Author Information

Is this project an undergraduate, graduate, or faculty project?

Graduate

Project Type

individual

Campus

Daytona Beach

Authors' Class Standing

Skyler Fabre, Graduate student

Lead Presenter's Name

Skyler Fabre

Lead Presenter's College

DB College of Arts and Sciences

Faculty Mentor Name

Dr. Yongxin Liu

Abstract

This project, titled Geometry-Conditioned Adversarial Defense for SAR Automatic Target Recognition via Regime-Specialist Classification Heads, addresses the critical vulnerability of deep neural networks deployed in Synthetic Aperture Radar (SAR) Automatic Target Recognition (ATR) systems to adversarial perturbations. This is where imperceptible pixel-level modifications cause confident misclassification, posing serious risks in defense and aerospace applications. The objective is to develop and evaluate RegimeResNet, a geometry-conditioned classification architecture that exploits sensor metadata unique to SAR collection systems. Rather than treating all images uniformly, RegimeResNet partitions the SAR capture space into nine geometric regimes defined by depression angle and target azimuth angle extracted from per-image XML annotation files, and trains a dedicated specialist classification head for each regime atop a shared ResNet-50 backbone. Each specialist head is further hardened through regime-aware adversarial training, in which Projected Gradient Descent (PGD) perturbations are generated exclusively through the geometrically correct head. Evaluated on the ATRNet-STAR SOC 40-class benchmark comprising over 54,000 training samples across 40 vehicle categories, preliminary results show the model achieves 85.72% clean accuracy while demonstrating substantially improved robustness under both Fast Gradient Sign Method (FGSM) and PGD attacks compared to standard ResNet baselines. A novel zero-cost adversarial detection signal, regime instability, is also introduced, measuring consistency between sensor-metadata-assigned and pixel-inferred regimes at inference time; this signal rises from exactly 0% on clean images to approximately 47% under any adversarial perturbation, providing a near-binary, attack-agnostic detector with no additional inference overhead. This work demonstrates that grounding adversarial defense in physical sensor geometry produces both stronger and more interpretable ATR systems suited to real-world defense applications.

Did this research project receive funding support (Spark, SURF, Research Abroad, Student Internal Grants, Collaborative, Climbing, or Ignite Grants) from the Office of Undergraduate Research?

No

Share

COinS
 

Geometry-Conditioned Adversarial Defense for SAR Automatic Target Recognition via Regime-Specialist Classification Heads

This project, titled Geometry-Conditioned Adversarial Defense for SAR Automatic Target Recognition via Regime-Specialist Classification Heads, addresses the critical vulnerability of deep neural networks deployed in Synthetic Aperture Radar (SAR) Automatic Target Recognition (ATR) systems to adversarial perturbations. This is where imperceptible pixel-level modifications cause confident misclassification, posing serious risks in defense and aerospace applications. The objective is to develop and evaluate RegimeResNet, a geometry-conditioned classification architecture that exploits sensor metadata unique to SAR collection systems. Rather than treating all images uniformly, RegimeResNet partitions the SAR capture space into nine geometric regimes defined by depression angle and target azimuth angle extracted from per-image XML annotation files, and trains a dedicated specialist classification head for each regime atop a shared ResNet-50 backbone. Each specialist head is further hardened through regime-aware adversarial training, in which Projected Gradient Descent (PGD) perturbations are generated exclusively through the geometrically correct head. Evaluated on the ATRNet-STAR SOC 40-class benchmark comprising over 54,000 training samples across 40 vehicle categories, preliminary results show the model achieves 85.72% clean accuracy while demonstrating substantially improved robustness under both Fast Gradient Sign Method (FGSM) and PGD attacks compared to standard ResNet baselines. A novel zero-cost adversarial detection signal, regime instability, is also introduced, measuring consistency between sensor-metadata-assigned and pixel-inferred regimes at inference time; this signal rises from exactly 0% on clean images to approximately 47% under any adversarial perturbation, providing a near-binary, attack-agnostic detector with no additional inference overhead. This work demonstrates that grounding adversarial defense in physical sensor geometry produces both stronger and more interpretable ATR systems suited to real-world defense applications.

 

To view the content in your browser, please download Adobe Reader or, alternately,
you may Download the file to your hard drive.

NOTE: The latest versions of Adobe Reader do not support viewing PDF files within Firefox on Mac OS and if you are using a modern (Intel) Mac, there is no official plugin for viewing PDF files within the browser window.