SAR-GPA: SAR Generation Perturbation Algorithm
The deep learning is widely used in optical image and synthetic aperture radar (SAR) image. Current academic research shows that adversarial perturbation can effectively attack the deep learning network in optical image. However, in SAR image target recognition network, the existence of universal perturbations and generation approach needs to be further explored. Here, this article firstly proposes a systematic SAR generation perturbation algorithm (SAR-GPA) for target recognition network. The modulation phase sequences of the jamming points can vary casually by using the state-of-the-art electromagnetic metasurface technology. Therefore, when it acts on the SAR deceptive jamming system, it can produce artificial controllable perturbations. First, we take the imperceptible perturbations from universal adversarial perturbations (UAP) as reference to construct a unconstrained minimum optimization problem to find the specific sequences. Then, we solve this issue by adaptive moment estimation (Adam) optimizer.Thus, the SAR adversarial examples can be quickly and flexibly generated through our system. Finally, We design a series of simulation and experiment to verify the effectiveness of the adversarial examples and also the modulation sequences. According to the results, different from the traditional SAR blanket jamming methods, our approach can quickly generate imperceptible jamming, which can effectively attack three classical recognition models.
Code (0)
등록된 구현이 없습니다.
Similar Papers 제목 키워드 기반
Fast-UAP: An Algorithm for Speeding up Universal Adversarial Perturbation Generation with Orientation of Perturbation Vectors
Convolutional neural networks (CNN) have become one of the most popular machine learning tools and are being applied in various tasks, however, CNN models are vulnerable to universal perturbations, which are usually huma…
Anti-Tamper Protection for Unauthorized Individual Image Generation
With the advancement of personalized image generation technologies, concerns about forgery attacks that infringe on portrait rights and privacy are growing. To address these concerns, protection perturbation algorithms h…
Personalized Image GenerationIWA: Integrated Gradient based White-box Attacks for Fooling Deep Neural Networks
The widespread application of deep neural network (DNN) techniques is being challenged by adversarial examples, the legitimate input added with imperceptible and well-designed perturbations that can fool DNNs easily in t…
DNN TestingOn the Matrix-Free Generation of Adversarial Perturbations for Black-Box Attacks
In general, adversarial perturbations superimposed on inputs are realistic threats for a deep neural network (DNN). In this paper, we propose a practical generation method of such adversarial perturbation to be applied t…
Semantic SegmentationSemantic Preserving Adversarial Attack Generation with Autoencoder and Genetic Algorithm
Widely used deep learning models are found to have poor robustness. Little noises can fool state-of-the-art models into making incorrect predictions. While there is a great deal of high-performance attack generation meth…
Adversarial Attack