Attention Heat Map-Based Black-Box Local Adversarial Attack for Synthetic Aperture Radar Target Recognition

被引:0
|
作者
Wan, Xuanshen [1 ]
Liu, Wei [1 ]
Niu, Chaoyang [1 ]
Lu, Wanjie [1 ]
机构
[1] Informat Engn Univ, Zhengzhou, Peoples R China
来源
关键词
CONVOLUTIONAL NEURAL-NETWORK;
D O I
10.14358/PERS.24-00015R2
中图分类号
P9 [自然地理学];
学科分类号
0705 ; 070501 ;
摘要
Synthetic aperture radar (SAR) automatic target recognition (ATR) models based on deep neural networks (DNNs) are susceptible to adversarial attacks. In this study, we proposed an SAR black-box local adversarial attack algorithm named attention heat map- based black-box local adversarial attack (AH-BLAA). First, we designed an attention heat map extraction module combined with the layer-wise relevance propagation (LRP) algorithm to obtain the high concerning areas of the SAR-ATR models. Then, to generate SAR adversarial attack examples, we designed a perturbation generator module, introducing the structural dissimilarity (DSSIM) metric in the loss function to limit image distortion and the differential evolution (DE) algorithm to search for optimal perturbations. Experimental results on the MSTAR and FUSAR-Ship datasets showed that compared with existing adversarial attack algorithms, the attack success rate of the AH-BLAA algorithm increased by 0.63% to 33.59% and 1.05% to 17.65%, respectively. Moreover, the lowest perturbation ratios reached 0.23% and 0.13%, respectively.
引用
收藏
页码:601 / 609
页数:56
相关论文
共 50 条
  • [21] RLVS: A Reinforcement Learning-Based Sparse Adversarial Attack Method for Black-Box Video Recognition
    Song, Jianxin
    Yu, Dan
    Teng, Hongfei
    Chen, Yongle
    ELECTRONICS, 2025, 14 (02):
  • [22] Multi-task Learning-based Black-box Adversarial Attack on Face Recognition Systems
    Kong, Jiefang
    Wang, Huabin
    Zhou, Jiacheng
    Tao, Liang
    Zhang, Jingjing
    2024 9TH INTERNATIONAL CONFERENCE ON SIGNAL AND IMAGE PROCESSING, ICSIP, 2024, : 554 - 558
  • [23] Multilevel Attention Networks for Synthetic Aperture Radar Automatic Target Recognition
    Guo, Yuxia
    Zeng, Zhiqiang
    Jin, Mingming
    Sun, Jinping
    Meng, Zhongjie
    Hong, Wen
    IEEE GEOSCIENCE AND REMOTE SENSING LETTERS, 2024, 21
  • [24] Transferable Black-Box Attack Against Face Recognition With Spatial Mutable Adversarial Patch
    Ma, Haotian
    Xu, Ke
    Jiang, Xinghao
    Zhao, Zeyu
    Sun, Tanfeng
    IEEE TRANSACTIONS ON INFORMATION FORENSICS AND SECURITY, 2023, 18 : 5636 - 5650
  • [25] Black-box Adversarial Attack Against Road Sign Recognition Model via PSO
    Chen J.-Y.
    Chen Z.-Q.
    Zheng H.-B.
    Shen S.-J.
    Su M.-M.
    Ruan Jian Xue Bao/Journal of Software, 2020, 31 (09): : 2785 - 2801
  • [26] Reputation Defender: Local Black-Box Adversarial Attack against Image-Translation-Based DeepFake
    Yang, Wang
    Zhao, Lingchen
    Ye, Dengpan
    2024 IEEE INTERNATIONAL CONFERENCE ON MULTIMEDIA AND EXPO, ICME 2024, 2024,
  • [27] An Optimized Black-Box Adversarial Simulator Attack Based on Meta-Learning
    Chen, Zhiyu
    Ding, Jianyu
    Wu, Fei
    Zhang, Chi
    Sun, Yiming
    Sun, Jing
    Liu, Shangdong
    Ji, Yimu
    ENTROPY, 2022, 24 (10)
  • [28] Boosting Decision-Based Black-Box Adversarial Attack with Gradient Priors
    Liu, Han
    Huang, Xingshuo
    Zhang, Xiaotong
    Li, Qimai
    Ma, Fenglong
    Wang, Wei
    Chen, Hongyang
    Yu, Hong
    Zhang, Xianchao
    PROCEEDINGS OF THE THIRTY-SECOND INTERNATIONAL JOINT CONFERENCE ON ARTIFICIAL INTELLIGENCE, IJCAI 2023, 2023, : 1195 - 1203
  • [29] Greedy-Based Black-Box Adversarial Attack Scheme on Graph Structure
    Shao, Shushu
    Xia, Hui
    Zhang, Rui
    Cheng, Xiangguo
    WIRELESS ALGORITHMS, SYSTEMS, AND APPLICATIONS, WASA 2021, PT II, 2021, 12938 : 96 - 106
  • [30] SUBSTITUTE MODEL GENERATION FOR BLACK-BOX ADVERSARIAL ATTACK BASED ON KNOWLEDGE DISTILLATION
    Cui, Weiyu
    Li, Xiaorui
    Huang, Jiawei
    Wang, Wenyi
    Wang, Shuai
    Chen, Jianwen
    2020 IEEE INTERNATIONAL CONFERENCE ON IMAGE PROCESSING (ICIP), 2020, : 648 - 652