[Paper Review] Channel-Aware Adversarial Attacks Against Deep Learning-Based Wireless Signal Classifiers
The paper demonstrates channel-aware over-the-air adversarial attacks against modulation classifiers and introduces a broadcast perturbation attack and defenses via randomized smoothing and certified guarantees.
This paper presents channel-aware adversarial attacks against deep learning-based wireless signal classifiers. There is a transmitter that transmits signals with different modulation types. A deep neural network is used at each receiver to classify its over-the-air received signals to modulation types. In the meantime, an adversary transmits an adversarial perturbation (subject to a power budget) to fool receivers into making errors in classifying signals that are received as superpositions of transmitted signals and adversarial perturbations. First, these evasion attacks are shown to fail when channels are not considered in designing adversarial perturbations. Then, realistic attacks are presented by considering channel effects from the adversary to each receiver. After showing that a channel-aware attack is selective (i.e., it affects only the receiver whose channel is considered in the perturbation design), a broadcast adversarial attack is presented by crafting a common adversarial perturbation to simultaneously fool classifiers at different receivers. The major vulnerability of modulation classifiers to over-the-air adversarial attacks is shown by accounting for different levels of information available about the channel, the transmitter input, and the classifier model. Finally, a certified defense based on randomized smoothing that augments training data with noise is introduced to make the modulation classifier robust to adversarial perturbations.
Motivation & Objective
- Motivate and model adversarial threats to DNN-based modulation classifiers in wireless systems.
- Develop channel-aware white-box and black-box adversarial attack strategies that account for transmitter-to-receiver and adversary-to-receiver channel effects.
- Explore broadcast attacks that fool multiple receivers with a single perturbation.
- Propose defense mechanisms, including randomized smoothing and certified robustness, to mitigate over-the-air adversarial perturbations.
Proposed method
- Model a transmitter, multiple receivers, and an adversary with single-antenna channels performing over-the-air attacks on DNN-based modulation classifiers at each receiver.
- Formulate channel-aware adversarial perturbations under a power constraint to cause misclassification, for both targeted and non-targeted attacks.
- Develop targeted channel-aware attacks: Channel Inversion, MMSE, and MRPP variants, under white-box settings with exact channel knowledge.
- Develop non-targeted channel-aware attacks: Naive, MMSE, and MRPP variants, under white-box settings with exact channel knowledge.
- Introduce a broadcast adversarial perturbation design to jointly fool classifiers at multiple receivers by leveraging broadcast nature of wireless channels.
- Extend attacks to scenarios with limited channel information using PCA and other dimensionality-reduction techniques, and to black-box settings with universal perturbations.
- Propose defense strategies based on randomized smoothing to augment training with Gaussian noise and to provide certified robustness.
Experimental results
Research questions
- RQ1How do channel effects from the adversary to each receiver affect the design and effectiveness of adversarial perturbations for modulation classification?
- RQ2Can a common perturbation be crafted to simultaneously fool multiple receivers, leveraging wireless broadcast nature?
- RQ3How effective are channel-aware targeted and non-targeted attacks under white-box and limited-information scenarios?
- RQ4What defenses, including randomized smoothing and certified robustness, can mitigate over-the-air adversarial perturbations to modulation classifiers?
Key findings
- Channel-aware attacks significantly reduce modulation classifier accuracy compared to attacks that ignore channel effects, especially at practical perturbation powers.
- MRPP attacks (maximum received perturbation power) utilizing channel information outperform other targeted and non-targeted strategies across many settings.
- Channel-specificity creates a selective attack: a perturbation designed for one receiver often fails to fool classifiers at others with different channels, enabling broadcast attack designs.
- A broadcast perturbation can simultaneously degrade multiple receivers’ classifiers when designed with joint channel information.
- Randomized smoothing-based training improves robustness to adversarial perturbations, and a certified defense framework provides robustness guarantees under Gaussian augmentation.
Better researchstarts right now
From reading papers to final review, dramatically reduce your research time.
No credit card · Free plan available
This review was created by AI and reviewed by human editors.