Universal Adversarial Perturbation of SAR Images for Deep Learning Based Target Classification
Lulu Wang, Xiaolei Wang, Shixin Ma, Yi Zhang · 2021 IEEE 4th International Conference on Electronics Technology (ICET) · 2021
Deep learning-based SAR target classification has gained great success recently. However, the machine learning models are vulnerable to adversarial attacks which may cause severe security issue. In this paper, a convolution neural network (CNN)-based SAR target classification model is trained and used to perform the universal perturbation attack. We find out that the SAR target classification model is also vulnerable to universal adversarial attacks. By adding an image-agnostic and very small perturbation, the classification accuracy deteriorates a lot.