雷达学报2026,Vol.15Issue(2):543-562,20.DOI:10.12000/JR25110
基于有源干扰机的SAR智能识别对抗方法
An Active Jammer-based Adversarial Attack Method Against SAR Automatic Target Recognition
摘要
Abstract
The effective utilization of Synthetic Aperture Radar(SAR)adversarial examples enables specific targets to achieve remote sensing stealth against intelligent detection systems,thereby evading detection and recognition by adversaries.Digital domain SAR adversarial methods,which operate exclusively in the image domain,produce adversarial images that are not physically realizable and therefore cannot generated by real SAR imaging systems.Existing physical domain approaches typically involve deploying corner reflectors or electromagnetic metasurfaces around targets and simulating adversarial examples using via computational electromagnetics.However,the limited accuracy of scattering estimation often constrains the practical protective efficacy of these methods.To overcome these limitations,this paper proposes an active jammer-based adversarial attack method that integrates SAR active jamming technology with adversarial attack methods to generate adversarial examples by perturbing the target's echo signals in the signal domain.First,a multiple-phase sectionalized modulation jamming method based on cosine amplitude weighting is selected,enabling parameterized control of the adversarial jamming signal through the design of perturbation components.Next,the adversarial jamming signal generated by the active jammer is fused with the target's echo signal according to the principles and actual processes of SAR imaging and is then subjected to imaging processing to produce physically realizable SAR adversarial examples.Finally,the differential evolution algorithm is employed to dynamically adjust parameters,such as the energy distribution and jamming range of the adversarial jamming signal,thereby optimizing the SAR adversarial examples to achieve optimal attack success rates even with minimal interference intensity.Experimental results on the MSTAR dataset,a widely used benchmark in the field of SAR Automatic Target Recognition(ATR),show that the proposed method achieves an average fooling rate of 90.88%and demonstrates superior transferability across five different SAR ATR models,with the highest transfer fooling rate reaching 75.57%.Overall,the proposed method generates more physically realizable adversarial examples compared with existing digital domain methods,effectively protecting specific targets in remote sensing detection and providing guidance for the practical application of active jamming signals in real-world scenarios.关键词
合成孔径雷达/SAR自动目标识别/有源干扰机/物理域对抗攻击/对抗样本Key words
Synthetic Aperture Radar(SAR)/Synthetic Aperture Radar Automatic Target Recognition(SAR ATR)/Active jammer/Physical domain adversarial attack/Adversarial example分类
信息技术与安全科学引用本文复制引用
周雅婷,周勇胜,薛清华,马飞,张帆..基于有源干扰机的SAR智能识别对抗方法[J].雷达学报,2026,15(2):543-562,20.基金项目
国家自然科学基金(62271034)The National Natural Science Foundation of China(62271034) (62271034)