Black-Box Universal Adversarial Attack for DNN-Based Models of SAR Automatic Target Recognition

被引:1
|
作者
Wan, Xuanshen [1 ]
Liu, Wei [1 ]
Niu, Chaoyang [1 ]
Lu, Wanjie [1 ]
Du, Meng [1 ]
Li, Yuanli [1 ]
机构
[1] Informat Engn Univ, Zhengzhou 450001, Peoples R China
基金
中国国家自然科学基金;
关键词
Closed box; Generators; Attenuators; Perturbation methods; Radar polarimetry; Target recognition; Generative adversarial networks; Adversarial example; automatic target recognition; deep neural network (DNN); synthetic aperture radar (SAR); transferability; universal adversarial perturbation (UAP);
D O I
10.1109/JSTARS.2024.3384188
中图分类号
TM [电工技术]; TN [电子技术、通信技术];
学科分类号
0808 ; 0809 ;
摘要
Synthetic aperture radar automatic target recognition (SAR-ATR) models based on deep neural networks (DNNs) are vulnerable to attacks of adversarial examples. Universal adversarial attack algorithms can help evaluate and improve the robustness of the SAR-ATR models and have become a research hotspot. However, current universal adversarial attack algorithms have limitations. First, considering the difficulty in obtaining information on the attacking SAR-ATR models, there is an urgent need to design a universal adversarial attack algorithm under a black-box scenario. Second, given the difficulty of acquiring synthetic aperture radar images, the effectiveness of attacks under small-sample conditions requires improvement. To address these limitations, this study proposed a black-box universal adversarial attack algorithm: transferable universal adversarial network (TUAN). Based on the idea of the generative adversarial network, we implemented the game of generator and attenuator to improve the transferability of universal adversarial perturbation (UAP). We designed loss functions for the generator and the attenuator, respectively, which can effectively improve the success rate of black-box attacks and the stealthiness of attacks. In addition, U-Net was used as a network structure of the generator and the attenuator to fully learn the distribution of examples, thereby enhancing the attack success rate under small-sample conditions. The TUAN attained a higher black-box attack success rate and superior stealthiness than up-to-date UAP algorithms in non-targeted and targeted attacks.
引用
收藏
页码:8673 / 8696
页数:24
相关论文
共 50 条
  • [1] An adversarial attack on DNN-based black-box object detectors
    Wang, Yajie
    Tan, Yu-an
    Zhang, Wenjiao
    Zhao, Yuhang
    Kuang, Xiaohui
    [J]. JOURNAL OF NETWORK AND COMPUTER APPLICATIONS, 2020, 161
  • [2] An Empirical Study of Fully Black-Box and Universal Adversarial Attack for SAR Target Recognition
    Peng, Bowen
    Peng, Bo
    Yong, Shaowei
    Liu, Li
    [J]. REMOTE SENSING, 2022, 14 (16)
  • [3] TAN: A Transferable Adversarial Network for DNN-Based UAV SAR Automatic Target Recognition Models
    Du, Meng
    Sun, Yuxin
    Sun, Bing
    Wu, Zilong
    Luo, Lan
    Bi, Daping
    Du, Mingyang
    [J]. DRONES, 2023, 7 (03)
  • [4] Black-box Universal Adversarial Attack on Text Classifiers
    Zhang, Yu
    Shao, Kun
    Yang, Junan
    Liu, Hui
    [J]. 2021 2ND ASIA CONFERENCE ON COMPUTERS AND COMMUNICATIONS (ACCC 2021), 2021, : 1 - 5
  • [5] Adversarial Eigen Attack on Black-Box Models
    Zhou, Linjun
    Cui, Peng
    Zhang, Xingxuan
    Jiang, Yinan
    Yang, Shiqiang
    [J]. 2022 IEEE/CVF CONFERENCE ON COMPUTER VISION AND PATTERN RECOGNITION (CVPR 2022), 2022, : 15233 - 15241
  • [6] Reinforcement Learning Based Sparse Black-box Adversarial Attack on Video Recognition Models
    Wang, Zeyuan
    Sha, Chaofeng
    Yang, Su
    [J]. PROCEEDINGS OF THE THIRTIETH INTERNATIONAL JOINT CONFERENCE ON ARTIFICIAL INTELLIGENCE, IJCAI 2021, 2021, : 3162 - 3168
  • [7] Black-box Adversarial Attack on License Plate Recognition System
    Chen, Jin-Yin
    Shen, Shi-Jing
    Su, Meng-Meng
    Zheng, Hai-Bin
    Xiong, Hui
    [J]. Zidonghua Xuebao/Acta Automatica Sinica, 2021, 47 (01): : 121 - 135
  • [8] Black-box Adversarial Attacks on Video Recognition Models
    Jiang, Linxi
    Ma, Xingjun
    Chen, Shaoxiang
    Bailey, James
    Jiang, Yu-Gang
    [J]. PROCEEDINGS OF THE 27TH ACM INTERNATIONAL CONFERENCE ON MULTIMEDIA (MM'19), 2019, : 864 - 872
  • [9] Hard-label Black-box Universal Adversarial Patch Attack
    Tao, Guanhong
    An, Shengwei
    Cheng, Siyuan
    Shen, Guangyu
    Zhang, Xiangyu
    [J]. PROCEEDINGS OF THE 32ND USENIX SECURITY SYMPOSIUM, 2023, : 697 - 714
  • [10] Data-free Universal Adversarial Perturbation and Black-box Attack
    Zhang, Chaoning
    Benz, Philipp
    Karjauv, Adil
    Kweon, In So
    [J]. 2021 IEEE/CVF INTERNATIONAL CONFERENCE ON COMPUTER VISION (ICCV 2021), 2021, : 7848 - 7857