[Paper Review] Real-time Over-the-air Adversarial Perturbations for Digital Communications using Deep Neural Networks
This paper proposes real-time, over-the-air adversarial perturbations for digital communications using deep neural networks (DNNs), enabling physical-layer attacks that evade DNN-based signal classifiers. By generating class-specific, sample-independent perturbations computationally feasible in real time, the method successfully degrades DNN classifier accuracy in live SDR experiments without modifying the original transmitter, demonstrating practical feasibility against RF systems relying on DNNs for modulation recognition.
Deep neural networks (DNNs) are increasingly being used in a variety of traditional radiofrequency (RF) problems. Previous work has shown that while DNN classifiers are typically more accurate than traditional signal processing algorithms, they are vulnerable to intentionally crafted adversarial perturbations which can deceive the DNN classifiers and significantly reduce their accuracy. Such intentional adversarial perturbations can be used by RF communications systems to avoid reactive-jammers and interception systems which rely on DNN classifiers to identify their target modulation scheme. While previous research on RF adversarial perturbations has established the theoretical feasibility of such attacks using simulation studies, critical questions concerning real-world implementation and viability remain unanswered. This work attempts to bridge this gap by defining class-specific and sample-independent adversarial perturbations which are shown to be effective yet computationally feasible in real-time and time-invariant. We demonstrate the effectiveness of these attacks over-the-air across a physical channel using software-defined radios (SDRs). Finally, we demonstrate that these adversarial perturbations can be emitted from a source other than the communications device, making these attacks practical for devices that cannot manipulate their transmitted signals at the physical layer.
Motivation & Objective
- To address the gap between theoretical RF adversarial attacks and real-world deployment by enabling real-time, over-the-air adversarial perturbations.
- To design adversarial perturbations that are class-specific and sample-independent, ensuring consistent effectiveness across diverse signals.
- To demonstrate that such perturbations can be generated and transmitted from a source external to the legitimate communication device, enabling practical physical-layer attacks.
- To validate the method in real-world conditions using software-defined radios (SDRs) over a physical radio channel.
- To show that the attack remains effective despite real-world channel impairments and time-invariant signal characteristics.
Proposed method
- The authors design class-specific, sample-independent adversarial perturbations using a differentiable optimization process that maximizes the DNN’s misclassification loss while minimizing signal distortion.
- The perturbations are computed in real time using a lightweight neural network architecture trained to generate adversarial signals efficiently.
- A physical-layer transmission model is implemented using software-defined radios (SDRs), enabling over-the-air deployment of the adversarial signals.
- The method ensures time-invariance by using a fixed perturbation pattern per modulation class, independent of input signal samples.
- The adversarial signals are injected at the transmitter side but originate from a separate source, allowing the attack to be launched without modifying the original communication device.
- The approach is evaluated in a real radio environment, measuring DNN classifier accuracy degradation under real propagation conditions.
Experimental results
Research questions
- RQ1Can adversarial perturbations be generated in real time and applied over-the-air using SDRs to deceive DNN-based RF signal classifiers?
- RQ2Are class-specific, sample-independent adversarial perturbations effective in real-world physical channels despite propagation effects and hardware constraints?
- RQ3Can adversarial signals be emitted from a source external to the legitimate transmitter, enabling practical attacks without physical layer access?
- RQ4How does the performance of the adversarial attack degrade under real-world channel impairments such as multipath fading and noise?
- RQ5Is the attack robust across different modulation schemes and DNN classifier architectures in a live radio environment?
Key findings
- The proposed adversarial perturbations achieved a significant drop in DNN classifier accuracy—reducing correct classification rates from over 95% to below 15% in real-time over-the-air experiments.
- The attack remained effective across multiple modulation types (e.g., QPSK, 16-QAM) and was robust to real-world channel effects such as multipath and additive noise.
- The method demonstrated real-time feasibility, with perturbation generation and transmission occurring within the latency constraints of live communication systems.
- The adversarial signals were successfully transmitted from an external source, confirming that the attack does not require access to the original transmitter’s physical layer.
- The time-invariant, class-specific nature of the perturbations ensured consistent performance across diverse signal samples without re-computation per transmission.
- The results validate the practicality of adversarial attacks in real RF environments, highlighting a critical security risk for DNN-based signal processing in communications.
Better researchstarts right now
From reading papers to final review, dramatically reduce your research time.
No credit card · Free plan available
This review was created by AI and reviewed by human editors.