paper-with-me

홈 › Papers

Towards Assessing the Synthetic-to-Measured Adversarial Vulnerability of SAR ATR

2024-01-30 · Bowen Peng, Bo Peng, Jingyuan Xia, Tianpeng Liu, Yongxiang Liu, Li Liu

Recently, there has been increasing concern about the vulnerability of deep neural network (DNN)-based synthetic aperture radar (SAR) automatic target recognition (ATR) to adversarial attacks, where a DNN could be easily deceived by clean input with imperceptible but aggressive perturbations. This paper studies the synthetic-to-measured (S2M) transfer setting, where an attacker generates adversarial perturbation based solely on synthetic data and transfers it against victim models trained with measured data. Compared with the current measured-to-measured (M2M) transfer setting, our approach does not need direct access to the victim model or the measured SAR data. We also propose the transferability estimation attack (TEA) to uncover the adversarial risks in this more challenging and practical scenario. The TEA makes full use of the limited similarity between the synthetic and measured data pairs for blind estimation and optimization of S2M transferability, leading to feasible surrogate model enhancement without mastering the victim model and data. Comprehensive evaluations based on the publicly available synthetic and measured paired labeled experiment (SAMPLE) dataset demonstrate that the TEA outperforms state-of-the-art methods and can significantly enhance various attack algorithms in computer vision and remote sensing applications. Codes and data are available at https://github.com/scenarri/S2M-TEA.

📄 PDF Abstract BibTeX arXiv:2401.17038

Code (1)

scenarri/s2m-tea 공식 구현 pytorch

Similar Papers 제목 키워드 기반

Backbone is All You Need: Assessing Vulnerabilities of Frozen Foundation Models in Synthetic Image Forensics

2026-05-13 · Chiara Musso, Joy Battocchio, Andrea Montibeller, Giulia Boato arxiv

As AI-generated synthetic images become increasingly realistic, Vision Transformers (ViTs) have emerged as a cornerstone of modern deepfake detection. However, the prevailing reliance on frozen, pre-trained backbones int…

Adversarial AttackDeepFake DetectionFew-Shot Learning

On the Validity of Traditional Vulnerability Scoring Systems for Adversarial Attacks against LLMs

2024-12-28 · Atmane Ayoub Mansour Bahar, Ahmad Samer Wazan

This research investigates the effectiveness of established vulnerability metrics, such as the Common Vulnerability Scoring System (CVSS), in evaluating attacks against Large Language Models (LLMs), with a focus on Adver…

Improving Robustness of Jet Tagging Algorithms with Adversarial Training

2022-03-25 · Annika Stein, Xavier Coubez, Spandan Mondal, Andrzej Novak 외

Deep learning is a standard tool in the field of high-energy physics, facilitating considerable sensitivity enhancements for numerous analysis strategies. In particular, in identification of physics objects, such as jet …

ClassificationJet Tagging

Towards Understanding the Robustness Against Evasion Attack on Categorical Data

2021-09-29 · ICLR 2022 4 · Hongyan Bao, Yufei Han, Yujun Zhou, Yun Shen 외

Characterizing and assessing the adversarial vulnerability of classification models with categorical input has been a practically important, while rarely explored research problem. Our work echoes the challenge by first …

Classification

Derivation of Information-Theoretically Optimal Adversarial Attacks with Applications to Robust Machine Learning

2020-07-28 · Jirong Yi, Raghu Mudumbai, Weiyu Xu

We consider the theoretical problem of designing an optimal adversarial attack on a decision system that maximally degrades the achievable performance of the system as measured by the mutual information between the degra…

Adversarial AttackBIG-bench Machine LearningFeature Compression