{"title":"Towards Robust Synthetic Aperture Radar Classification: Counteracting Black-Box Adversarial Attacks","authors":"Kaijie Wang, Yingwen Wu, Jie Yang, Xiaolin Huang","doi":"10.1049/rsn2.70062","DOIUrl":null,"url":null,"abstract":"<p>Synthetic Aperture Radar (SAR) image classification using deep neural networks (DNNs) has demonstrated vulnerability to adversarial attacks, particularly black-box attacks, which rely solely on model output scores to craft effective perturbations. Despite their practical threat, defences against such attacks in SAR tasks remain underexplored. To bridge this gap, we propose a novel defence mechanism that introduces a pointwise modulation layer to enforce gradient orthogonality, thereby disrupting the gradient estimation process employed in black-box attacks. This method preserves high accuracy on clean data by maintaining logit consistency while significantly reducing attack success rates. Furthermore, the approach is computationally efficient and can be easily integrated into existing models. Extensive experiments demonstrate the effectiveness of the proposed method in enhancing the robustness of SAR classifiers against a range of black-box attack scenarios, without compromising their performance on clean data. This work contributes to the development of secure and reliable SAR-based machine learning systems for critical applications.</p>","PeriodicalId":50377,"journal":{"name":"Iet Radar Sonar and Navigation","volume":"19 1","pages":""},"PeriodicalIF":1.5000,"publicationDate":"2025-07-29","publicationTypes":"Journal Article","fieldsOfStudy":null,"isOpenAccess":false,"openAccessPdf":"https://onlinelibrary.wiley.com/doi/epdf/10.1049/rsn2.70062","citationCount":"0","resultStr":null,"platform":"Semanticscholar","paperid":null,"PeriodicalName":"Iet Radar Sonar and Navigation","FirstCategoryId":"94","ListUrlMain":"https://ietresearch.onlinelibrary.wiley.com/doi/10.1049/rsn2.70062","RegionNum":4,"RegionCategory":"管理学","ArticlePicture":[],"TitleCN":null,"AbstractTextCN":null,"PMCID":null,"EPubDate":"","PubModel":"","JCR":"Q3","JCRName":"ENGINEERING, ELECTRICAL & ELECTRONIC","Score":null,"Total":0}
引用次数: 0
Abstract
Synthetic Aperture Radar (SAR) image classification using deep neural networks (DNNs) has demonstrated vulnerability to adversarial attacks, particularly black-box attacks, which rely solely on model output scores to craft effective perturbations. Despite their practical threat, defences against such attacks in SAR tasks remain underexplored. To bridge this gap, we propose a novel defence mechanism that introduces a pointwise modulation layer to enforce gradient orthogonality, thereby disrupting the gradient estimation process employed in black-box attacks. This method preserves high accuracy on clean data by maintaining logit consistency while significantly reducing attack success rates. Furthermore, the approach is computationally efficient and can be easily integrated into existing models. Extensive experiments demonstrate the effectiveness of the proposed method in enhancing the robustness of SAR classifiers against a range of black-box attack scenarios, without compromising their performance on clean data. This work contributes to the development of secure and reliable SAR-based machine learning systems for critical applications.
期刊介绍:
IET Radar, Sonar & Navigation covers the theory and practice of systems and signals for radar, sonar, radiolocation, navigation, and surveillance purposes, in aerospace and terrestrial applications.
Examples include advances in waveform design, clutter and detection, electronic warfare, adaptive array and superresolution methods, tracking algorithms, synthetic aperture, and target recognition techniques.