arrow
返回

Universal Attack Against Automatic Modulation Classification DNNs Under Frequency and Data Constraints

delete2023-07-15
delete6
PRE
AI
C
Chao Wang
X
Xianglin Wei
J
Jianhua Fan
Y
Yongyang Hu
L
Long Yu *
Q
Qing Tian
DOI:10.1109/JIOT.2023.3254648delete
delete原文链接
delete原文求助
delete分享
delete收藏
摘要

摘要

En 中文
In spite of unique advantages like higher recognition accuracy and better generalization capability, automatic modulation classification (AMC)-oriented deep neural networks (ADNNs) are still vulnerable to adversarial examples (AEs). Recent results revealed that an attacker can easily fool ADNNs through adding a small and imperceptible perturbation to the original signal. Among different AE generation methods, universal adversarial perturbation (UAP) has unique characteristics, including input agnostic and shift invariance. However, applying UAP directly to RF signals faces three main challenges, i.e., perturbation neutralization, high perceptibility, and dependency of original signals. In this backdrop, a novel UAP under frequency and data constraints (UAP-FD) attack is put forward for solving these problems in this article. First, an individual perturbation is filtered based on the representation visualization algorithm to counter the neutralization problem in perturbation integration. Second, the high-frequency components in the integrated UAP is eliminated through signal decomposition and reconstruction for promoting the imperceptibility. Third, a proxy signal generation method is proposed to help UAP-FD adapt to data-free black-box settings. A series of experiments is conducted to evaluate the aggressiveness and imperceptibility of UAP-FD attack in different settings on a public data set. Results show that, compared with the existing proposal, UAP-FD has a 40% higher fooling rate, and it can reduce the accuracy of the ADNN model from 83% to 9% while maintaining a good imperceptibility and shift-invariance property. In addition, UAP-FD is applied to real-world captured signals over the transmission channel; and it can reduce the model accuracy from 98.3% to 12.5%.
Keyword:
Adversarial attacks
automatic modulation classification (AMC)
deep learning
wireless security

期刊

IEEE Internet of Things Journal 封面图
IEEE Internet of Things Journal
IF:
8.9
论文数:
1.4W
被引数:
7.8W

机构

N
national university of defense technology - china
学者数:
1.8W
论文数: 1.4W
被引数: 9
引用论文

引用论文

Artificial Intelligence and Big Data
err
IF0
err2018-02-16
err0
PREAI
errFernando Iafrate
err分享
err收藏
Side-Channel Gray-Box Attack for DNNs
err2021-01-01
err23
PREAI
errXiang, Yun; Xu, Yongchao; Li, Yingjie; Ma, Wen; Xuan, Qi; Liu, Yi
err分享
err收藏
Large-scale real-world radio signal recognition with deep learning
err2022-09-01
err151
PREAI
errTu, Ya; Lin, Yun; Zha, Haoran; Zhang, Ju; Wang, Yu; Gui, Guan; Mao, Shiwen
err分享
err收藏
学者 查看更多内容