A Multi-Intermediate Domain Adversarial Defense Method for SAR Land Cover Classification

Yinkai Zan, Pingping Lu, Fei Zhao, Robert Wang · 2023

Convolutional neural networks (CNNs) have achieved greate success in a variety of computer vision tasks. However, they are susceptible to elaborate, human-imperceptible adversarial noise patterns, which limit their deployment in safety-critical systems. In this paper, we propose an adversarial training method for synthetic aperture radar (SAR) image segmentation, which can effectively suppress the effects of adversarial perturbations. The proposed method introduces a multiple intermediate domain mechanism to enhance the robustness of the network to adversarial attacks, by dynamically adjusting the distribution of input data during the training process, without modifying the network structure or adding a separate mechanism to detect adversarial images. Experiments validate that our approach not only improves the segmentation accuracy of the network, but also effectively enhances the robustness of the network when facing white-box adversarial attacks.

Read the paper · More papers on PaperTik