VLDB 2026 Research / reviewers in the wild / expert
Jie Zhou 0031
dblp:00/5012-31
· DBLP profile ↗
8ranked-venue papers
4as first author
8since 2021 · last 2026
0009-0004-3384-0556ORCID · verified
Domains — the database's venue-derived domains; a paper can count in several
Applied, interdisciplinary, general and emerging computing · 5 · 3 first-author · 5 since 2021Artificial intelligence and machine learning · 2 · 2 since 2021Graphics, computer vision, multimedia, augmented reality and games · 1 · 1 first-author · 1 since 2021
| Year | Publication | Venue | Position |
|---|---|---|---|
| 2026 | ATRNet-STAR: A Large Dataset and Benchmark Toward Remote Sensing Object Recognition in the WildabstractThe absence of publicly available, large-scale, high-quality datasets for Synthetic Aperture Radar Automatic Target Recognition (SAR ATR) has significantly hindered the application of rapidly advancing deep learning techniques, which hold huge potential to unlock new capabilities in this field. This is primarily because collecting large volumes of diverse target samples from SAR images is prohibitively expensive, largely due to privacy concerns, the characteristics of microwave radar imagery perception, and the need for specialized expertise in data annotation. Throughout the history of SAR ATR research, there have been only a number of small datasets, mainly including targets like ships, airplanes, buildings, etc. There is only one vehicle dataset MSTAR collected in the 1990 s, which has been a valuable source for SAR ATR. To fill this gap, this paper introduces a large-scale, new dataset named ATRNet-STAR with 40 different vehicle categories collected under various realistic imaging conditions and scenes. It marks a substantial advancement in dataset scale and diversity, comprising over 190,000 well-annotated samples-$10\times$ larger than its predecessor, the famous MSTAR. Building such a large dataset is a challenging task, and the data collection scheme will be detailed. Secondly, we illustrate the value of ATRNet-STAR via extensively evaluating the performance of 15 representative methods with 7 different experimental settings on challenging classification and detection benchmarks derived from the dataset. Finally, based on our extensive experiments, we identify valuable insights for SAR ATR and discuss potential future research directions in this field. We hope that the scale, diversity, and benchmark of ATRNet-STAR can significantly facilitate the advancement of SAR ATR. Yongxiang Liu, Li Liu 0002, Jie Zhou 0031, Bowen Peng, Xuying Xiong, Wei Yang 0046, Tianpeng Liu, Zhen Liu 0004, Xiang Li 0014 |
IEEE Trans. Pattern Anal. Mach. Intell. | 4 |
| 2025 | MaDiNet: Mamba Diffusion Network for SAR Target DetectionabstractThe fundamental challenge in SAR target detection lies in developing discriminative, efficient, and robust representations of target characteristics within intricate non-cooperative environments. However, accurate target detection is impeded by factors including the sparse distribution and discrete features of the targets, as well as complex background interference. In this study, we propose a Gamma Diffusion Model Network with MambaSAR module (MaDiNet) for SAR target detection. Specifically, MaDiNet leverages the Gamma distribution to model the statistical characteristics of SAR images, and conceptulizes SAR target detection as the task of generating target bounding boxes in the image space. Furthermore, we design a MambaSAR module to capture intricate spatial structural information of targets and enhance the capability of the model to differentiate between targets and complex backgrounds. The experimental results on multi-class target detection datasets have all achieved SOTA, with a particularly notable improvement of 6.7% in mAP50 on the ODSOG-1.0 dataset, proving the effectiveness of the proposed network. Code is available at https://github.com/JoyeZLearning/MaDiNet. Jie Zhou 0031, Yongxiang Liu, Bowen Peng, Li Liu 0002, Xiang Li 0014 |
IEEE Trans. Circuits Syst. Video Technol. | 1 |
| 2024 | Conditional Random Field-Based Adversarial Attack Against SAR Target DetectionabstractThe existence of adversarial examples causes serious security risks when deep neural networks are applied to synthetic aperture radar (SAR) target detection. In SAR image processing, the added small disturbances can cause the model to output incorrect predictions. Due to the multipath effect in the propagation of detection signals, there are complex interactions between targets and their surroundings serving as supportive clues for target detection. The interactions are manifested as tight correlations between pixels and contextual information in the SAR image (where context refers to various relationships, e.g., target-to-target co-occurrence relationships). In this letter, we proposed a novel conditional random field-based adversarial attack (CRFA) method, which disturbs the intrinsic interactions between the target and its surroundings. To the best of our knowledge, we are the first to exploit the contextual information for attacking the SAR target detector. We formulate the attack as an optimization problem and design the context information loss to calculate the energy differences in local feature patterns before and after perturbation. By maximizing the energy differences, the context area information around the target is destroyed, and the detector outputs the candidate box with a slight shift, even ignoring the ground truth and missing targets. Extensive experimental results on the SAR Ship Detection dataset (SSDD) demonstrate that our proposed algorithm reduces mAP by 4.29% on existing object detection models, validating the effectiveness of the method. Jie Zhou 0031, Jianyue Xie, Bowen Peng, Li Liu 0002, Xiang Li 0014 |
IEEE Geosci. Remote. Sens. Lett. | 1 |
| 2024 | DiffDet4SAR: Diffusion-Based Aircraft Target Detection Network for SAR ImagesabstractAircraft target detection in SAR images is a challenging task due to the discrete scattering points and severe background clutter interference. Currently, methods with convolution-based or transformer-based paradigms cannot adequately address these issues. In this letter, we explore diffusion models for SAR image aircraft target detection for the first time and propose a novel Diffusion-based aircraft target Detection network for SAR images (DiffDet4SAR). Specifically, the proposed DiffDet4SAR yields two main advantages for SAR aircraft target detection: 1) DiffDet4SAR maps the SAR aircraft target detection task to a denoising diffusion process of bounding boxes without heuristic anchor size selection, effectively enabling large variations in aircraft sizes to be accommodated; and 2) the dedicatedly designed Scattering Feature Enhancement (SFE) module further reduces the clutter intensity and enhances the target saliency during inference. Extensive experimental results on the SAR-AIRcraft-1.0 dataset show that the proposed DiffDet4SAR achieves 88.4% mAP50, outperforming the state-of-the-art methods by 6%. Code is availabel at https://github.com/JoyeZLearning/DiffDet4SAR. Jie Zhou 0031, Zhen Liu 0004, Li Liu 0002, Yongxiang Liu, Xiang Li 0014 |
IEEE Geosci. Remote. Sens. Lett. | 1 |
| 2023 | Low-Frequency Features Optimization for Transferability Enhancement in Radar Target Adversarial Attack
Bowen Peng, Jie Zhou 0031, Xichen Huang, Lingxin Meng, Xunzhang Gao |
ICANN (5) | 3 |
| 2022 | Adversarial Attacks on Radar Target Recognition Based on Deep LearningabstractSynthetic aperture radar (SAR) image classification is a challenging problem due to the complex imaging mechanism as well as the random speckle noise, which affects radar image interpretation. Recently, deep neural networks (DNNs) have been shown to outperform previous state-of-the-art techniques in computer vision tasks owing to their ability to learn relevant features from the data. However, the fragility of these models has received far less academic attention in the remote sensing community, which limits our understanding of the security of remote sensing image classification models. To explore the basic characteristic of adversarial examples of SAR images, we compare several mainstream adversarial methods and evaluate the securities of used DNNs from the perspective of attention. We subsequently perform other attempts. The experimental results provide data support and an effective reference for the defense capabilities of various DNNs regarding attack in SAR image classification models. Jie Zhou 0031, Bowen Peng |
IGARSS | 1 |
| 2022 | Speckle-Variant Attack: Toward Transferable Adversarial Attack to SAR Target RecognitionabstractRecent advances of deep neural networks (DNNs) highlight the success on synthetic aperture radar automatic target recognition (SAR ATR) with superiority effectiveness and efficiency. However, the DNNs are known to be vulnerable to the adversarial examples, whose performance will be dramatically reduced when the imperceptible perturbation exists. In optical image processing, invisible perturbations are typically embedded in the way of a full-scaled distribution in purely digital setting. Whereas, it is not feasible to achieve this in SAR ATR tasks due to the inaccessibility of SAR system and unique imaging mechanism. In practical, the subtle perturbations could be produced by physical approaches that change the scattering property of the target. Therefore, the adversarial perturbations for SAR ATR should be of good transferability to achieve effective attack on major DNNs classifiers, as well as accessible additive region in SAR images with respect to the realistic target locations. In this letter, we present a novel approach, namely speckle variant attack (SVA). The proposed SVA is composed of two major modules: an iterative gradient based perturbation generator and a target region extractor. The perturbation generator implements a speckle variant transformation that continuously reconstruct the speckle noise pattern during each of the iterations for strong transferability. The target region extractor ensures the feasibility of the additive adversarial perturbations in practical scenarios through restricting the region of the perturbation. Therefore, the proposed SVA is capable of producing adversarial examples that are more transferable and physically feasible. Extensive evaluations on the MSTAR dataset show that the SVA has achieved the superior transferability and competitive time consumption compared with the SOTA transformation-based techniques, including the diverse inputs method and the scale-invariant method. Bowen Peng, Jie Zhou 0031, Jingyuan Xia, Li Liu 0002 |
IEEE Geosci. Remote. Sens. Lett. | 3 |
| 2022 | Scattering Model Guided Adversarial Examples for SAR Target Recognition: Attack and DefenseabstractDeep Neural Networks (DNNs) based Synthetic Aperture Radar (SAR) Automatic Target Recognition (ATR) systems have shown to be highly vulnerable to adversarial perturbations that are deliberately designed yet almost imperceptible but can bias DNN inference when added to targeted objects. This leads to serious safety concerns when applying DNNs to high-stakes SAR ATR applications. Therefore, enhancing the adversarial robustness of DNNs is essential for applying DNNs to modern real-world SAR ATR systems. Toward building more robust DNN-based SAR ATR models, this article explores the domain knowledge of SAR imaging process and proposes a novel Scattering Model Guided Adversarial Attack (SMGAA) algorithm which can generate adversarial perturbations in the form of electromagnetic scattering response (called adversarial scatterers). The proposed SMGAA consists of two parts: 1) a parametric scattering model and corresponding imaging method and 2) a customized gradient-based optimization algorithm. First, we introduce the effective Attributed Scattering Center Model (ASCM) and a general imaging method to describe the scattering behavior of typical geometric structures in the SAR imaging process. By further devising several strategies to take the domain knowledge of SAR target images into account and relax the greedy search procedure, the proposed method does not need to be prudentially finetuned, and can efficiently find the effective ASCM parameters to fool the SAR classifiers and facilitate the robust model training. Comprehensive evaluations on the MSTAR dataset show that the adversarial scatterers generated by SMGAA are more robust to perturbations and transformations in the SAR processing chain than the currently studied attacks, and are effective to construct a defensive model against the malicious scatterers. Bowen Peng, Jie Zhou 0031, Jianyue Xie, Li Liu 0002 |
IEEE Trans. Geosci. Remote. Sens. | 3 |