对抗样本攻击下提高雷达智能识别模型稳健性的算法研究OA
Robustness of Radar Intelligent Recognition Models Under Adversarial Samples Attacks
针对对抗样本攻击下雷达高分辨一维像(HRRP)智能识别模型稳健性不足的问题,本文提出一种轻量化增强算法.首先,综合分析在快速梯度符号法(FGSM)、投影梯度下降(PGD)及黑盒迁移攻击下,轻量卷积神经网络(CNN)的脆弱性;其次,提出"快速对抗训练+输入去噪自编码器+异常检测后置"的级联防御策略;最后,基于3类空中目标 的6 000组实测样本开展对抗实验.结果表明:该算法可将攻击成功率抑制至9.2%,仅牺牲2.1个百分点的清洁准确率,推理延时增加低于20%;算法在模型体量、实时性与稳健性之间取得了良好平衡,可为雷达智能识别系统的抗干扰设计提供实用化解决方案.
Addressing the problem of insufficient robustness of the intelligent recognition model of radar High Resolution Range Profile(HRRP)under adversarial sample attacks,a lightweight enhancement method was proposed in this study.Firstly,a comprehensive analysis was conducted using the Fast Gradient Sign Method(FGSM),Projected Gradient Descent(PGD),and a black-box migration attack to assess the vulnerability of the lightweight Convolutional Neural Network(CNN).Secondly,a cascaded defense strategy of"fast adversarial training+input denoising auto encoder+post-anomaly detection"was established.Finally,countermeasure experiments were carried out using three types of air targets and 6,000 sets of measured samples.The results show that this strategy can reduce the attack success rate to 9.2%,sacrificing only 2.1 percentage point of the cleaning accuracy,and increasing inference delay by less than 20%.It achieves a stable balance among model size,real-time performance,and robustness,providing a practical solution for the anti-interference design in radar-intelligent recognition systems.
沈曈;陈敬贤;钟平
上海机电工程研究所,上海 201109上海机电工程研究所,上海 201109自动目标识别重点实验室(长沙),湖南 长沙 410073
航空航天
雷达目标识别对抗样本雷达智能识别模型稳健性对抗训练
radar target recognitionadversarial examplesrobustness of radar intelligent recognition modeladversarial training
《空天防御》 2026 (1)
46-51,114,7
评论