Skip to main content
QUICK REVIEW

[论文解读] Over-the-Air Adversarial Attacks on Deep Learning Based Modulation Classifier over Wireless Channels

Brian Kim, Yalin E. Sagduyu|arXiv (Cornell University)|Feb 5, 2020
Adversarial Robustness in Machine Learning参考文献 18被引用 8
一句话总结

本文提出了一种针对无线系统中基于深度学习的调制分类器的真实空中对抗攻击,考虑了瑞利衰落、路径损耗和阴影效应。结果表明,即使知识有限,对抗扰动也能显著降低分类准确率,证明了在真实无线信道条件下,基于DNN的调制分类器存在脆弱性。

ABSTRACT

We consider a wireless communication system that consists of a transmitter, a receiver, and an adversary. The transmitter transmits signals with different modulation types, while the receiver classifies its received signals to modulation types using a deep learning-based classifier. In the meantime, the adversary makes over-the-air transmissions that are received as superimposed with the transmitter's signals to fool the classifier at the receiver into making errors. While this evasion attack has received growing interest recently, the channel effects from the adversary to the receiver have been ignored so far such that the previous attack mechanisms cannot be applied under realistic channel effects. In this paper, we present how to launch a realistic evasion attack by considering channels from the adversary to the receiver. Our results show that modulation classification is vulnerable to an adversarial attack over a wireless channel that is modeled as Rayleigh fading with path loss and shadowing. We present various adversarial attacks with respect to availability of information about channel, transmitter input, and classifier architecture. First, we present two types of adversarial attacks, namely a targeted attack (with minimum power) and non-targeted attack that aims to change the classification to a target label or to any other label other than the true label, respectively. Both are white-box attacks that are transmitter input-specific and use channel information. Then we introduce an algorithm to generate adversarial attacks using limited channel information where the adversary only knows the channel distribution. Finally, we present a black-box universal adversarial perturbation (UAP) attack where the adversary has limited knowledge about both channel and transmitter input.

研究动机与目标

  • 研究在存在瑞利衰落和路径损耗的真实无线环境中,基于深度学习的调制分类器对对抗攻击的脆弱性。
  • 设计一种从攻击者到接收方均考虑信道影响的对抗攻击方法,而此前的研究忽略了这一点。
  • 在不同知识水平下评估攻击性能:白盒(完整信道和输入信息)、有限信道知识,以及黑盒(通用对抗扰动)。
  • 证明通用对抗扰动(UAPs)在不同信道和输入条件下具有良好的迁移能力。
  • 表明即使在信息有限的情况下,对抗攻击也能在实际无线环境中显著降低分类准确率。

提出的方法

  • 提出使用信道状态信息和发射端输入的定向与非定向白盒对抗攻击,以最小化扰动功率。
  • 引入最小接收功率投影(MRPP)方法,在功率约束下优化对抗扰动。
  • 提出一种仅使用信道分布知识(而非瞬时信道状态)生成对抗攻击的方法。
  • 设计一种黑盒通用对抗扰动(UAP)攻击,利用替代DNN生成扰动,而无需了解目标DNN或输入信息。
  • 采用线性搜索优化MMSE-based攻击公式中的正则化参数λ,以提升性能。
  • 使用VT-CNN2作为调制分类器,并在RML2016.10a数据集上进行训练,涵盖11种调制类型及不同信噪比(SNR)下的数据。

实验结果

研究问题

  • RQ1当考虑真实无线信道效应(如瑞利衰落、路径损耗和阴影)时,对抗攻击是否能有效降低基于深度学习的调制分类器的性能?
  • RQ2信道状态信息和发射端输入的可用性如何影响对抗攻击的成功率和功率效率?
  • RQ3通用对抗扰动(UAPs)在无线环境中对不同信道状态和输入信号的迁移能力有多大?
  • RQ4仅具备信道分布知识(而非完整信道状态)是否仍能实现有效的对抗攻击?其性能与完整知识相比如何?
  • RQ5在真实信道条件下,非定向攻击与定向攻击在成功率和计算复杂度方面有何比较?

主要发现

  • 先前假设仅存在加性白高斯噪声(AWGN)的白盒攻击在真实衰落信道中失效,因为信道效应会扭曲扰动并降低其影响。
  • 所提出的定向MRPP攻击优于信道逆技巧,通过优化接收端的接收功率,实现了更高的误分类率。
  • 非定向MRPP攻击优于定向攻击,因为其在扰动设计上具有更大的方向自由度,从而能更有效地引发误分类。
  • 在高PNR区域,使用40个预采集输入和完整信道知识的UAP性能甚至优于定向信道逆攻击,证明了UAP的强大能力。
  • 具有有限信道知识的UAP与黑盒UAP性能相近,表明对抗样本在不同信道和输入条件下具有极强的迁移性。
  • 分类器在对抗攻击下准确率显著下降——例如,图1中[10]的攻击(仅考虑AWGN)性能几乎与无攻击时相当,而本文提出的攻击在真实信道条件下实现了显著的性能下降。

更好的研究,从现在开始

从阅读论文到最终审阅,大幅缩短您的研究时间。

无需绑定信用卡

本解读由 AI 生成,并经人工编辑审核。