Transferable Anti-intelligence Recognition Radar Waveform Design based on Adversarial Attacks

Ruibin Zhang, Yunjie Li, Jiabin Liu*

*Corresponding author for this work

Research output: Contribution to journalArticlepeer-review

Abstract

The widespread integration of deep neural networks in modern electronic reconnaissance systems has resulted in a significant enhancement in the perception ability of these systems, thereby improving their interference effect against radar systems. In response to this challenge, this paper proposes a method for designing an anti-recognition waveform (ARW) based on adversarial attacks for the radar side. The proposed method can effectively degrade the automatic modulation recognition (AMR) performance of the reconnaissance side. Specifically, the method mainly consists of two operations: variance tuning and weighted forecasting gradients attack (VWFGA), and random packet ensemble (RPE). VWFGA incorporates weighted forecasting gradients, gradient variance, and adaptive step size to boost the ARW's transferability and accelerate the algorithm's convergence. Additionally, RPE further enhances transferability through the formulation of various model ensembles based on gradient similarities. The generated ARW can mislead AMR networks within reconnaissance systems while maintaining compatibility with signal processing methods commonly used in radar systems like pulse Doppler radar and synthetic aperture radar. Extensive experiments on a simulated dataset based on domain knowledge demonstrate that our method outperforms state-of-the-art methods and reduces the average accuracy of seventeen models by 32.82% in the black-box scenario.

Original languageEnglish
JournalIEEE Transactions on Aerospace and Electronic Systems
DOIs
Publication statusAccepted/In press - 2024

Keywords

  • Adversarial attacks
  • Automatic modulation recognition
  • Deep neural networks
  • Similarity constraint
  • Waveform design

Fingerprint

Dive into the research topics of 'Transferable Anti-intelligence Recognition Radar Waveform Design based on Adversarial Attacks'. Together they form a unique fingerprint.

Cite this