Adversarial Perturbations in Pol-ISAR Image Classification: A Study on Explanation Consistency and Ensemble Learning

Amir Hosein Oveis, Ajeet Kumar, Elisa Giusti, Marco Martorella, Alessandro Cantelli‐Forti · 2024

Polarimetric Inverse Synthetic Aperture Radar (PolISAR) images have been exploited for automatic target recognition (ATR) and classification due to their rich and detailed information. However, the performance of Pol-ISAR image classification systems can be degraded by adversarial attacks, which are imperceptible perturbations introduced into the input data to deceive the classifier. In this paper, we first examine the impact of adversarial perturbations on the explainability of the classification process. In particular, we employ the Local Interpretable Model-Agnostic Explanations (LIME) method to explain the feature importance of a convolutional neural network (CNN) under adversarial perturbations generated by the fast gradient sign method (FGSM). By comparing the LIME explanation under different perturbation levels with that of the non-perturbed scenario, we propose a numerical metric called the LIME Consistency Score (LCS) to assess the consistency of LIME explanations across various levels of perturbation. We then examine how this score aligns with the CNN's decision. Additionally, we propose an ensemble learning strategy with different architectures and loss functions to improve the resilience of Pol-ISAR-ATR against adversarial examples (AEs) and reduce their transferability. We conduct our experiments on a Pol-ISAR dataset of a T72 tank, which is converted to 3-channel data using Pauli's decomposition. The results demonstrate the effectiveness and potential of our proposed framework.

Read the paper · More papers on PaperTik