry of Education of the People's Republic of China

科研成果: 期刊稿件文章同行评审

摘要

The vulnerability of deep neural networks (DNNs) to adversarial examples is a growing concern in synthetic aperture radar automatic target recognition (SAR-ATR). Given the rigorous data-free and model-agnostic black-box (DFMABB) attack scenario, where the internal parameters, architecture, outputs, or training data of the target victim model are completely inaccessible, and only a similar source domain is available, this paper proposes a novel generative attack method via dual-diversity augmentation (DDA) to systematically enhance adversarial transferability. The proposed DDA comprises two key components: instance diversity augmentation (IDA) and feature diversity augmentation (FDA). Specifically, IDA applies identical transformations to clean and adversarial examples to mitigate overfitting caused by SAR data scarcity to the source surrogate model. Meanwhile, FDA diversifies adversarial features through coordinated mixup and masking to construct perturbation patterns robust to inconsistent feature responses. Comprehensive experimental results demonstrate that DDA outperforms state-of-the-art methods in the DFMABB attack scenario across diverse models, architectures, and datasets.

源语言英语
页(从-至)282-299
页数18
期刊ISPRS Journal of Photogrammetry and Remote Sensing
238
DOI
出版状态已出版 - 8月 2026

指纹

探究 'Towards data-free and model-agnostic black-box attacks against SAR-ATR via dual-diversity augmentation' 的科研主题。它们共同构成独一无二的指纹。

引用此