[论文解读] Channel-Aware Adversarial Attacks Against Deep Learning-Based Wireless Signal Classifiers
本文展示了针对调制分类器的信道感知的空中对抗攻击,并引入一种广播扰动攻击,以及通过随机平滑和认证保障的防御。
This paper presents channel-aware adversarial attacks against deep learning-based wireless signal classifiers. There is a transmitter that transmits signals with different modulation types. A deep neural network is used at each receiver to classify its over-the-air received signals to modulation types. In the meantime, an adversary transmits an adversarial perturbation (subject to a power budget) to fool receivers into making errors in classifying signals that are received as superpositions of transmitted signals and adversarial perturbations. First, these evasion attacks are shown to fail when channels are not considered in designing adversarial perturbations. Then, realistic attacks are presented by considering channel effects from the adversary to each receiver. After showing that a channel-aware attack is selective (i.e., it affects only the receiver whose channel is considered in the perturbation design), a broadcast adversarial attack is presented by crafting a common adversarial perturbation to simultaneously fool classifiers at different receivers. The major vulnerability of modulation classifiers to over-the-air adversarial attacks is shown by accounting for different levels of information available about the channel, the transmitter input, and the classifier model. Finally, a certified defense based on randomized smoothing that augments training data with noise is introduced to make the modulation classifier robust to adversarial perturbations.
研究动机与目标
- 激发并建模无线系统中基于DNN的调制分类器的对抗威胁。
- 开发考虑发射机到接收机以及对手到接收机信道效应的信道感知白盒和黑盒对抗攻击策略。
- 研究用单一扰动同时欺骗多个接收机的广播攻击。
- 提出防御机制,包括随机平滑和认证鲁棒性,以缓解空中对抗扰动。
提出的方法
- 建模一个发射机、多接收机以及具有单天线通道的对手,在每个接收机对基于DNN的调制分类器执行空中攻击。
- 在功率约束下建立信道感知对抗扰动,以引起误分类,适用于定向攻击和非定向攻击。
- 开发有针对性的信道感知攻击:信道反转、MMSE 和 MRPP 变体,在具备精确信道知识的白盒设定下。
- 开发非定向的信道感知攻击:朴素、MMSE 和 MRPP 变体,在具备精确信道知识的白盒设定下。
- 引入广播对抗扰动设计,通过利用无线信道的广播特性,联合欺骗多个接收机的分类器。
- 将攻击扩展到信道信息有限的情形,使用主成分分析等降维技术,以及在黑盒设置中使用通用扰动。
- 提出基于随机平滑的防御策略,通过引入高斯噪声来增强训练并提供认证鲁棒性。
实验结果
研究问题
- RQ1对手到每个接收机的信道效应如何影响针对调制分类的对抗扰动的设计和效果?
- RQ2是否可以设计一个通用扰动,利用无线广播特性来同时欺骗多个接收机?
- RQ3在白盒和信息有限的情形下,信道感知的定向和非定向攻击有多有效?
- RQ4包括随机平滑和认证鲁棒性在内的哪些防御措施可以缓解对调制分类器的空中对抗扰动?
主要发现
- 与忽略信道效应的攻击相比,信道感知攻击显著降低调制分类器的准确性,尤其在实际扰动功率下。
- 利用信道信息的 MRPP 攻击(最大接收扰动功率)在许多设定中优于其他定向和非定向策略。
- 信道特异性产生选择性攻击:为某个接收机设计的扰动在其他具有不同信道的接收机上常常无法欺骗分类器,从而支持广播攻击设计。
- 当结合联合信道信息设计时,广播扰动可以同时降低多个接收机的分类器性能。
- 基于随机平滑的训练提高了对抗扰动的鲁棒性,且认证防御框架在高斯增强下提供鲁棒性保证。
更好的研究,从现在开始
从阅读论文到最终审阅,大幅缩短您的研究时间。
无需绑定信用卡
本解读由 AI 生成,并经人工编辑审核。