Is this project an undergraduate, graduate, or faculty project?
Graduate
Project Type
individual
Campus
Daytona Beach
Authors' Class Standing
Skyler Fabre, Graduate student
Lead Presenter's Name
Skyler Fabre
Lead Presenter's College
DB College of Arts and Sciences
Faculty Mentor Name
Dr. Yongxin Liu
Abstract
This project, titled Geometry-Conditioned Adversarial Defense for SAR Automatic Target Recognition via Regime-Specialist Classification Heads, addresses the critical vulnerability of deep neural networks deployed in Synthetic Aperture Radar (SAR) Automatic Target Recognition (ATR) systems to adversarial perturbations. This is where imperceptible pixel-level modifications cause confident misclassification, posing serious risks in defense and aerospace applications. The objective is to develop and evaluate RegimeResNet, a geometry-conditioned classification architecture that exploits sensor metadata unique to SAR collection systems. Rather than treating all images uniformly, RegimeResNet partitions the SAR capture space into nine geometric regimes defined by depression angle and target azimuth angle extracted from per-image XML annotation files, and trains a dedicated specialist classification head for each regime atop a shared ResNet-50 backbone. Each specialist head is further hardened through regime-aware adversarial training, in which Projected Gradient Descent (PGD) perturbations are generated exclusively through the geometrically correct head. Evaluated on the ATRNet-STAR SOC 40-class benchmark comprising over 54,000 training samples across 40 vehicle categories, preliminary results show the model achieves 85.72% clean accuracy while demonstrating substantially improved robustness under both Fast Gradient Sign Method (FGSM) and PGD attacks compared to standard ResNet baselines. A novel zero-cost adversarial detection signal, regime instability, is also introduced, measuring consistency between sensor-metadata-assigned and pixel-inferred regimes at inference time; this signal rises from exactly 0% on clean images to approximately 47% under any adversarial perturbation, providing a near-binary, attack-agnostic detector with no additional inference overhead. This work demonstrates that grounding adversarial defense in physical sensor geometry produces both stronger and more interpretable ATR systems suited to real-world defense applications.
Did this research project receive funding support (Spark, SURF, Research Abroad, Student Internal Grants, Collaborative, Climbing, or Ignite Grants) from the Office of Undergraduate Research?
No
Geometry-Conditioned Adversarial Defense for SAR Automatic Target Recognition via Regime-Specialist Classification Heads
This project, titled Geometry-Conditioned Adversarial Defense for SAR Automatic Target Recognition via Regime-Specialist Classification Heads, addresses the critical vulnerability of deep neural networks deployed in Synthetic Aperture Radar (SAR) Automatic Target Recognition (ATR) systems to adversarial perturbations. This is where imperceptible pixel-level modifications cause confident misclassification, posing serious risks in defense and aerospace applications. The objective is to develop and evaluate RegimeResNet, a geometry-conditioned classification architecture that exploits sensor metadata unique to SAR collection systems. Rather than treating all images uniformly, RegimeResNet partitions the SAR capture space into nine geometric regimes defined by depression angle and target azimuth angle extracted from per-image XML annotation files, and trains a dedicated specialist classification head for each regime atop a shared ResNet-50 backbone. Each specialist head is further hardened through regime-aware adversarial training, in which Projected Gradient Descent (PGD) perturbations are generated exclusively through the geometrically correct head. Evaluated on the ATRNet-STAR SOC 40-class benchmark comprising over 54,000 training samples across 40 vehicle categories, preliminary results show the model achieves 85.72% clean accuracy while demonstrating substantially improved robustness under both Fast Gradient Sign Method (FGSM) and PGD attacks compared to standard ResNet baselines. A novel zero-cost adversarial detection signal, regime instability, is also introduced, measuring consistency between sensor-metadata-assigned and pixel-inferred regimes at inference time; this signal rises from exactly 0% on clean images to approximately 47% under any adversarial perturbation, providing a near-binary, attack-agnostic detector with no additional inference overhead. This work demonstrates that grounding adversarial defense in physical sensor geometry produces both stronger and more interpretable ATR systems suited to real-world defense applications.