A Two-Step Adversarial Sample Detection Technique for SAR Image Classification
CSTR:
Author:
Affiliation:

College of Computer Science and Technology, Nanjing University of Aeronautics & Astronautics, Nanjing 211106, China

Clc Number:

TP391

Fund Project:

  • Article
  • |
  • Figures
  • |
  • Metrics
  • |
  • Reference
  • |
  • Related
  • |
  • Cited by
  • |
  • Materials
  • |
  • Comments
    Abstract:

    Deep learning techniques have greatly improved the classification accuracy of synthetic aperture radar (SAR) images target, but the security of SAR image classification systems is threatened by the inherent vulnerability of neural networks. In this paper, we analyze the aggressiveness of SAR adversarial samples, and the difference between SAR adversarial examples and original examples in the frequency domain. With the analysis results, a two-step SAR adversarial samples detection technique is proposed to improve the security of SAR classification models. The first step of adversarial sample detection is performed on the input image based on the frequency domain analysis to separate the adversarial samples. Then, the remaining images are fed into an adversarial trained model and an untrained model to complete the second step of adversarial sample detection. By using this two-step detection method, the adversarial samples can be effectively detected with a detection success rate of no less than 95.73%, effectively improving the security of the SAR classification model.

    Reference
    Related
    Cited by
Get Citation

WANG Jian, ZHANG Sainan, CHEN Fang. A Two-Step Adversarial Sample Detection Technique for SAR Image Classification[J].,2024,39(1):106-119.

Copy
Related Videos

Share
Article Metrics
  • Abstract:
  • PDF:
  • HTML:
  • Cited by:
History
  • Received:March 07,2023
  • Revised:June 16,2023
  • Adopted:
  • Online: January 25,2024
  • Published:
Article QR Code