A journal of IEEE and CAA , publishes high-quality papers in English on original theoretical/experimental research and development in all areas of automation
Volume 13 Issue 7
Jul.  2026

IEEE/CAA Journal of Automatica Sinica

  • JCR Impact Factor: 18.3, Top 1 (SCI Q1)
    CiteScore: 28.2, Top 1% (Q1)
    Google Scholar h5-index: 95, TOP 5
Turn off MathJax
Article Contents
G.-Q. Zeng, H.-N. Wei, K.-D. Lu, and G.-G. Geng, “CMo-IABA: Constrained multi-objective invisible and adaptive backdoor attack for deep neural networks-based SAR image classification,” IEEE/CAA J. Autom. Sinica, vol. 13, no. 7, pp. 1731–1746, Jul. 2026. doi: 10.1109/JAS.2025.125888
Citation: G.-Q. Zeng, H.-N. Wei, K.-D. Lu, and G.-G. Geng, “CMo-IABA: Constrained multi-objective invisible and adaptive backdoor attack for deep neural networks-based SAR image classification,” IEEE/CAA J. Autom. Sinica, vol. 13, no. 7, pp. 1731–1746, Jul. 2026. doi: 10.1109/JAS.2025.125888

CMo-IABA: Constrained Multi-Objective Invisible and Adaptive Backdoor Attack for Deep Neural Networks-Based SAR Image Classification

doi: 10.1109/JAS.2025.125888
Funds:  This work was supported in part by the Zhejiang Provincial Natural Science Foundation of China (LZ25F030007), the National Natural Science Foundation of China (62573326, 62533016, 62403122), the Shanghai Sailing Program (24YF2701300), and Guangdong Key Laboratory of Data Security and Privacy Preserving (2023B1212060036)
More Information
  • Deep neural networks (DNNs) have been widely applied in the field of synthetic aperture radar (SAR) image while they are facing more and more serious threats from a variety of malicious attacks. As one of the malicious attacks with strong destructiveness and stealth, backdoor attacks have severely affected DNNs, but there are no related research studies concerning the backdoor attacks against the DNNs-based SAR image classification models. In this work, we make the first attempt to automatically design a constrained multi-objective invisible and adaptive backdoor attack termed as CMo-IABA for DNNs-based SAR image classification. In the CMo-IABA, we firstly generate an initial trigger-based backdoor attack randomly by a random combination of pixels with random noise conforming to the Gaussian distribution. Then, we design multi-objective functions by considering the trade-off between maximizing the attack success rate and minimizing $ L_2 $ distance-based invisibility. The classification error between the backdoor DNN and the clean model is considered as the constraint to maintain the original performance of the model. To solve the optimization problem, a discrete non-dominated sorting genetic algorithm-II is introduced as the search engine with the developed crossover operation and mutation operation. The superiority of the proposed CMo-IABA to five state-of-the-art backdoor attacks on six different types of DNNs-based SAR image classification models has been demonstrated by the experimental results on Fudan University SAR (FUSAR)-ship and moving and stationary target acquisition and recognition (MSTAR) datasets in terms of attack success rate and $ L_2 $ distance-based invisibility.

     

  • loading
  • [1]
    F. Zhang, T. Meng, D. Xiang, F. Ma, X. Sun, and Y. Zhou, “Adversarial deception against SAR target recognition network,” IEEE J. Sel. Top. Appl. Earth Obs. Remote Sens., vol. 15, pp. 4507–4520, May 2022. doi: 10.1109/JSTARS.2022.3179171
    [2]
    H. Sun, J. Chen, L. Lei, K. Ji, and G. Kuang, “Adversarial robustness of deep convolutional neural network-based image recognition models: A review,” J. Radars, vol. 10, no. 4, pp. 571–594, Aug. 2021.
    [3]
    L. Chen, Z. Xu, Q. Li, J. Peng, S. Wang, and H. Li, “An empirical study of adversarial examples on remote sensing image scene classification,” IEEE Trans. Geosci. Remote Sens., vol. 59, no. 9, pp. 7419–7433, Sep. 2021. doi: 10.1109/TGRS.2021.3051641
    [4]
    C. Du, C. Huo, L. Zhang, B. Chen, and Y. Yuan, “Fast C&W: A fast adversarial attack algorithm to fool SAR target recognition with deep convolutional neural networks,” IEEE Geosci. Remote Sens. Lett., vol. 19, Art. no. 4010005, 2022. doi: 10.1109/lgrs.2021.3058011
    [5]
    H. Li, H. Huang, L. Chen, J. Peng, H. Huang, Z. Cui, X. Mei, and G. Wu, “Adversarial examples for CNN-based SAR image classification: An experience study,” IEEE J. Sel. Top. Appl. Earth Obs. Remote Sens., vol. 14, pp. 1333–1347, 2021. doi: 10.1109/JSTARS.2020.3038683
    [6]
    Q. Zhang, W. Ma, Y. Wang, Y. Zhang, Z. Shi, and Y. Li, “Backdoor attacks on image classification models in deep neural networks,” Chin. J. Electron., vol. 31, no. 2, pp. 199–212, Mar. 2022. doi: 10.1049/cje.2021.00.126
    [7]
    B. Biggio, B. Nelson, and P. Laskov, “Poisoning attacks against support vector machines,” in Proc. 29th Int. Conf. Machine Learning, Edinburgh, Scotland, 2012, pp. 1467−1474.
    [8]
    C. Yang, Q. Wu, H. Li, and Y. Chen, “Generative poisoning attack method against neural networks,” arXiv preprint arXiv: 1703.01340, 2017.
    [9]
    A. Shafahi, W. R. Huang, M. Najibi, O. Suciu, C. Studer, T. Dumitras, and T. Goldstein, “Poison frogs! Targeted clean-label poisoning attacks on neural networks,” in Proc. 32nd Int. Conf. Neural Information Processing Systems, Montréal, Canada, 2018, pp. 6106−6116.
    [10]
    C. Ren, C. Zou, Z. Xiong, H. Yu, Z.-Y. Dong, and N. Dusit, “Achieving 500X acceleration for adversarial robustness verification of tree-based smart grid dynamic security assessment,” IEEE/CAA J. Autom. Sinica, vol. 11, no. 3, pp. 800–802, Mar. 2024. doi: 10.1109/JAS.2023.124053
    [11]
    I. J. Goodfellow, J. Shlens, and C. Szegedy, “Explaining and harnessing adversarial examples,” arXiv preprint arXiv: 1412.6572v3, 2015.
    [12]
    A. Madry, A. Makelov, L. Schmidt, D. Tsipras, and A. Vladu, “Towards deep learning models resistant to adversarial attacks,” arXiv preprint arXiv: 1706.06083, 2017.
    [13]
    N. Carlini and D. Wagner, “Towards evaluating the robustness of neural networks,” in Proc. IEEE Symp. Secur. Privacy, San Jose, USA, 2017, pp. 39–57.
    [14]
    S.-M. Moosavi-Dezfooli, A. Fawzi, and P. Frossard, “DeepFool: A simple and accurate method to fool deep neural networks,” in Proc. IEEE Conf. Computer Vision and Pattern Recognition, Las Vegas, USA, 2016, pp. 2574−2582.
    [15]
    T. Gu, B. Dolan-Gavitt, and S. Garg, “BadNets: Identifying vulnerabilities in the machine learning model supply chain,” arXiv preprint arXiv: 1708.06733, 2017.
    [16]
    X. Chen, C. Liu, B. Li, K. Lu, and D. Song, “Targeted backdoor attacks on deep learning systems using data poisoning,” arXiv preprint arXiv: 1712.05526, 2017.
    [17]
    E. Wenger, J. Passanati, Y. Yao, H. Zheng, and B. Y. Zhao, “Backdoor attacks on facial recognition in the physical world,” arXiv preprint arXiv: 2006.14580, 2020.
    [18]
    E. Sarkar, H. Benkraouda, and M. Maniatakos, “FaceHack: Triggering backdoored facial recognition systems using facial characteristics,” arXiv preprint arXiv: 2006.11623, 2020.
    [19]
    M. Xue, X. Wang, S. Sun, Y. Zhang, J. Wang, and W. Liu, “Compression-resistant backdoor attack against deep neural networks,” Appl. Intell., vol. 53, no. 17, pp. 20402–20417, Apr. 2023. doi: 10.1007/s10489-023-04575-8
    [20]
    E. Quiring and K. Rieck, “Backdooring and poisoning neural networks with image-scaling attacks,” in Proc. IEEE Security and Privacy Workshops, San Francisco, USA, 2020, pp. 41−47.
    [21]
    T. A. Nguyen and A. T. Tran, “WaNet-imperceptible warping-based backdoor attack,” arXiv preprint arXiv: 2102.10369v4, 2021.
    [22]
    K. Doan, Y. Lao, and P. Li, “Backdoor attack with imperceptible input and latent modification,” in Proc. 35th Int. Conf. Neural Inform. Processing Systems, 2021, Art. no. 1448.
    [23]
    Y. Ren, L. Li, and J. Zhou, “Simtrojan: Stealthy backdoor attack,” in Proc. IEEE Int. Conf. Image Processing, Anchorage, USA, 2021, pp. 819−823.
    [24]
    J. Geiping, L. H. Fowl, W. R. Huang, W. Czaja, G. Taylor, M. Moeller, and T. Goldstein, “Witches’ brew: Industrial scale data poisoning via gradient matching,” arXiv preprint arXiv: 2009.02276v2, 2021.
    [25]
    T. A. Nguyen and T. A. Tran, “Input-aware dynamic backdoor attack,” in Proc. 34th Int. Conf. Neural Information Processing Systems, Vancouver, Canada, 2020, Art. no. 291.
    [26]
    Y. Li, Y. Jiang, Z. Li, and S.-T. Xia, “Backdoor learning: A survey,” IEEE Trans. Neural Networks Learn. Syst., vol. 35, no. 1, pp. 5–22, Jan. 2024. doi: 10.1109/TNNLS.2022.3182979
    [27]
    H. Chen, B. D. Rouhani, C. Fu, J. Zhao, and F. Koushanfar, “DeepMarks: A secure fingerprinting framework for digital rights management of deep learning models,” in Proc. Int. Conf. Multimedia Retrieval, Ottawa, Canada, 2019, pp. 105−113.
    [28]
    J. Zhang, C. Dongdong, Q. Huang, J. Liao, W. Zhang, H. Feng, G. Hua, and N. Yu, “Poison ink: Robust and invisible backdoor attack,” IEEE Trans. Image Process., vol. 31, pp. 5691–5705, Aug. 2022. doi: 10.1109/TIP.2022.3201472
    [29]
    Y. Liu, X. Ma, J. Bailey, and F. Lu, “Reflection backdoor: A natural backdoor attack on deep neural networks,” in Proc. 16th European Conf. Computer Vision, Glasgow, UK, 2020, pp. 182−199.
    [30]
    A. Turner, D. Tsipras, and A. Madry, “Clean-label backdoor attacks,” in Proc. 7th Int. Conf. Learning Representations, New Orleans, USA, 2019.
    [31]
    E. Brewer, J. Lin, and D. Runfola, “Susceptibility & defense of satellite image-trained convolutional networks to backdoor attacks,” Inf. Sci., vol. 603, pp. 244–261, Jul. 2022. doi: 10.1016/j.ins.2022.05.004
    [32]
    N. Dräger, Y. Xu, and P. Ghamisi, “Backdoor attacks for remote sensing data with wavelet transform,” IEEE Trans. Geosci. Remote Sens., vol. 61, Art no. 5613715, Jun. 2023. doi: 10.1109/tgrs.2023.3289307
    [33]
    K. Deb, A. Pratap, S. Agarwal, and T. Meyarivan, “A fast and elitist multiobjective genetic algorithm: NSGA-II,” IEEE Trans. Evol. Computat., vol. 6, no. 2, pp. 182–197, Apr. 2002.
    [34]
    L. Guo, “SAR image classification based on multi-feature fusion decision convolutional neural network,” IET Image Process., vol. 16, no. 1, pp. 1–10, Jan. 2022.
    [35]
    M. Barni, K. Kallas, and B. Tondi, “A new backdoor attack in CNNs by training set corruption without label poisoning,” in Proc. IEEE Int. Conf. Image Processing, Taipei, China, 2019, pp. 101−105.
    [36]
    X. Hou, W. Ao, Q. Song, J. Lai, H. Wang, and F. Xu, “FUSAR-Ship: Building a high-resolution SAR-AIS matchup dataset of Gaofen-3 for ship detection and recognition,” Sci. China Inf. Sci., vol. 63, no. 4, Art. no. 140303, 2020. doi: 10.1007/s11432-019-2772-5
    [37]
    Mstar, “The air force moving and stationary target recognition database,” [Online]. Available: https://www.sdms.afrl.af.mil/index.php?collection=mstar, Accessed on: Jun. 27, 2025.
    [38]
    Y. Gao, C. Xu, D. Wang, S. Chen, D. C. Ranasinghe, and S. Nepal, “STRIP: A defence against Trojan attacks on deep neural networks,” in Proc. 35th Annu. Computer Security Applications Conf., San Juan, USA, 2019, pp. 113−125.
    [39]
    K. Liu, B. Dolan-Gavitt, and S. Garg, “Fine-pruning: Defending against backdooring attacks on deep neural networks,” in Proc. 21st Int. Symp. Research in Attacks, Intrusions, and Defenses, Heraklion, Greece, 2018, pp. 273−294.
    [40]
    R. R. Selvaraju, A. Das, R. Vedantam, M. Cogswell, D. Parikh, and D. Batra, “Grad-CAM: Why did you say that?” arXiv preprint arXiv: 1611.07450, 2016.
    [41]
    Y. Gao, B. G. Doan, Z. Zhang, S. Ma, J. Zhang, A. Fu, S. Nepal, and H. Kim, “Backdoor attacks and countermeasures on deep learning: A comprehensive review,” arXiv preprint arXiv: 2007.10760, 2020.
    [42]
    H. Zhong, C. Liao, A. C. Squicciarini, S. Zhu, and D. J. Miller, “Backdoor embedding in convolutional neural network models via invisible perturbation,” in Proc. 10th ACM Conf. Data and Application Security and Privacy, New Orleans, USA, 2020, pp. 97−108.
    [43]
    Y. Li, Y. Li, B. Wu, L. Li, R. He, and S. Lyu, “Invisible backdoor attack with sample-specific triggers,” in Proc. IEEE/CVF Int. Conf. Computer Vision, Montreal, Canada, 2021, pp. 16443−16452.
    [44]
    K. Doan, Y. Lao, W. Zhao, and P. Li, “LIRA: Learnable, imperceptible and robust backdoor attacks,” in Proc. IEEE/CVF Int. Conf. Computer Vision, Montreal, Canada, 2021, pp. 11946−11956.
    [45]
    A. Saha, A. Subramanya, and H. Pirsiavash, “Hidden trigger backdoor attacks,” in Proc. 34th AAAI Conf. Artificial Intelligence, New York, USA, 2020, pp. 11957−11965.
    [46]
    Z. Zhao, X. Chen, Y. Xuan, Y. Dong, D. Wang, and K. Liang, “DEFEAT: Deep hidden feature backdoor attacks by imperceptible perturbation and latent representation constraints,” in Proc. IEEE/CVF Conf. Computer Vision and Pattern Recognition, New Orleans, USA, 2022, pp. 15192−15201.
    [47]
    S. Li, H. Li, and H. Chen, “Stand-in backdoor: A stealthy and powerful backdoor attack,” in Proc. IEEE Global Communications Conf., Madrid, Spain, 2021, pp. 1−6.
    [48]
    J. Chen, H. Zheng, M. Su, T. Du, C. Lin, and S. Ji, “Invisible poisoning: Highly stealthy targeted poisoning attack,” in Proc. 15th Int. Conf. Information Security and Cryptology, Nanjing, China, 2019, pp. 173−198.
    [49]
    J. Shen, X. Zhu, and D. Ma, “TensorClog: An imperceptible poisoning attack on deep neural network applications,” IEEE Access, vol. 7, pp. 41498–41506, Mar. 2019. doi: 10.1109/ACCESS.2019.2905915
    [50]
    Q. Huynh-Thu and M. Ghanbari, “Scope of validity of PSNR in image/video quality assessment,” Electron. Lett., vol. 44, no. 13, pp. 800–801, Jun. 2008. doi: 10.1049/el:20080522
    [51]
    Z. Wang, A. C. Bovik, H. R. Sheikh, and E. P. Simoncelli, “Image quality assessment: From error visibility to structural similarity,” IEEE Trans. Image Process., vol. 13, no. 4, pp. 600–612, Apr. 2004. doi: 10.1109/TIP.2003.819861
    [52]
    R. Zhang, P. Isola, A. A. Efros, E. Shechtman, and O. Wang, “The unreasonable effectiveness of deep features as a perceptual metric,” in Proc. IEEE Conf. Computer Vision and Pattern Recognition, Salt Lake City, USA, 2018, pp. 586−595.
    [53]
    F. Ming, W. Gong, and Y. Jin, “Even search in a promising region for constrained multi-objective optimization,” IEEE/CAA J. Autom. Sinica, vol. 11, no. 2, pp. 474–486, Feb. 2024. doi: 10.1109/JAS.2023.123792
    [54]
    J. Liang, X. Ban, K. Yu, B. Qu, K. Qiao, C. Yue, K. Chen, and K. C. Tan, “A survey on evolutionary constrained multiobjective optimization,” IEEE Trans. EComputat., vol. 27, no. 2, pp. 201–221, Apr. 2023.
    [55]
    F. Ming, W. Gong, L. Wang, and Y. Jin, “Constrained multi-objective optimization with deep reinforcement learning assisted operator selection,” IEEE/CAA J. Autom. Sinica, vol. 11, no. 4, pp. 919–931, Apr. 2024. doi: 10.1109/JAS.2023.123687
    [56]
    Y. Tian, J. Pan, S. Yang, X. Zhang, S. He, and Y. Jin, “Imperceptible and sparse adversarial attacks via a dual-population based constrained evolutionary algorithm,” IEEE Trans. Artif. Intell., vol. 4, no. 2, pp. 268–281, Apr. 2023. doi: 10.1109/TAI.2022.3168038
    [57]
    Y. Xue, Y. Wang, J. Liang, and A. Slowik, “A self-adaptive mutation neural architecture search algorithm based on blocks,” IEEE Comput. Intell. Mag., vol. 16, no. 3, pp. 67–78, Aug. 2021. doi: 10.1109/MCI.2021.3084435
    [58]
    C. Wang, H. Gu, and W. Su, “SAR image classification using contrastive learning and pseudo-labels with limited data,” IEEE Geosci. Remote Sens. Lett., vol. 19, Art. no. 4012505, 2022. doi: 10.1109/lgrs.2021.3069224
    [59]
    B. Wu, H. Chen, M. Zhang, Z. Zhu, S. Wei, D. Yuan, and C. Shen, “BackdoorBench: A comprehensive benchmark of backdoor learning,” in Proc. 36th Int. Conf. Neural Inform. Processing Systems, New Orleans, USA, 2022, Art. no. 766.
    [60]
    E. Zitzler and L. Thiele, “Multiobjective evolutionary algorithms: A comparative case study and the strength Pareto approach,” IEEE Trans. EComput., vol. 3, no. 4, pp. 257–271, Nov. 1999.
    [61]
    B. Peng, B. Peng, J. Zhou, J. Xie, and L. Liu, “Scattering model guided adversarial examples for SAR target recognition: Attack and defense,” IEEE Trans. Geosci. Remote Sens., vol. 60, Art no. 5236217, Oct. 2022.
    [62]
    B. Peng, B. Peng, J. Zhou, J. Xia, and L. Liu, “Speckle-variant attack: Toward transferable adversarial attack to SAR target recognition,” IEEE Geosci. Remote Sens. Lett., vol. 19, Art no. 4509805, Jun. 2022. doi: 10.1109/icetci57876.2023.10176719
    [63]
    W. Xia, Z. Liu, and Y. Li, “SAR-PeGA: A generation method of adversarial examples for SAR image target recognition network,” IEEE Trans. Aerosp. Electron. Syst., vol. 59, no. 2, pp. 1910–1920, Apr. 2023.
    [64]
    J. Zhou, S. Feng, H. Sun, L. Zhang, and G. Kuang, “Attributed scattering center guided adversarial attack for DCNN SAR target recognition,” IEEE Geosci. Remote Sens. Lett., vol. 20, Art no. 4001805, Jan. 2023.
    [65]
    W. Qin, B. Long, and F. Wang, “SCMA: A scattering center model attack on CNN-SAR target recognition,” IEEE Geosci. Remote Sens. Lett., vol. 20, Art no. 4003305, Mar. 2023. doi: 10.1109/lgrs.2023.3253189
    [66]
    F. Zhang, Y. Yu, F. Ma, and Y. Zhou, “A physically realizable adversarial attack method against SAR target recognition model,” IEEE J. Sel. Top. Appl. Earth Obs. Remote Sens., vol. 17, pp. 11943–11957, Jun. 2024. doi: 10.1109/JSTARS.2024.3420690

Catalog

    通讯作者: 陈斌, bchen63@163.com
    • 1. 

      沈阳化工大学材料科学与工程学院 沈阳 110142

    1. 本站搜索
    2. 百度学术搜索
    3. 万方数据库搜索
    4. CNKI搜索

    Figures(10)  / Tables(7)

    Article Metrics

    Article views (14) PDF downloads(3) Cited by()

    /

    DownLoad:  Full-Size Img  PowerPoint
    Return
    Return