Next Article in Journal
Synthetic-Aperture Radar Radio-Frequency Interference Suppression Based on Regularized Optimization Feature Decomposition Network
Previous Article in Journal
Characterisation of Two Vineyards in Mexico Based on Sentinel-2 and Meteorological Data
 
 
Font Type:
Arial Georgia Verdana
Font Size:
Aa Aa Aa
Line Spacing:
Column Width:
Background:
This is an early access version, the complete PDF, HTML, and XML versions will be available soon.
Article

Enhancing Transferability with Intra-Class Transformations and Inter-Class Nonlinear Fusion on SAR Images

1
School of Electronic Science, National University of Defense Technology (NUDT), Changsha 410073, China
2
Test Center, National University of Defense Technology (NUDT), Xi’an 710100, China
*
Author to whom correspondence should be addressed.
Remote Sens. 2024, 16(14), 2539; https://doi.org/10.3390/rs16142539
Submission received: 21 May 2024 / Revised: 22 June 2024 / Accepted: 27 June 2024 / Published: 10 July 2024
(This article belongs to the Section Remote Sensing Image Processing)

Abstract

Recent research has revealed that the deep neural network (DNN)-based synthetic-aperture radar (SAR) automatic target recognition (ATR) techniques are vulnerable to adversarial examples, which poses significant security risks for their deployment in real-world systems. At the same time, the adversarial examples often exhibit transferability across DNN models, whereby when they are generated on the surrogate model they can also attack other target models. As the significant property in black-box scenarios, transferability has been enhanced by various methods, among which input transformations have demonstrated excellent effectiveness. However, we find that existing transformations suffer from limited enhancement of transferability due to the unique imaging mechanism and scattering characteristics of SAR images. To overcome this issue, we propose a novel method called intra-class transformations and inter-class nonlinear fusion attack (ITINFA). It enhances transferability from two perspectives: intra-class single image transformations and inter-class multiple images fusion. The intra-class transformations module utilizes a series of diverse transformations that align with the intrinsic characteristics of SAR images to obtain a more stable gradient update direction and prevent the adversarial examples from overfitting the surrogate model. The inter-class fusion strategy incorporates the information from other categories in a nonlinear manner, effectively enhances the feature fusion effect, and guides the misclassification of adversarial examples. Extensive experiments on the MSTAR dataset and SEN1-2 dataset demonstrate that ITINFA exhibits significantly better transferability than the existing transfer-based methods, with the average transfer attack success rate increases exceeding 8% for single models and over 4% for ensemble models.
Keywords: synthetic-aperture radar; automatic target recognition; adversarial attack; deep neural network; transferability synthetic-aperture radar; automatic target recognition; adversarial attack; deep neural network; transferability

Share and Cite

MDPI and ACS Style

Huang, X.; Lu, Z.; Peng, B. Enhancing Transferability with Intra-Class Transformations and Inter-Class Nonlinear Fusion on SAR Images. Remote Sens. 2024, 16, 2539. https://doi.org/10.3390/rs16142539

AMA Style

Huang X, Lu Z, Peng B. Enhancing Transferability with Intra-Class Transformations and Inter-Class Nonlinear Fusion on SAR Images. Remote Sensing. 2024; 16(14):2539. https://doi.org/10.3390/rs16142539

Chicago/Turabian Style

Huang, Xichen, Zhengzhi Lu, and Bo Peng. 2024. "Enhancing Transferability with Intra-Class Transformations and Inter-Class Nonlinear Fusion on SAR Images" Remote Sensing 16, no. 14: 2539. https://doi.org/10.3390/rs16142539

Note that from the first issue of 2016, this journal uses article numbers instead of page numbers. See further details here.

Article Metrics

Back to TopTop