SAIPAS: Simulating aspect-angles-invariant physical adversarial attacks on SAR target recognition models
Synthetic aperture radar (SAR) enables versatile, all-time, all-weather remote sensing. Coupled with automatic target recognition (ATR) leveraging machine learning (ML), SAR is empowering a wide range of Earth observation and surveillance applications. However, the surge of attacks based on adversarial perturbations against the ML algorithms underpinning SAR ATR is prompting the need for systematic research into adversarial perturbation mechanisms. Research in this area began in the digital (image) domain and evolved into the (simulated) physical domain, resulting in physical adversarial attacks (PAAs) that strategically exploit corner reflectors as attack vectors to evade ML-based ATR. Existing PAAs assume that the attacker knows the SAR platform's aspect angles, restricting their applicability to idealized scenarios. We propose the Simulated Aspect-angle-Invariant Physical Adversarial SAR attack (SAIPAS), a framework that determines adversarially effective positions and orientations of any given set of reflectors, regardless of their number or size, even when the attacker lacks knowledge of the SAR platform's aspect angles. This is enabled by rigorous physics-based modeling of the reflected signal and the SAR imaging process. To facilitate mapping between image and scene coordinates, we additionally propose a method for generating bounding boxes in densely sampled azimuthal SAR images, allowing the target object to serve as a spatial reference. The resulting adversarial configurations offer a clear physical interpretation while maintaining high fooling rates across continuous aspect trajectories under more realistic operational assumptions (69.1% for AConvNet for a four-reflector white-box attack). This paper has supplementary material available, which demonstrates the SAIPAS.