Deep neural networks have demonstrated excellent performance in SAR target detection tasks but remain susceptible to adversarial attacks. Existing SAR-specific attack methods can effectively deceive detectors; however, they often introduce noticeable perturbations and are largely confined to digital domain, neglecting physical implementation constrains for attacking SAR systems. In this paper, a novel Adversarial Attenuation Patch (AAP) method is proposed that employs energy-constrained optimization strategy coupled with an attenuation-based deployment framework to achieve a seamless balance between attack effectiveness and stealthiness. More importantly, AAP exhibits strong potential for physical realization by aligning with signal-level electronic jamming mechanisms. Experimental results show that AAP effectively degrades detection performance while preserving high imperceptibility, and shows favorable transferability across different models. This study provides a physical grounded perspective for adversarial attacks on SAR target detection systems and facilitates the design of more covert and practically deployable attack strategies. The source code is made available at https://github.com/boremycin/SAAP.
翻译:深度神经网络在SAR目标检测任务中展现出优异性能,但仍易受对抗性攻击影响。现有针对SAR的攻击方法能有效欺骗检测器,但往往引入显著扰动且多局限于数字域,忽视了攻击SAR系统时的物理实现约束。本文提出一种新型对抗性衰减补丁(AAP)方法,采用能量受限优化策略结合基于衰减的部署框架,在攻击效能与隐蔽性之间实现无缝平衡。更重要的是,AAP通过对齐信号级电子干扰机制,展现了强大的物理实现潜力。实验结果表明,AAP在有效降低检测性能的同时保持高隐蔽性,并在不同模型间展现出良好的可迁移性。本研究为SAR目标检测系统的对抗性攻击提供了物理基础视角,有助于设计更具隐蔽性和实际可部署性的攻击策略。源代码已开源至https://github.com/boremycin/SAAP。