电信科学 ›› 2024, Vol. 40 ›› Issue (3): 64-74.doi: 10.11959/j.issn.1000-0801.2024081

• 研究与开发 • 上一篇    下一篇

基于掩模提取的SAR图像对抗样本生成方法

章坚武1, 能豪1, 李杰1, 钱建华2, 方银锋1   

  1. 1 杭州电子科技大学,浙江 杭州 310018
    2 中国联通(浙江)产业互联网有限公司,浙江 杭州 311199
  • 修回日期:2024-01-10 出版日期:2024-03-01 发布日期:2024-03-01
  • 作者简介:章坚武(1961- ),男,杭州电子科技大学教授、博士生导师,中国电子学会、中国通信学会高级会员,浙江省通信学会常务理事,主要研究方向为无线通信与移动通信、通信网络与信息安全
    能豪 (1999- ),男,杭州电子科技大学通信工程学院硕士生,主要研究方向为无线通信与信息安全
    李杰(1976- ),女,杭州电子科技大学信息工程学院副教授,主要研究方向为无线通信与移动通信
    钱建华(1971- ),男,中国联通(浙江)产业互联网有限公司总经理、高级工程师,主要研究方向为数据通信
    方银锋(1986- ),男,杭州电子科技大学校副教授、硕士生导师,主要从事人机接口设计、生物信号处理与分析、模式识别与智能系统等领域的研究
  • 基金资助:
    国家自然科学基金资助项目(IEC\NSFC\181300);浙江省自然科学基金重点项目(LZ23F010001)

Adversarial example generation method for SAR images based on mask extraction

Jianwu ZHANG1, Hao NAI1, Jie LI1, Jianhua QIAN2, Yinfeng FANG1   

  1. 1 Hangzhou Dianzi University, Hangzhou 310018, China
    2 China Unicom (Zhejiang) Industrial Internet Co., Ltd., Hangzhou 311199, China
  • Revised:2024-01-10 Online:2024-03-01 Published:2024-03-01
  • Supported by:
    The National Natural Science Foundation of China(IEC\NSFC\181300);The Natural Science Foundation of Zhejiang Province(LZ23F010001)

摘要:

合成孔径雷达(synthetic aperture radar,SAR)图像的对抗样本生成在当前已经有很多方法,但仍存在对抗样本扰动量较大、训练不稳定以及对抗样本的质量无法保证等问题。针对上述问题,提出了一种SAR图像对抗样本生成模型,该模型基于AdvGAN模型架构,首先根据SAR图像的特点设计了一种由增强Lee滤波器和最大类间方差法(OTSU)自适应阈值分割等模块组成的掩模提取模块,这种方法产生的扰动量更小,与原始样本的结构相似性(structural similarity,SSIM)值达到0.997以上。其次将改进的相对均值生成对抗网络(relativistic average generative adversarial network,RaGAN)损失引入AdvGAN中,使用相对均值判别器,让判别器在训练中同时依赖于真实数据和生成的数据,提高了训练的稳定性与攻击效果。在MSTAR数据集上与相关方法进行了实验对比,实验表明,此方法生成的SAR图像对抗样本在攻击防御模型时的攻击成功率较传统方法提高了10%~15%。

关键词: 对抗样本, 生成对抗网络, 合成孔径雷达, 半白盒攻击, 掩模提取

Abstract:

There are many ways to generate adversarial samples for synthetic aperture radar (SAR) images at present, but some problems such as large amount of perturbation of adversarial samples, unstable training, and unguaranteed quality of adversarial samples still exist.To solve the above problems, a SAR image adversarial sample generation model was proposed.The model was based on the AdvGAN model architecture.Firstly, according to the characteristics of the SAR images, an adaptive threshold segmentation method based on the enhanced Lee filter OTSU was designed.The mask extraction module composed of equal modules, this method produced a smaller amount of disturbance, and the structural similarity (SSIM) with the original sample reached that more than 0.997.Secondly, the improved relativistic average GAN (RaGAN) loss was introduced into AdvGAN, and the relative mean discriminator was used to make the discriminator rely on both real data and generated data during training, which improved the stability of training and the attack effect.Experiments were compared with related methods on the MSTAR dataset.Experiments show that the attack success rate of SAR image adversarial samples generated by this method is increased by 10%~15% than that of traditional methods when attacking defense models.

Key words: adversarial sample, generative adversarial network, synthetic aperture radar, semi-white box attack, mask extraction

中图分类号: 

No Suggested Reading articles found!