SAR对抗攻击方法综述及发展趋势

    A Comprehensive Review and Development Trends of SAR Adversarial Attack Methods

    • 摘要: 随着人工智能技术的快速发展,基于深度学习的合成孔径雷达(SAR)自动目标识别(ATR)方法在SAR图像解译中取得了显著成效。通过在原始SAR图像中引入人眼难以分辨的微小扰动,容易导致SAR-ATR模型识别错误,即受到对抗攻击的影响。当前,对抗攻击技术逐渐应用于SAR-ATR领域。文中首先系统梳理了SAR图像对抗攻击的国内外研究现状,深入剖析了不同算法的原理、优劣特性与适用场景;其次利用公开数据集,开展针对典型SAR对抗攻击算法的性能评估;最后针对现有算法存在的局限性,提出五点该领域值得研究的问题。该文可为复数域、跨数据域、跨任务场景下的对抗攻击研究,建立数字域与物理域的多元联系机制,以及模型鲁棒性增强与评测体系完善等后续工作提供理论参考。

       

      Abstract: With the rapid development of artificial intelligence technology, the deep learning-based automatic target recognition (ATR) method for synthetic aperture radar (SAR) has achieved remarkable results in SAR image interpretation. However, introducing subtle perturbations that are imperceptible to human eye into original SAR images can easily lead to recognition errors in SAR-ATR models, indicating that these models are affected by adversarial attacks. At present, adversarial attack techniques are increasingly being applied in the SAR-ATR field. Firstly, the current research status of SAR image adversarial attack both at home and abroad is systematically reviewed, and the principles, advantages, disadvantages, and applicable scenarios of different algorithms are deeply analyzed in the paper. Secondly, performance evaluation of typical SAR adversarial attack algorithms is carried out using publicly available datasets. Finally, considering the limitations of existing algorithms, five topics worthy of study in this field are proposed, which can provide theoretical reference for subsequent studies such as conducting research on adversarial attacks in complex domain, cross-data domain and cross-task scenarios, establishing a multi-dimensional connection mechanism between digital and physical domains, as well as enhancing model robustness and improving the evaluation system.

       

    /

    返回文章
    返回