TY - JOUR
T1 - Transferable Anti-intelligence Recognition Radar Waveform Design based on Adversarial Attacks
AU - Zhang, Ruibin
AU - Li, Yunjie
AU - Liu, Jiabin
N1 - Publisher Copyright:
© 1965-2011 IEEE.
PY - 2024
Y1 - 2024
N2 - The widespread integration of deep neural networks in modern electronic reconnaissance systems has resulted in a significant enhancement in the perception ability of these systems, thereby improving their interference effect against radar systems. In response to this challenge, this paper proposes a method for designing an anti-recognition waveform (ARW) based on adversarial attacks for the radar side. The proposed method can effectively degrade the automatic modulation recognition (AMR) performance of the reconnaissance side. Specifically, the method mainly consists of two operations: variance tuning and weighted forecasting gradients attack (VWFGA), and random packet ensemble (RPE). VWFGA incorporates weighted forecasting gradients, gradient variance, and adaptive step size to boost the ARW's transferability and accelerate the algorithm's convergence. Additionally, RPE further enhances transferability through the formulation of various model ensembles based on gradient similarities. The generated ARW can mislead AMR networks within reconnaissance systems while maintaining compatibility with signal processing methods commonly used in radar systems like pulse Doppler radar and synthetic aperture radar. Extensive experiments on a simulated dataset based on domain knowledge demonstrate that our method outperforms state-of-the-art methods and reduces the average accuracy of seventeen models by 32.82% in the black-box scenario.
AB - The widespread integration of deep neural networks in modern electronic reconnaissance systems has resulted in a significant enhancement in the perception ability of these systems, thereby improving their interference effect against radar systems. In response to this challenge, this paper proposes a method for designing an anti-recognition waveform (ARW) based on adversarial attacks for the radar side. The proposed method can effectively degrade the automatic modulation recognition (AMR) performance of the reconnaissance side. Specifically, the method mainly consists of two operations: variance tuning and weighted forecasting gradients attack (VWFGA), and random packet ensemble (RPE). VWFGA incorporates weighted forecasting gradients, gradient variance, and adaptive step size to boost the ARW's transferability and accelerate the algorithm's convergence. Additionally, RPE further enhances transferability through the formulation of various model ensembles based on gradient similarities. The generated ARW can mislead AMR networks within reconnaissance systems while maintaining compatibility with signal processing methods commonly used in radar systems like pulse Doppler radar and synthetic aperture radar. Extensive experiments on a simulated dataset based on domain knowledge demonstrate that our method outperforms state-of-the-art methods and reduces the average accuracy of seventeen models by 32.82% in the black-box scenario.
KW - Adversarial attacks
KW - Automatic modulation recognition
KW - Deep neural networks
KW - Similarity constraint
KW - Waveform design
UR - http://www.scopus.com/inward/record.url?scp=85208673900&partnerID=8YFLogxK
U2 - 10.1109/TAES.2024.3490540
DO - 10.1109/TAES.2024.3490540
M3 - Article
AN - SCOPUS:85208673900
SN - 0018-9251
JO - IEEE Transactions on Aerospace and Electronic Systems
JF - IEEE Transactions on Aerospace and Electronic Systems
ER -