Impact Investigation of Adversarial Samples on CNN-Based SAR Image Target Detectors
Peng Zhou, Shunping Xiao, Mingdian Li, Junwu Deng, Xiangwei Xing, Si-Wei Chen · 2023
In recent years, deep learning algorithms based on convolutional neural networks (CNN) have made breakthroughs in the field of target detection in Synthetic Aperture Radar (SAR) images. However, CNN may be vulnerable to adversarial examples, raising security concerns for practical deployment. To gain a deeper understanding of adversarial examples and provide a theoretical basis for building robust detection networks, this study comprehensively investigates the impacts of adversarial samples generated by deep recognition networks (DRN) in SAR images on the performance of target detection networks with different principles, using YOLOv3 and Faster-RCNN as examples. Experimental results on the MiniSAR vehicle target dataset show that adversarial samples pose a more serious threat to the single-stage detection network YOLOv3. Simply adding small perturbation that are invisible for human eyes to the SAR image can mislead the detector into missing the majority of targets. In contrast, two-stage detection networks like Faster-RCNN exhibit stronger robustness with their detection performance being less influenced by the adversarial examples generated by different DRN.