Volume 13
Issue 7
IEEE/CAA Journal of Automatica Sinica
| Citation: | G.-Q. Zeng, H.-N. Wei, K.-D. Lu, and G.-G. Geng, “CMo-IABA: Constrained multi-objective invisible and adaptive backdoor attack for deep neural networks-based SAR image classification,” IEEE/CAA J. Autom. Sinica, vol. 13, no. 7, pp. 1731–1746, Jul. 2026. doi: 10.1109/JAS.2025.125888 |
| [1] |
F. Zhang, T. Meng, D. Xiang, F. Ma, X. Sun, and Y. Zhou, “Adversarial deception against SAR target recognition network,” IEEE J. Sel. Top. Appl. Earth Obs. Remote Sens., vol. 15, pp. 4507–4520, May 2022. doi: 10.1109/JSTARS.2022.3179171
|
| [2] |
H. Sun, J. Chen, L. Lei, K. Ji, and G. Kuang, “Adversarial robustness of deep convolutional neural network-based image recognition models: A review,” J. Radars, vol. 10, no. 4, pp. 571–594, Aug. 2021.
|
| [3] |
L. Chen, Z. Xu, Q. Li, J. Peng, S. Wang, and H. Li, “An empirical study of adversarial examples on remote sensing image scene classification,” IEEE Trans. Geosci. Remote Sens., vol. 59, no. 9, pp. 7419–7433, Sep. 2021. doi: 10.1109/TGRS.2021.3051641
|
| [4] |
C. Du, C. Huo, L. Zhang, B. Chen, and Y. Yuan, “Fast C&W: A fast adversarial attack algorithm to fool SAR target recognition with deep convolutional neural networks,” IEEE Geosci. Remote Sens. Lett., vol. 19, Art. no. 4010005, 2022. doi: 10.1109/lgrs.2021.3058011
|
| [5] |
H. Li, H. Huang, L. Chen, J. Peng, H. Huang, Z. Cui, X. Mei, and G. Wu, “Adversarial examples for CNN-based SAR image classification: An experience study,” IEEE J. Sel. Top. Appl. Earth Obs. Remote Sens., vol. 14, pp. 1333–1347, 2021. doi: 10.1109/JSTARS.2020.3038683
|
| [6] |
Q. Zhang, W. Ma, Y. Wang, Y. Zhang, Z. Shi, and Y. Li, “Backdoor attacks on image classification models in deep neural networks,” Chin. J. Electron., vol. 31, no. 2, pp. 199–212, Mar. 2022. doi: 10.1049/cje.2021.00.126
|
| [7] |
B. Biggio, B. Nelson, and P. Laskov, “Poisoning attacks against support vector machines,” in Proc. 29th Int. Conf. Machine Learning, Edinburgh, Scotland, 2012, pp. 1467−1474.
|
| [8] |
C. Yang, Q. Wu, H. Li, and Y. Chen, “Generative poisoning attack method against neural networks,” arXiv preprint arXiv: 1703.01340, 2017.
|
| [9] |
A. Shafahi, W. R. Huang, M. Najibi, O. Suciu, C. Studer, T. Dumitras, and T. Goldstein, “Poison frogs! Targeted clean-label poisoning attacks on neural networks,” in Proc. 32nd Int. Conf. Neural Information Processing Systems, Montréal, Canada, 2018, pp. 6106−6116.
|
| [10] |
C. Ren, C. Zou, Z. Xiong, H. Yu, Z.-Y. Dong, and N. Dusit, “Achieving 500X acceleration for adversarial robustness verification of tree-based smart grid dynamic security assessment,” IEEE/CAA J. Autom. Sinica, vol. 11, no. 3, pp. 800–802, Mar. 2024. doi: 10.1109/JAS.2023.124053
|
| [11] |
I. J. Goodfellow, J. Shlens, and C. Szegedy, “Explaining and harnessing adversarial examples,” arXiv preprint arXiv: 1412.6572v3, 2015.
|
| [12] |
A. Madry, A. Makelov, L. Schmidt, D. Tsipras, and A. Vladu, “Towards deep learning models resistant to adversarial attacks,” arXiv preprint arXiv: 1706.06083, 2017.
|
| [13] |
N. Carlini and D. Wagner, “Towards evaluating the robustness of neural networks,” in Proc. IEEE Symp. Secur. Privacy, San Jose, USA, 2017, pp. 39–57.
|
| [14] |
S.-M. Moosavi-Dezfooli, A. Fawzi, and P. Frossard, “DeepFool: A simple and accurate method to fool deep neural networks,” in Proc. IEEE Conf. Computer Vision and Pattern Recognition, Las Vegas, USA, 2016, pp. 2574−2582.
|
| [15] |
T. Gu, B. Dolan-Gavitt, and S. Garg, “BadNets: Identifying vulnerabilities in the machine learning model supply chain,” arXiv preprint arXiv: 1708.06733, 2017.
|
| [16] |
X. Chen, C. Liu, B. Li, K. Lu, and D. Song, “Targeted backdoor attacks on deep learning systems using data poisoning,” arXiv preprint arXiv: 1712.05526, 2017.
|
| [17] |
E. Wenger, J. Passanati, Y. Yao, H. Zheng, and B. Y. Zhao, “Backdoor attacks on facial recognition in the physical world,” arXiv preprint arXiv: 2006.14580, 2020.
|
| [18] |
E. Sarkar, H. Benkraouda, and M. Maniatakos, “FaceHack: Triggering backdoored facial recognition systems using facial characteristics,” arXiv preprint arXiv: 2006.11623, 2020.
|
| [19] |
M. Xue, X. Wang, S. Sun, Y. Zhang, J. Wang, and W. Liu, “Compression-resistant backdoor attack against deep neural networks,” Appl. Intell., vol. 53, no. 17, pp. 20402–20417, Apr. 2023. doi: 10.1007/s10489-023-04575-8
|
| [20] |
E. Quiring and K. Rieck, “Backdooring and poisoning neural networks with image-scaling attacks,” in Proc. IEEE Security and Privacy Workshops, San Francisco, USA, 2020, pp. 41−47.
|
| [21] |
T. A. Nguyen and A. T. Tran, “WaNet-imperceptible warping-based backdoor attack,” arXiv preprint arXiv: 2102.10369v4, 2021.
|
| [22] |
K. Doan, Y. Lao, and P. Li, “Backdoor attack with imperceptible input and latent modification,” in Proc. 35th Int. Conf. Neural Inform. Processing Systems, 2021, Art. no. 1448.
|
| [23] |
Y. Ren, L. Li, and J. Zhou, “Simtrojan: Stealthy backdoor attack,” in Proc. IEEE Int. Conf. Image Processing, Anchorage, USA, 2021, pp. 819−823.
|
| [24] |
J. Geiping, L. H. Fowl, W. R. Huang, W. Czaja, G. Taylor, M. Moeller, and T. Goldstein, “Witches’ brew: Industrial scale data poisoning via gradient matching,” arXiv preprint arXiv: 2009.02276v2, 2021.
|
| [25] |
T. A. Nguyen and T. A. Tran, “Input-aware dynamic backdoor attack,” in Proc. 34th Int. Conf. Neural Information Processing Systems, Vancouver, Canada, 2020, Art. no. 291.
|
| [26] |
Y. Li, Y. Jiang, Z. Li, and S.-T. Xia, “Backdoor learning: A survey,” IEEE Trans. Neural Networks Learn. Syst., vol. 35, no. 1, pp. 5–22, Jan. 2024. doi: 10.1109/TNNLS.2022.3182979
|
| [27] |
H. Chen, B. D. Rouhani, C. Fu, J. Zhao, and F. Koushanfar, “DeepMarks: A secure fingerprinting framework for digital rights management of deep learning models,” in Proc. Int. Conf. Multimedia Retrieval, Ottawa, Canada, 2019, pp. 105−113.
|
| [28] |
J. Zhang, C. Dongdong, Q. Huang, J. Liao, W. Zhang, H. Feng, G. Hua, and N. Yu, “Poison ink: Robust and invisible backdoor attack,” IEEE Trans. Image Process., vol. 31, pp. 5691–5705, Aug. 2022. doi: 10.1109/TIP.2022.3201472
|
| [29] |
Y. Liu, X. Ma, J. Bailey, and F. Lu, “Reflection backdoor: A natural backdoor attack on deep neural networks,” in Proc. 16th European Conf. Computer Vision, Glasgow, UK, 2020, pp. 182−199.
|
| [30] |
A. Turner, D. Tsipras, and A. Madry, “Clean-label backdoor attacks,” in Proc. 7th Int. Conf. Learning Representations, New Orleans, USA, 2019.
|
| [31] |
E. Brewer, J. Lin, and D. Runfola, “Susceptibility & defense of satellite image-trained convolutional networks to backdoor attacks,” Inf. Sci., vol. 603, pp. 244–261, Jul. 2022. doi: 10.1016/j.ins.2022.05.004
|
| [32] |
N. Dräger, Y. Xu, and P. Ghamisi, “Backdoor attacks for remote sensing data with wavelet transform,” IEEE Trans. Geosci. Remote Sens., vol. 61, Art no. 5613715, Jun. 2023. doi: 10.1109/tgrs.2023.3289307
|
| [33] |
K. Deb, A. Pratap, S. Agarwal, and T. Meyarivan, “A fast and elitist multiobjective genetic algorithm: NSGA-II,” IEEE Trans. Evol. Computat., vol. 6, no. 2, pp. 182–197, Apr. 2002.
|
| [34] |
L. Guo, “SAR image classification based on multi-feature fusion decision convolutional neural network,” IET Image Process., vol. 16, no. 1, pp. 1–10, Jan. 2022.
|
| [35] |
M. Barni, K. Kallas, and B. Tondi, “A new backdoor attack in CNNs by training set corruption without label poisoning,” in Proc. IEEE Int. Conf. Image Processing, Taipei, China, 2019, pp. 101−105.
|
| [36] |
X. Hou, W. Ao, Q. Song, J. Lai, H. Wang, and F. Xu, “FUSAR-Ship: Building a high-resolution SAR-AIS matchup dataset of Gaofen-3 for ship detection and recognition,” Sci. China Inf. Sci., vol. 63, no. 4, Art. no. 140303, 2020. doi: 10.1007/s11432-019-2772-5
|
| [37] |
Mstar, “The air force moving and stationary target recognition database,” [Online]. Available: https://www.sdms.afrl.af.mil/index.php?collection=mstar, Accessed on: Jun. 27, 2025.
|
| [38] |
Y. Gao, C. Xu, D. Wang, S. Chen, D. C. Ranasinghe, and S. Nepal, “STRIP: A defence against Trojan attacks on deep neural networks,” in Proc. 35th Annu. Computer Security Applications Conf., San Juan, USA, 2019, pp. 113−125.
|
| [39] |
K. Liu, B. Dolan-Gavitt, and S. Garg, “Fine-pruning: Defending against backdooring attacks on deep neural networks,” in Proc. 21st Int. Symp. Research in Attacks, Intrusions, and Defenses, Heraklion, Greece, 2018, pp. 273−294.
|
| [40] |
R. R. Selvaraju, A. Das, R. Vedantam, M. Cogswell, D. Parikh, and D. Batra, “Grad-CAM: Why did you say that?” arXiv preprint arXiv: 1611.07450, 2016.
|
| [41] |
Y. Gao, B. G. Doan, Z. Zhang, S. Ma, J. Zhang, A. Fu, S. Nepal, and H. Kim, “Backdoor attacks and countermeasures on deep learning: A comprehensive review,” arXiv preprint arXiv: 2007.10760, 2020.
|
| [42] |
H. Zhong, C. Liao, A. C. Squicciarini, S. Zhu, and D. J. Miller, “Backdoor embedding in convolutional neural network models via invisible perturbation,” in Proc. 10th ACM Conf. Data and Application Security and Privacy, New Orleans, USA, 2020, pp. 97−108.
|
| [43] |
Y. Li, Y. Li, B. Wu, L. Li, R. He, and S. Lyu, “Invisible backdoor attack with sample-specific triggers,” in Proc. IEEE/CVF Int. Conf. Computer Vision, Montreal, Canada, 2021, pp. 16443−16452.
|
| [44] |
K. Doan, Y. Lao, W. Zhao, and P. Li, “LIRA: Learnable, imperceptible and robust backdoor attacks,” in Proc. IEEE/CVF Int. Conf. Computer Vision, Montreal, Canada, 2021, pp. 11946−11956.
|
| [45] |
A. Saha, A. Subramanya, and H. Pirsiavash, “Hidden trigger backdoor attacks,” in Proc. 34th AAAI Conf. Artificial Intelligence, New York, USA, 2020, pp. 11957−11965.
|
| [46] |
Z. Zhao, X. Chen, Y. Xuan, Y. Dong, D. Wang, and K. Liang, “DEFEAT: Deep hidden feature backdoor attacks by imperceptible perturbation and latent representation constraints,” in Proc. IEEE/CVF Conf. Computer Vision and Pattern Recognition, New Orleans, USA, 2022, pp. 15192−15201.
|
| [47] |
S. Li, H. Li, and H. Chen, “Stand-in backdoor: A stealthy and powerful backdoor attack,” in Proc. IEEE Global Communications Conf., Madrid, Spain, 2021, pp. 1−6.
|
| [48] |
J. Chen, H. Zheng, M. Su, T. Du, C. Lin, and S. Ji, “Invisible poisoning: Highly stealthy targeted poisoning attack,” in Proc. 15th Int. Conf. Information Security and Cryptology, Nanjing, China, 2019, pp. 173−198.
|
| [49] |
J. Shen, X. Zhu, and D. Ma, “TensorClog: An imperceptible poisoning attack on deep neural network applications,” IEEE Access, vol. 7, pp. 41498–41506, Mar. 2019. doi: 10.1109/ACCESS.2019.2905915
|
| [50] |
Q. Huynh-Thu and M. Ghanbari, “Scope of validity of PSNR in image/video quality assessment,” Electron. Lett., vol. 44, no. 13, pp. 800–801, Jun. 2008. doi: 10.1049/el:20080522
|
| [51] |
Z. Wang, A. C. Bovik, H. R. Sheikh, and E. P. Simoncelli, “Image quality assessment: From error visibility to structural similarity,” IEEE Trans. Image Process., vol. 13, no. 4, pp. 600–612, Apr. 2004. doi: 10.1109/TIP.2003.819861
|
| [52] |
R. Zhang, P. Isola, A. A. Efros, E. Shechtman, and O. Wang, “The unreasonable effectiveness of deep features as a perceptual metric,” in Proc. IEEE Conf. Computer Vision and Pattern Recognition, Salt Lake City, USA, 2018, pp. 586−595.
|
| [53] |
F. Ming, W. Gong, and Y. Jin, “Even search in a promising region for constrained multi-objective optimization,” IEEE/CAA J. Autom. Sinica, vol. 11, no. 2, pp. 474–486, Feb. 2024. doi: 10.1109/JAS.2023.123792
|
| [54] |
J. Liang, X. Ban, K. Yu, B. Qu, K. Qiao, C. Yue, K. Chen, and K. C. Tan, “A survey on evolutionary constrained multiobjective optimization,” IEEE Trans. EComputat., vol. 27, no. 2, pp. 201–221, Apr. 2023.
|
| [55] |
F. Ming, W. Gong, L. Wang, and Y. Jin, “Constrained multi-objective optimization with deep reinforcement learning assisted operator selection,” IEEE/CAA J. Autom. Sinica, vol. 11, no. 4, pp. 919–931, Apr. 2024. doi: 10.1109/JAS.2023.123687
|
| [56] |
Y. Tian, J. Pan, S. Yang, X. Zhang, S. He, and Y. Jin, “Imperceptible and sparse adversarial attacks via a dual-population based constrained evolutionary algorithm,” IEEE Trans. Artif. Intell., vol. 4, no. 2, pp. 268–281, Apr. 2023. doi: 10.1109/TAI.2022.3168038
|
| [57] |
Y. Xue, Y. Wang, J. Liang, and A. Slowik, “A self-adaptive mutation neural architecture search algorithm based on blocks,” IEEE Comput. Intell. Mag., vol. 16, no. 3, pp. 67–78, Aug. 2021. doi: 10.1109/MCI.2021.3084435
|
| [58] |
C. Wang, H. Gu, and W. Su, “SAR image classification using contrastive learning and pseudo-labels with limited data,” IEEE Geosci. Remote Sens. Lett., vol. 19, Art. no. 4012505, 2022. doi: 10.1109/lgrs.2021.3069224
|
| [59] |
B. Wu, H. Chen, M. Zhang, Z. Zhu, S. Wei, D. Yuan, and C. Shen, “BackdoorBench: A comprehensive benchmark of backdoor learning,” in Proc. 36th Int. Conf. Neural Inform. Processing Systems, New Orleans, USA, 2022, Art. no. 766.
|
| [60] |
E. Zitzler and L. Thiele, “Multiobjective evolutionary algorithms: A comparative case study and the strength Pareto approach,” IEEE Trans. EComput., vol. 3, no. 4, pp. 257–271, Nov. 1999.
|
| [61] |
B. Peng, B. Peng, J. Zhou, J. Xie, and L. Liu, “Scattering model guided adversarial examples for SAR target recognition: Attack and defense,” IEEE Trans. Geosci. Remote Sens., vol. 60, Art no. 5236217, Oct. 2022.
|
| [62] |
B. Peng, B. Peng, J. Zhou, J. Xia, and L. Liu, “Speckle-variant attack: Toward transferable adversarial attack to SAR target recognition,” IEEE Geosci. Remote Sens. Lett., vol. 19, Art no. 4509805, Jun. 2022. doi: 10.1109/icetci57876.2023.10176719
|
| [63] |
W. Xia, Z. Liu, and Y. Li, “SAR-PeGA: A generation method of adversarial examples for SAR image target recognition network,” IEEE Trans. Aerosp. Electron. Syst., vol. 59, no. 2, pp. 1910–1920, Apr. 2023.
|
| [64] |
J. Zhou, S. Feng, H. Sun, L. Zhang, and G. Kuang, “Attributed scattering center guided adversarial attack for DCNN SAR target recognition,” IEEE Geosci. Remote Sens. Lett., vol. 20, Art no. 4001805, Jan. 2023.
|
| [65] |
W. Qin, B. Long, and F. Wang, “SCMA: A scattering center model attack on CNN-SAR target recognition,” IEEE Geosci. Remote Sens. Lett., vol. 20, Art no. 4003305, Mar. 2023. doi: 10.1109/lgrs.2023.3253189
|
| [66] |
F. Zhang, Y. Yu, F. Ma, and Y. Zhou, “A physically realizable adversarial attack method against SAR target recognition model,” IEEE J. Sel. Top. Appl. Earth Obs. Remote Sens., vol. 17, pp. 11943–11957, Jun. 2024. doi: 10.1109/JSTARS.2024.3420690
|