• Adversarial sample generation is formulated as a joint optimization problem. • The SMPI-FGSM method is proposed to craft potent adversarial samples. • An aggression-concealment metric combining ASR and SSIM is defined. • The NSTGWOA is developed to obtain Pareto-optimal parameters. Adversarial attack is a key security issue in deep learning models for Synthetic Aperture Radar Automatic Target Recognition (SAR ATR). To balance attack effectiveness with visual concealment, this paper frames adversarial sample generation as a joint optimization problem and proposes an optimal generation method based on an Aggression-Concealment balance strategy. First, by integrating transformation and stabilized momentum mechanisms, a stabilized momentum with pre-convergence and input transformation fast gradient sign method (SMPI-FGSM) is proposed to enhance the potency of generated adversarial samples. Second, an aggression-concealment evaluation model is established, using the Attack Success Rate (ASR) and Structural Similarity (SSIM) index as objective functions for optimization. Third, by introducing Kent chaotic map, golden section strategy and time-varying weight into non-dominated sorting whale optimization algorithm (NSWOA), a non-dominated sorting time-varying golden-section whale optimization algorithm (NSTGWOA) is developed to solve the model and identify candidate optimal adversarial samples. Finally, the YOLOv8 detection network is employed to perform disturbance detection on samples within the Pareto set, thereby determining the optimal balance parameters. Experimental results demonstrate that the average ASR of SMPI-FGSM method for different classification networks is over 90%, which is 4-5% higher than that of mainstream methods. The optimal balanced adversarial samples maintain the concealment of SSIM = 0.403 while achieving ASR = 74.40 %, and the disturbance factor is only 0.089, which provides a general reference for other adversarial sample generation methods.
Su et al. (2026) studied this question.