Meta-Adversarial Despeckling Network for Attacking SAR Image Target Detectors
Peng Zhou, Shunping Xiao, Si-Wei Chen · IEEE Transactions on Geoscience and Remote Sensing · 2025
Recently, integrated deep learning methods cascading speckle filtering and target detection have garnered increasing attention in synthetic aperture radar (SAR) image target detection. These methods use despeckling networks to suppress speckle noise, enhancing the performance of followed detectors. However, recent studies have shown that deep neural networks (DNNs) are vulnerable to adversarial attacks, where adding imperceptible perturbations to benign examples can cause incorrect predictions. This phenomenon raises serious concerns about the security of current integrated deep learning algorithms in SAR images. To this end, this work conducts adversarial attack research on integrated speckle filtering and detection methods to assess its adversarial robustness. Specifically, a novel meta-adversarial despeckling network (Meta-ADNet) architecture is proposed, which leverages the despeckling network as a potential attack pathway to inject perturbations, generating adversarial despeckled examples that invalidate subsequent detection processes. Meta-ADNet consists of two core components: the baseline model adversarial despeckling network (ADNet) and the corresponding meta-adversarial attack framework. ADNet first generates benign despeckled SAR images through a despeckling network, which are then fed into the perturbation injection branch. This branch guides the despeckling network in producing adversarial examples by backpropagating the confidence loss of the surrogate detection model. The meta-adversarial attack framework constructs different tasks by selecting multiple surrogate detection models and iteratively simulates white-box ensemble attacks and black-box attacks within each task to enhance the transfer attack capability of ADNet on black-box models. Extensive experimental results on the SAR detection datasets SSDD and HRSID demonstrate that the proposed algorithm can effectively attack white-box surrogate detectors and exhibits strong black-box transfer attack capabilities.