arrow
Return

Multi-Oriented Open Set Adversarial Attacks to Automatic Modulation Classification

delete2026-02-06
delete0
PRE
AI
Y
Yandie Yang
S
Sicheng Zhang
K
Kuixian Li
Y
Yun Lin
DOI:10.1109/TCCN.2026.3661500delete
deleteOriginal
deleteOriginal request for help
deleteShare
deleteSave
Abstract

Abstract

En 中文
Automatic Modulation Classification (AMC) plays a crucial role in spectrum monitoring and communication security. Open Set Recognition (OSR) methods have been widely applied to AMC tasks to address the challenge of recognizing known modulation types and identifying unknown modulation signals in open-world scenarios. However, existing research primarily emphasize the accuracy of open set recognition while overlooking potential security threats posed by adversarial attacks. To address this gap, we investigate the security vulnerabilities of AMC methods under adversarial attacks in open electromagnetic environments from the perspective of artificial intelligence security. We propose two types of multi-oriented open set adversarial attacks, including Label-oriented Open Set Adversarial Attacks (OSLoA) and Feature-oriented Open Set Adversarial Attack (OSFoA). Based on the discrimination mechanism of the OSR model, we propose the OSLoA method. This method increases the confidence of misclassification for unknown signals, which causes them to be recognized as known classes. Additionally, we introduce the innovative OSFoA method. It reduces the distance between the class activation features of signals from unknown classes and those of the known classes into which unknown signals are most likely to be misclassified. As a result, the unknown classes are pushed closer to the known classes in the feature space, further enhancing the attack effectiveness. Notably, during the computation of class activation features, only those features that make positive contributions to the prediction output are retained. Comprehensive experiments were conducted on both public and real-world datasets. The results demonstrate that the proposed OSLoA and OSFoA methods achieve excellent performance and further reveal the vulnerability of AMC methods to open adversarial security threats.
Keywords:
Automatic modulation classification
open set recognition
adversarial security
gradient-based adversarial attack
class activation features

Journal

I
IEEE Transactions on Cognitive Communications and Networking
IF:
7
Papers:
1.5K
Citations:
5.5K

Organization

H
harbin engineering university
Scholars:
5.3K
Papers: 1.9K
Citations: 0