article Open access

Towards Robust Synthetic Aperture Radar Classification: Counteracting Black‐Box Adversarial Attacks

  • IET Radar Sonar & Navigation
  • Institution of Engineering and Technology
Research footprint

At a glance

Citations
0
References
35
Comments
0
Paper overview

Öz

ABSTRACT Synthetic Aperture Radar (SAR) image classification using deep neural networks (DNNs) has demonstrated vulnerability to adversarial attacks, particularly black‐box attacks, which rely solely on model output scores to craft effective perturbations. Despite their practical threat, defences against such attacks in SAR tasks remain underexplored. To bridge this gap, we propose a novel defence mechanism that introduces a pointwise modulation layer to enforce gradient orthogonality, thereby disrupting the gradient estimation process employed in black‐box attacks. This method preserves high accuracy on clean data by maintaining logit consistency while significantly reducing attack success rates. Furthermore, the approach is computationally efficient and can be easily integrated into existing models. Extensive experiments demonstrate the effectiveness of the proposed method in enhancing the robustness of SAR classifiers against a range of black‐box attack scenarios, without compromising their performance on clean data. This work contributes to the development of secure and reliable SAR‐based machine learning systems for critical applications.

Record transparency

Publication details

DOI
10.1049/rsn2.70062
OpenAlex
W4412766636
Document type
article
Language
EN
Source
IET Radar Sonar & Navigation
Last metadata update
Community

Comments

Oturum Açın to join the discussion.

  1. No comments yet. Start the discussion.