Return
Random Response-Based SAR Purification Defense
DOI:10.1109/LGRS.2024.3522590.png)
Abstract
En 中文
Deep learning-driven synthetic aperture radar automatic target recognition (SAR ATR) has gained increasing attention recently. However, current methods remain highly vulnerable to adversarial attacks, limiting their practical application. Most adversarial defense methods rely on adversarial training or attack detection, which tend to overfit and result in poor robustness against different attack types. Moreover, these methods show limited resilience to query-based attacks, where attackers iteratively probe the model to identify vulnerabilities and generate precise adversarial samples. To overcome these challenges, we propose a random response-based SAR purification defense (RRPD) framework composed of two key components: a diffusion purification module (DPM) and a multiexpert randomized response module (MRRM). The DPM removes adversarial noise through diffusion denoising while preserving critical information for accurate recognition. The MRRM introduces multiple expert models to increase response randomness, thus reducing the effectiveness of query-based attacks. Experimental results show that the proposed framework significantly enhances robustness against adversarial attacks on public SAR datasets, improving system security and reliability. The code is available at https://github.com/SmartDSP2024/RRPD.
Keywords:
Purification
Perturbation methods
Noise
Accuracy
Target recognition
Security
Training
Synthetic aperture radar
Robustness
Noise reduction
Defense framework
diffusion purification
synthetic aperture radar automatic target recognition (SAR ATR)
Journal
IF:
16.4
Papers:
1.0W
Citations:
5.1K

