A Radar Image Adversarial Sample Generation and Target Detection Attack Method Based on Meta-Adversarial Despeckling Network

By constructing a meta-adversarial despeckling network and utilizing white-box and black-box attacks of a multi-agent detection model to generate adversarial samples, the problems of coherent speckle noise interference and adversarial sample attacks in radar images are solved, achieving efficient target detection attack effects.

CN119540535BActive Publication Date: 2025-09-16NAT UNIV OF DEFENSE TECH
View PDF 2 Cites 0 Cited by

Patent Information

Application Number
CN202411674715.5
Authority / Receiving Office
CN · China
Patent Type
Patents(China)
Current Assignee / Owner
Filing Date
2024-11-21
Publication Date
2025-09-16
Estimated Expiration
2044-11-21

AI Technical Summary

Technical Problem

The existing integrated cascaded speckle filtering and target detection algorithm is vulnerable to adversarial sample attacks, resulting in a decrease in detection performance, and deep learning algorithms are difficult to effectively suppress speckle noise interference in radar images.

Method used

A meta-adversarial despeckling network is constructed. The despeckling network is trained by simulating a coherent speckle filtering dataset. Combined with a real SAR detection dataset, a meta-adversarial despeckling network training framework is constructed. Multiple proxy detection models are used for white-box and black-box attacks to generate adversarial samples to attack the target detection model.

Benefits of technology

The generalization ability of the despeckle network in practical applications is improved, and it can effectively attack a variety of proxy detection models. While maintaining high-quality images, it has powerful black-box attack capabilities and improves the robustness of detection.

✦ Generated by Eureka AI based on patent content.

Smart Images

  • Figure CN119540535B_ABST
    Figure CN119540535B_ABST
Patent Text Reader

Abstract

The present invention provides a radar image adversarial sample generation and target detection attack method based on a meta-adversarial despeckle network. The method comprises constructing a simulated speckle filtering dataset based on a speckle statistical model for an optical image dataset; training a despeckle network based on the constructed simulated speckle filtering dataset, and constructing a real SAR image target detection and filtering dataset in combination with a real SAR detection dataset; constructing a meta-adversarial despeckle network training framework, and using the real SAR image target detection and filtering dataset to train the meta-adversarial despeckle network model; and performing adversarial despeckle processing on the original SAR image using the trained meta-adversarial despeckle network model. The present invention has a simple principle and is easy to implement. The despeckle results maintain high image quality while possessing strong black-box attack capabilities. Furthermore, the method has a wide range of applicable attack scenarios.
Need to check novelty before this filing date? Find Prior Art

Description

Technical Field

[0001] The present invention relates to the field of radar image application security, and in particular to a radar image adversarial sample generation and target detection attack method based on a meta-adversarial despeckling network. Background Art

[0002] Synthetic Aperture Radar (SAR), as an active microwave sensor, offers all-day, all-weather Earth observation imaging capabilities. It has achieved numerous successful applications in both civilian and military fields, encompassing disaster detection, land cover mapping, and target detection and recognition. In recent years, radar imaging technology has advanced rapidly, significantly improving the resolution of SAR images. Consequently, the efficient and accurate detection of man-made targets from massive amounts of high-resolution SAR imagery has attracted increasing attention. With the expansion of SAR target detection datasets, deep learning-based target detection algorithms have rapidly developed and achieved significant success. Limited by the SAR imaging mechanism, speckle noise is always present, which degrades the performance of detection algorithms. To mitigate this noise, integrated algorithms combining cascaded speckle filtering and target detection have gained increasing attention and achieved significant performance improvements. However, recent research has shown that deep neural networks are vulnerable to adversarial examples, whereby inaccurate predictions can be made by adding imperceptible perturbations to benign samples. This phenomenon has raised concerns about the security of current integrated deep learning algorithms. This paper presents an adversarial attack against current integrated cascaded filtering and detection methods, proposing a method for generating adversarial examples and performing target detection attacks on radar images based on a meta-adversarial despeckling network. Summary of the Invention

[0003] In view of the shortcomings of the existing technology, the present invention provides a radar image adversarial sample generation and target detection attack method based on a meta-adversarial despeckling network.

[0004] To achieve the above object, the technical solution adopted by the present invention is as follows:

[0005] A radar image adversarial sample generation and target detection attack method based on a meta-adversarial despeckling network, comprising:

[0006] For the optical image dataset, a simulated speckle filtering dataset is constructed based on the speckle statistical model.

[0007] The despeckling network is trained based on the constructed simulated speckle filtering dataset, and combined with the real SAR detection dataset, a real SAR image target detection and filtering dataset is constructed;

[0008] Construct a meta-adversarial despeckling network training framework and use a real SAR image target detection and filtering dataset to train the meta-adversarial despeckling network model;

[0009] The trained meta-adversarial despeckling network model is used to perform adversarial despeckling on the original SAR image.

[0010] Furthermore, the constructing of the simulated speckle filter data set comprises the following steps:

[0011] Based on the optical image data set, the first v images Construct the equivalent view number as Simulated speckle image , forming a training data pair ;

[0012] Among them, the coherent speckle statistical model is

[0013]

[0014] Indicates the image size, To simulate the coherent speckle image, represents the Hadamrd product, is the optical image data image, is a coherent speckle; in the case of a unit mean and a variance of In the case of Gamma distribution, The probability density distribution of

[0015]

[0016] in, represents the gamma distribution, It is the number of views in the optical image formation process;

[0017] All training data pairs in the optical image dataset Construct the speckle filter data set for the simulation.

[0018] Furthermore, the construction of a real SAR image target detection and filtering dataset includes the following steps:

[0019] Training the despeckle network based on the constructed simulated speckle filtering dataset , and load the despeckle network trained weights;

[0020] Despeckle Network The trained weights are used to calculate the first r images Perform inference to obtain the corresponding despeckled image , forming a real SAR detection data set data pair ; All data pairs in the real SAR detection dataset Construct a real SAR image target detection and filtering dataset.

[0021] Furthermore, the construction of the meta-adversarial despeckle network training framework includes:

[0022] Based on the given inclusion U Model set of proxy detection models , randomly selected times, each extraction t +1 proxy detection model, consisting of tasks, each of which also includes randomly selected K images, each image is considered as a training sample, in the i In the task, the training samples are recorded as , ;

[0023] Each task includes a meta-training phase and a meta-testing phase, which are used to build a meta-adversarial despeckle network training framework.

[0024] In each task, the first t The proxy detection models are used in the meta-training phase, and the last proxy detection model is used in the meta-testing phase;

[0025] In the meta-training phase, t Proxy detection model ensemble attack despeckle network Get the trained adversarial despeckle network ; In the meta-test phase, the trained adversarial despeckle network is used Attacking the last proxy detection model makes the generated adversarial images easier to transfer to other proxy detection models.

[0026] Furthermore, in the meta-training and meta-testing phases of each task, the MAE-based Spot loss and The total loss function of confidence loss is used to train the despeckle network model. The total loss function is

[0027] .

[0028] Furthermore, the MAE-based The spot removal loss is

[0029]

[0030]

[0031] in, To detect real SAR images and its ground truth despeckled SAR image Set the despeckle image; For the i Task No. j Sample images The ground truth despeckled image, , .

[0032] Furthermore, the The confidence loss is

[0033]

[0034] in, Represents the number of prediction boxes generated by the proxy detection model; Represents the true value of the label box; represents the set of matching prediction boxes, , and Respectively represent g Prediction boxes The center point coordinates and their corresponding length and width; define Indicates the g The predicted boxes correspond to the label boxes; The type of the target object in the prediction box; It is the logit output, which indicates the probability that the predicted box is the true target; Indicates the number of label boxes; represents the weight assigned to the loss and is set to 0.5 to ensure a balance between the two tasks.

[0035] Furthermore, the meta-training includes:

[0036] For the i tasks, which include training samples ,use t Proxy Detection Model Integration to guide the despeckle network Generate adversarial despeckle images; for the i The first task j The first training sample m The confidence loss of the proxy detection model can be expressed as , ; Combine the confidence losses of all proxy detection models, for the i The first of the tasks j training samples, the total confidence loss of all proxy detection models is

[0037]

[0038] in, Represents the input real SAR detection image When , the adversarial despeckled image generated by the adversarial filtering network; is the weight of each surrogate model, ,and ;

[0039] The minimum confidence loss and despeckle loss are used to jointly optimize the adversarial despeckle network. The objective optimization function of meta-training is:

[0040]

[0041] in , ; and further expand the above formula as follows:

[0042] .

[0043] Furthermore, the meta-test includes:

[0044] Use the trained adversarial despeckle network model to attack the last sampled proxy detection model , enter K +1 test sample , by calculating The confidence loss further optimizes the trained adversarial despeckle network

[0045]

[0046] Referring to the meta-training process, the objective optimization function of the meta-testing process is

[0047] .

[0048] A radar image adversarial sample generation and target detection attack system based on a meta-adversarial despeckling network, including:

[0049] A simulated speckle filter data set construction module is used to construct a simulated speckle filter data set for the optical image data set based on the speckle statistical model;

[0050] A real SAR image target detection and filtering dataset construction module is used to train the despeckling network based on the constructed simulated speckle filtering dataset, and to construct a real SAR image target detection and filtering dataset in combination with the real SAR detection dataset;

[0051] Meta-adversarial despeckling network construction and training module, used to build a meta-adversarial despeckling network training framework and train the meta-adversarial despeckling network model using a real SAR image target detection and filtering dataset;

[0052] The original SAR image processing module uses the trained meta-adversarial despeckling network model to perform adversarial despeckling on the original SAR image.

[0053] A computer device comprises a memory and a processor, wherein the memory contains a computer program, and when the processor executes the computer program, the following steps are implemented:

[0054] For the optical image dataset, a simulated speckle filtering dataset is constructed based on the speckle statistical model.

[0055] The despeckling network is trained based on the constructed simulated speckle filtering dataset, and combined with the real SAR detection dataset, a real SAR image target detection and filtering dataset is constructed;

[0056] Construct a meta-adversarial despeckling network training framework and use a real SAR image target detection and filtering dataset to train the meta-adversarial despeckling network model;

[0057] The trained meta-adversarial despeckling network model is used to perform adversarial despeckling on the original SAR image.

[0058] A computer-readable storage medium stores a computer program, which, when executed by a processor, implements the following steps:

[0059] For the optical image dataset, a simulated speckle filtering dataset is constructed based on the speckle statistical model.

[0060] The despeckling network is trained based on the constructed simulated speckle filtering dataset, and combined with the real SAR detection dataset, a real SAR image target detection and filtering dataset is constructed;

[0061] Construct a meta-adversarial despeckling network training framework and use a real SAR image target detection and filtering dataset to train the meta-adversarial despeckling network model;

[0062] The trained meta-adversarial despeckling network model is used to perform adversarial despeckling on the original SAR image.

[0063] The above-mentioned method, system, computer device, and storage medium for radar image adversarial sample generation and target detection attack based on a meta-adversarial despeckling network can use despeckled images to generate adversarial samples, achieving the effect of covertly attacking proxy detection models and causing them to lose their targets. The present invention constructs different tasks by randomly sampling multiple proxy detection models. Within these constructed tasks, a meta-adversarial despeckling network training framework is constructed in two phases: meta-training and meta-testing. In the meta-training phase, white-box attacks are simulated, and the despeckling network is trained to generate adversarial samples using a model ensemble approach, combining the confidence losses of multiple proxy detection models. In the meta-testing phase, black-box attacks are simulated, using a temporarily trained despeckling network to attack an unseen proxy detection model. Simulating white-box and black-box attacks in each task iteration further optimizes the despeckling network, enhancing its transfer attack capability. The trained adversarial despeckling network is then used to perform coherent speckle filtering on images in a SAR detection test set, generating adversarial despeckled images that effectively attack multiple proxy detection models. The present invention is simple in principle and easy to implement, and the despeckling results maintain high image quality while also possessing strong black-box attack capabilities.

[0064] The present invention uses a real SAR detection data set to train a speckle removal network model, which can improve the generalization ability of the trained speckle removal network model in practical applications and make the trained speckle removal network model more adaptable to real scenarios.

[0065] For the real SAR detection dataset in the present invention, in addition to using the existing public SAR ship detection dataset, SAR artificial target detection datasets of different bands, different polarization modes and different resolutions, such as aircraft detection datasets, vehicle detection datasets, etc., can also be subjected to adversarial despeckling processing. Therefore, the present invention has a wider range of attack application scenarios. BRIEF DESCRIPTION OF THE DRAWINGS

[0066] In order to more clearly illustrate the embodiments of the present invention or the technical solutions in the prior art, the following briefly introduces the drawings required for use in the embodiments or the description of the prior art. Obviously, the drawings described below are only some embodiments of the present invention. For ordinary technicians in this field, other drawings can be obtained based on the structures shown in these drawings without paying any creative work.

[0067] Figure 1 A schematic flow chart of a radar image adversarial sample generation and target detection attack method based on a meta-adversarial despeckling network provided in one embodiment;

[0068] Figure 2 A schematic diagram of a meta-adversarial despeckle network training framework provided in one embodiment;

[0069] Figure 3 A schematic diagram of the U-Net network structure provided by an embodiment;

[0070] Figure 4 This is a graph showing the results of anti-speckle removal detection provided by an embodiment. DETAILED DESCRIPTION

[0071] The following will clearly and completely describe the technical solutions in the embodiments of the present invention in conjunction with the accompanying drawings. Obviously, the described embodiments are only part of the embodiments of the present invention, not all of the embodiments. All other embodiments obtained by ordinary technicians in this field based on the embodiments of the present invention without making any creative efforts shall fall within the scope of protection of the present invention.

[0072] Reference Figure 1 In one embodiment, a radar image adversarial sample generation and target detection attack method based on a meta-adversarial despeckling network is provided, comprising:

[0073] For the optical image dataset, a simulated speckle filtering dataset is constructed based on the speckle statistical model.

[0074] The despeckling network is trained based on the constructed simulated speckle filtering dataset, and combined with the real SAR detection dataset, a real SAR image target detection and filtering dataset is constructed;

[0075] Construct a meta-adversarial despeckling network training framework and use a real SAR image target detection and filtering dataset to train the meta-adversarial despeckling network model;

[0076] The trained meta-adversarial despeckling network model is used to perform adversarial despeckling on the original SAR image.

[0077] Multiplicative speckle in SAR images is the main reason for reducing SAR image quality.

[0078] The construction of the simulated speckle filter data set comprises the following steps:

[0079] Based on the optical image data set, the first v images Construct the equivalent view number as Simulated speckle image , forming a training data pair ;

[0080] Among them, the coherent speckle statistical model is

[0081]

[0082] Indicates the image size, To simulate the coherent speckle image, represents the Hadamrd product, is the optical image data image, is a coherent speckle; in the case of a unit mean and a variance of In the case of Gamma distribution, The probability density distribution of

[0083]

[0084] in, represents the gamma distribution, It is the number of views in the optical image formation process;

[0085] All training data pairs in the optical image dataset Construct the speckle filter data set for the simulation.

[0086] In one embodiment, based on the optical image dataset Waterloo, the first v image Construct the equivalent view number as Simulated speckle image , forming a training data pair ; All training data pairs in Waterloo The Waterloo optical image dataset contains 4744 optical images, which can be used to obtain 4744 training data pairs.

[0087] For a given original SAR image And the parameters are and Despeckle Network and adversarial despeckle networks , the despeckled image and the adversarial despeckled image can be expressed as and , assuming The attack parameters are Proxy detection model .set up Contains E label box truth values ,in , and Represents the e-th label box respectively The center point coordinates and their corresponding length and width, is the type of the target object in the label box, , when the category is m, For a true value target ,assumed exist If the target is successfully detected, and . For adversarial samples , and the test results are ( Can be empty, ), if it can satisfy and The IoU between them is less than 0.5 or , which means the detector has been successfully attacked.

[0088] The construction of a real SAR image target detection and filtering dataset comprises the following steps:

[0089] Training the despeckle network based on the constructed simulated speckle filtering dataset , and load the despeckle network trained weights;

[0090] Despeckle Network The trained weights are used to calculate the first r images Perform inference to obtain the corresponding despeckled image , forming a real SAR detection data set data pair ; All data pairs in the real SAR detection dataset Construct a real SAR image target detection and filtering dataset.

[0091] In one embodiment, the real SAR ship detection dataset SSDD is r images Perform inference to obtain the corresponding despeckled image ; Data pair Combining all the images in the real SAR ship detection dataset SSDD, we can get 928 sets of training data pairs. , forming the final real SAR image target detection and filtering dataset for training the meta-adversarial despeckling network.

[0092] Using real SAR detection datasets to train the despeckling network model can improve the generalization ability of the trained despeckling network model in practical applications and make the trained despeckling network model more adaptable to real scenarios.

[0093] Reference Figure 2 , the construction of the meta-adversarial despeckle network training framework includes:

[0094] Based on the given inclusion U Model set of proxy detection models ,in , When represents the adversarial despeckle attack against a single detection network; randomly selected times, each extraction t +1 proxy detection model, consisting of tasks, each of which also includes randomly selected K images, each image is considered as a training sample, in the i In the task, the training samples are recorded as , ;

[0095] Each task includes a meta-training phase and a meta-testing phase, which are used to build a meta-adversarial despeckle network training framework.

[0096] In each task, the first t The proxy detection models are used in the meta-training phase, and the last proxy detection model is used in the meta-testing phase;

[0097] In the meta-training phase, t Proxy detection model ensemble attack despeckle network Get the trained adversarial despeckle network , which is equivalent to simulating white box attacks; in the meta-test phase, the trained adversarial despeckle network is used Attacking the last proxy detection model is equivalent to simulating a black-box attack, making the generated adversarial images easier to migrate to other proxy detection models.

[0098] In the meta-training and meta-testing phases of each task, the MAE-based Spot loss and The total loss function of confidence loss is used to train the despeckle network model. The total loss function is

[0099] .

[0100] The MAE-based The spot removal loss is

[0101]

[0102]

[0103] in, To detect real SAR images and its ground truth despeckled SAR image Set the despeckle image; For the i Task No. j Sample images The ground truth despeckled image, , .

[0104] Using MAE-based Despeckle loss to supervise adversarial despeckle network , to ensure that the output SAR image quality is improved.

[0105] Adding confidence loss To attack the target confidence learning process of the proxy detection model, the despeckled SAR image can fool the current mainstream proxy detection model and lose most of the target boxes. For each image in the training sample, the proxy detection model will first generate prediction boxes, and then according to the overlap rate of the center coordinates and the anchor box, Each label box in is assigned the best matching anchor box and prediction vector. The confidence loss aims to destroy the confidence of the proxy detection model for the positive sample box to make it invalid.

[0106] described The confidence loss is

[0107]

[0108] in, Represents the number of prediction boxes generated by the proxy detection model; Represents the true value of the label box; represents the set of matching prediction boxes, , and Respectively represent g Prediction boxes The center point coordinates and their corresponding length and width; define Indicates the g The predicted boxes correspond to the label boxes; The type of the target object in the prediction box; It is the logit output, which indicates the probability that the predicted box is the true target; Indicates the number of label boxes; represents the weight assigned to the loss and is set to 0.5 to ensure a balance between the two tasks.

[0109] By combining Spot loss and The confidence loss is used to train the despeckling network model, which can destroy the confidence of the proxy detection model for the positive sample box while ensuring the output of high-quality SAR images.

[0110] The meta-training includes:

[0111] For the i tasks, which include training samples ,use t Proxy Detection Model An ensemble of (simulated white boxes) to guide the despeckle network Generate adversarial despeckle images; for the i The first task j The first training sample m The confidence loss of the proxy detection model can be expressed as , ; Combine the confidence losses of all proxy detection models, for the i The first of the tasks j training samples, the total confidence loss of all proxy detection models is

[0112]

[0113] in, Represents the input real SAR detection image When , the adversarial despeckled image generated by the adversarial filtering network; is the weight of each surrogate model, ,and ;

[0114] The minimum confidence loss and despeckle loss are used to jointly optimize the adversarial despeckle network to ensure high transfer aggressiveness and visual quality of the despeckled image. The objective optimization function of meta-training is

[0115]

[0116] in , ; and further expand the above formula as follows:

[0117] .

[0118] The meta-tests include:

[0119] After obtaining the temporarily trained adversarial despeckle network through the integrated attack in the meta-training phase, a black box attack is simulated and the trained adversarial despeckle network model is used to attack the last sampled proxy detection model. , enter K +1 test sample , by calculating The confidence loss further optimizes the trained adversarial despeckle network

[0120]

[0121] Referring to the meta-training process, the objective optimization function of the meta-testing process is

[0122] .

[0123] By iteratively optimizing the objective functions of meta-training and meta-testing, the adversarial despeckling network is trained to obtain a specific weight. By loading this weight, the original benign despeckling network can output a perturbed despeckled image to attack proxy detection models of different architectures.

[0124] In one embodiment, the optical remote sensing dataset Waterloo is used to construct the visual data. A dataset of simulated SAR image speckle filtering.

[0125] Reference Figure 3 , the classic U-Net network is used as the despeckling network; during inference, the real SAR ship dataset SSDD is selected as the image to be despeckled, and a real SAR image target detection and filtering dataset is constructed.

[0126] During the construction of the meta-adversarial despeckling network, 10,000 tasks were constructed by randomly sampling proxy detection models. In each task cycle, the meta-training process included 3 training samples and 4 (white-box) proxy detection models, and the meta-testing process included 1 training sample and 1 (black-box) proxy detection model. The meta-adversarial despeckling network was trained using a real SAR image target detection and filtering dataset constructed from the despeckled SSDD ship detection training set. The network optimizer selected the Adaptive Moment Estimation (ADAM) optimizer, where the optimizer parameters were set to 、 as well as .

[0127] The trained meta-adversarial despeckling network is used to perform adversarial despeckling on the images to be despeckled in the SSDD ship detection test set, and the despeckling effect is evaluated on the trained two-stage detection model Faster-RCNN and the single-stage detection model YOLOv3. Figure 4 ,Depend on Figure 4 It can be observed that the proposed method not only filters coherent speckle noise but also injects adversarial perturbations, successfully causing the two proxy detection models to miss most targets. Peak Signal-to-Noise Ratio (PSNR) and Attack Success Ratio (ASR) metrics were used to quantitatively evaluate the adversarial despeckled SAR images. The average PSNR of all adversarially despeckled images compared to the original despeckled labeled images in the test set, as well as the ASR metrics for the two proxy detection models, are shown in Table 1.

[0128] Table 1 Comparison of average PSNR results of different methods

[0129]

[0130] It can be seen that the PSNR index of the method provided by the present invention is higher than 35db, with high visual quality, and the attack success rate for both is higher than 80%.

[0131] In one embodiment, a radar image adversarial sample generation and target detection attack system based on a meta-adversarial despeckling network is provided, comprising:

[0132] A simulated speckle filter data set construction module is used to construct a simulated speckle filter data set for the optical image data set based on the speckle statistical model;

[0133] A real SAR image target detection and filtering dataset construction module is used to train the despeckling network based on the constructed simulated speckle filtering dataset, and to construct a real SAR image target detection and filtering dataset in combination with the real SAR detection dataset;

[0134] Meta-adversarial despeckling network construction and training module, used to build a meta-adversarial despeckling network training framework and train the meta-adversarial despeckling network model using a real SAR image target detection and filtering dataset;

[0135] The original SAR image processing module uses the trained meta-adversarial despeckling network model to perform adversarial despeckling on the original SAR image.

[0136] The specific limitations of a radar image adversarial sample generation and target detection attack system based on a meta-adversarial despeckle network can be found in the limitations of a radar image adversarial sample generation and target detection attack method based on a meta-adversarial despeckle network described above and will not be further elaborated here. Each module in the aforementioned radar image adversarial sample generation and target detection attack system based on a meta-adversarial despeckle network can be implemented in whole or in part via software, hardware, or a combination thereof. Each of these modules can be embedded in or independent of a processor in a computer device in hardware form, or stored in a computer device memory in software form, allowing the processor to call and execute the corresponding operations of each module.

[0137] In one embodiment, a computer device is provided, which may be a terminal. The computer device includes a processor, memory, a network interface, a display screen, and an input device connected via a system bus. The processor of the computer device is configured to provide computing and control capabilities. The memory of the computer device includes a non-volatile storage medium and internal memory. The non-volatile storage medium stores an operating system and a computer program. The internal memory provides an environment for the operation of the operating system and computer program in the non-volatile storage medium. The network interface of the computer device is configured to communicate with an external terminal via a network connection. When executed by the processor, the computer program implements a radar image adversarial sample generation and target detection attack method based on a meta-adversarial despeckling network. The display screen of the computer device may be a liquid crystal display or an electronic ink display screen. The input device of the computer device may be a touch layer covering the display screen, or may be buttons, a trackball, or a touchpad provided on the computer device housing, or may be an external keyboard, touchpad, or mouse.

[0138] In one embodiment, a computer device is provided, including a memory and a processor. The memory stores a computer program, and the processor implements the steps in the above method embodiment when executing the computer program.

[0139] In one embodiment, a computer-readable storage medium is provided, on which a computer program is stored. When the computer program is executed by a processor, the steps in the above method embodiment are implemented.

[0140] Those skilled in the art will understand that all or part of the processes in the above-mentioned embodiments can be implemented by instructing the relevant hardware through a computer program. The computer program can be stored in a non-volatile computer-readable storage medium. When the computer program is executed, it can include the processes of the embodiments of the above-mentioned methods. Among them, any reference to memory, storage, database or other media used in the embodiments provided in this application may include non-volatile and / or volatile memory. Non-volatile memory may include read-only memory (ROM), programmable ROM (PROM), electrically programmable ROM (EPROM), electrically erasable programmable ROM (EEPROM) or flash memory. Volatile memory may include random access memory (RAM) or external cache memory. By way of illustration and not limitation, RAM is available in many forms such as static RAM (SRAM), dynamic RAM (DRAM), synchronous DRAM (SDRAM), double data rate SDRAM (DDRSDRAM), enhanced SDRAM (ESDRAM), Synchronous Link DRAM (SLDRAM), Rambus direct RAM (RDRAM), direct memory bus dynamic RAM (DRDRAM), and memory bus dynamic RAM (RDRAM), etc.

[0141] The technical features of the above embodiments can be combined arbitrarily. To make the description concise, not all possible combinations of the technical features in the above embodiments are described. However, as long as there is no contradiction in the combination of these technical features, they should be considered to be within the scope of this specification.

[0142] The above-described embodiments merely represent several implementation methods of the present application. While the descriptions are relatively specific and detailed, they should not be construed as limiting the scope of the present invention. It should be noted that a person skilled in the art may make various modifications and improvements without departing from the spirit of the present application, and these modifications and improvements fall within the scope of protection of the present application. Therefore, the scope of protection of the present application shall be determined by the appended claims.

Claims

1. A radar image adversarial sample generation and target detection attack method based on meta-adversarial despeckling network, characterized by: include: For the optical image dataset, a simulated speckle filtering dataset is constructed based on the speckle statistical model. The construction of the simulated speckle filter data set comprises the following steps: Based on the optical image data set, the first v images Construct the equivalent view number as Simulated speckle image , forming a training data pair ; Among them, the coherent speckle statistical model is: ; Indicates the image size, To simulate the coherent speckle image, represents the Hadamrd product, is the optical image data image, is a coherent speckle; in the case of a unit mean and a variance of In the case of Gamma distribution, The probability density distribution of is: ; in, represents the gamma distribution, It is the number of views in the optical image formation process; All training data pairs in the optical image dataset Constructing a simulated speckle filter data set; The despeckling network is trained based on the constructed simulated speckle filtering dataset, and combined with the real SAR detection dataset to construct a real SAR image target detection and filtering dataset; the construction of the real SAR image target detection and filtering dataset includes the following steps: Training the despeckle network based on the constructed simulated speckle filtering dataset , and load the despeckle network trained weights; Despeckle Network The trained weights are used to calculate the first r images Perform inference to obtain the corresponding despeckled image , forming a real SAR detection data set data pair ; All data pairs in the real SAR detection dataset Construct a real SAR image target detection and filtering dataset; Constructing a meta-adversarial despeckle network training framework, and using a real SAR image target detection and filtering dataset to train a meta-adversarial despeckle network model; said constructing a meta-adversarial despeckle network training framework includes: Based on the given inclusion U Model set of proxy detection models , randomly selected times, each extraction t +1 proxy detection model, consisting of tasks, each of which also includes randomly selected K images, each image is considered as a training sample, in the i In the task, the training samples are recorded as , ; Each task includes a meta-training phase and a meta-testing phase, which are used to build a meta-adversarial despeckle network training framework. In each task, the first t The proxy detection models are used in the meta-training phase, and the last proxy detection model is used in the meta-testing phase; In the meta-training phase, t Proxy detection model ensemble attack despeckle network Get the trained adversarial despeckle network ; In the meta-test phase, the trained adversarial despeckle network is used Attacking the last proxy detection model makes it easier to transfer the generated adversarial images to other proxy detection models; The trained meta-adversarial despeckling network model is used to perform adversarial despeckling on the original SAR image.

2. The radar image adversarial sample generation and target detection attack method based on meta-adversarial despeckling network according to claim 1, characterized in that: In the meta-training and meta-testing phases of each task, the MAE-based Spot loss and The total loss function of confidence loss is used to train the despeckle network model. The total loss function is: 。 3. The radar image adversarial sample generation and target detection attack method based on meta-adversarial despeckling network according to claim 2, characterized in that: The MAE-based The despeckle loss is: ; ; in, To detect real SAR images and its ground truth despeckled SAR image Set the despeckle image; For the i Task No. j Sample images The ground truth despeckled image, , .

4. The radar image adversarial sample generation and target detection attack method based on meta-adversarial despeckling network according to claim 2, characterized in that: described The confidence loss is: ; in, Represents the number of prediction boxes generated by the proxy detection model; Represents the true value of the label box; represents the set of matching prediction boxes, , and Respectively represent g Prediction boxes The center point coordinates and their corresponding length and width; define Indicates the g The predicted boxes correspond to the label boxes; The type of the target object in the prediction box; It is the logit output, which indicates the probability that the predicted box is the true target; Indicates the number of label boxes; represents the weight assigned to the loss and is set to 0.5 to ensure a balance between the two tasks.

5. The radar image adversarial sample generation and target detection attack method based on meta-adversarial despeckling network according to claim 1, characterized in that: The meta-training includes: For the i tasks, which include training samples ,use t Proxy Detection Model Integration to guide the despeckle network Generate adversarial despeckled images; for the i The first task j The first training sample m The confidence loss of the proxy detection model can be expressed as , ; Combine the confidence losses of all proxy detection models, for the i The first of the tasks j training samples, the total confidence loss of all proxy detection models is: ; in, Represents the input real SAR detection image When , the adversarial despeckled image generated by the adversarial filtering network; is the weight of each surrogate model, ,and ; is the confidence loss; The minimum confidence loss and the despeckle loss are used to jointly optimize the adversarial despeckle network. The objective optimization function of meta-training is: ; in , ; and further expand the above formula as follows: 。 6. The radar image adversarial sample generation and target detection attack method based on meta-adversarial despeckling network according to claim 1, characterized in that: The meta-tests include: Use the trained adversarial despeckle network model to attack the last sampled proxy detection model , enter K +1 test sample , by calculating The confidence loss further optimizes the trained adversarial despeckle network: ; in, is the confidence loss; Referring to the meta-training process, the objective optimization function of the meta-testing process is: 。 7. A radar image adversarial sample generation and target detection attack system based on meta-adversarial despeckle network, characterized by: include: A simulated speckle filter data set construction module is used to construct a simulated speckle filter data set for the optical image data set based on the speckle statistical model; The construction of the simulated speckle filter data set comprises the following steps: Based on the optical image data set, the first v images Construct the equivalent view number as Simulated speckle image , forming a training data pair ; Among them, the coherent speckle statistical model is: ; Indicates the image size, To simulate the coherent speckle image, represents the Hadamrd product, is the optical image data image, is a coherent speckle; in the case of a unit mean and a variance of In the case of Gamma distribution, The probability density distribution of is: ; in, represents the gamma distribution, It is the number of views in the optical image formation process; All training data pairs in the optical image dataset Constructing a simulated speckle filter data set; A real SAR image target detection and filtering dataset construction module is used to train a despeckling network based on the constructed simulated speckle filtering dataset, and to construct a real SAR image target detection and filtering dataset in combination with the real SAR detection dataset. The construction of the real SAR image target detection and filtering dataset includes the following steps: Training the despeckle network based on the constructed simulated speckle filtering dataset , and load the despeckle network trained weights; Despeckle Network The trained weights are used to calculate the first r images Perform inference to obtain the corresponding despeckled image , forming a real SAR detection data set data pair ; All data pairs in the real SAR detection dataset Construct a real SAR image target detection and filtering dataset; The meta-adversarial despeckle network training module is used to construct a meta-adversarial despeckle network training framework and train the meta-adversarial despeckle network model using a real SAR image target detection and filtering dataset. The construction of the meta-adversarial despeckle network training framework includes: Based on the given inclusion U Model set of proxy detection models , randomly selected times, each extraction t +1 proxy detection model, consisting of tasks, each of which also includes randomly selected K images, each image is considered as a training sample, in the i In the task, the training samples are recorded as , ; Each task includes a meta-training phase and a meta-testing phase, which are used to build a meta-adversarial despeckle network training framework. In each task, the first t The proxy detection models are used in the meta-training phase, and the last proxy detection model is used in the meta-testing phase; In the meta-training phase, t Proxy detection model ensemble attack despeckle network Get the trained adversarial despeckle network ; In the meta-test phase, the trained adversarial despeckle network is used Attacking the last proxy detection model makes it easier to transfer the generated adversarial images to other proxy detection models; The original SAR image processing module uses the trained meta-adversarial despeckling network model to perform adversarial despeckling on the original SAR image.

Citation Information

Patent Citations

  • SAR image simulation method based on conditional generative adversarial network

    CN111462012A

  • Rice extraction method based on semi-supervised learning generative adversarial network

    CN118366044A