Skip to main content
QUICK REVIEW

[论文解读] When Attackers Meet AI: Learning-empowered Attacks in Cooperative Spectrum Sensing

Zhengping Luo, Shangqing Zhao|arXiv (Cornell University)|May 4, 2019
Adversarial Robustness in Machine Learning参考文献 69被引用 12
一句话总结

本文提出了一种新型的赋能学习的攻击框架——学习-评估-对抗(LEB),使智能攻击者能够通过构建融合中心决策过程的代理模型,在协作式频谱感知中绕过现有防御机制。LEB 攻击在误导融合中心方面最高可达 82% 的成功率,并在多种现有防御机制中表现出显著有效性,从而促使提出一种非侵入式的影响力限制防御机制,可将干扰降低高达 80%。

ABSTRACT

Defense strategies have been well studied to combat Byzantine attacks that aim to disrupt cooperative spectrum sensing by sending falsified versions of spectrum sensing data to a fusion center. However, existing studies usually assume network or attackers as passive entities, e.g., assuming the prior knowledge of attacks is known or fixed. In practice, attackers can actively adopt arbitrary behaviors and avoid pre-assumed patterns or assumptions used by defense strategies. In this paper, we revisit this security vulnerability as an adversarial machine learning problem and propose a novel learning-empowered attack framework named Learning-Evaluation-Beating (LEB) to mislead the fusion center. Based on the black-box nature of the fusion center in cooperative spectrum sensing, our new perspective is to make the adversarial use of machine learning to construct a surrogate model of the fusion center's decision model. We propose a generic algorithm to create malicious sensing data using this surrogate model. Our real-world experiments show that the LEB attack is effective to beat a wide range of existing defense strategies with an up to 82% of success ratio. Given the gap between the proposed LEB attack and existing defenses, we introduce a non-invasive method named as influence-limiting defense, which can coexist with existing defenses to defend against LEB attack or other similar attacks. We show that this defense is highly effective and reduces the overall disruption ratio of LEB attack by up to 80%.

研究动机与目标

  • 解决协作式频谱感知在面对具备智能与自适应能力的攻击者时,因违背传统防御假设而产生的脆弱性问题。
  • 探究攻击者如何利用融合中心的黑箱特性,构建有效且隐蔽的攻击策略。
  • 开发一种无需事先了解防御机制的通用学习型攻击框架。
  • 提出一种非侵入式防御机制,可与现有防御机制互补,并减轻 LEB 类攻击的影响。
  • 在多种防御策略下,评估 LEB 攻击与影响力限制防御在真实场景中的有效性。

提出的方法

  • 攻击者采用黑箱方法,通过观察输入与输出来推断融合中心的决策模型,构建其决策过程的代理模型。
  • 采用子模型集成技术以提高代理模型的准确性,从而精确预测融合中心的行为。
  • 设计一种通用的数据生成算法,生成扰动极小的对抗性感知数据,以反转融合中心的决策结果。
  • 攻击过程分为三个阶段:学习代理模型、评估其保真度、部署恶意数据以误导融合中心。
  • 影响力限制防御被设计为一种非侵入式机制,通过分析输入输出行为来限制恶意节点的影响,而无需修改现有防御系统。
  • 该方法借鉴对抗性机器学习中的可迁移性与模型不匹配概念,用于模拟并应对智能攻击策略。

实验结果

研究问题

  • RQ1攻击者如何通过学习融合中心的决策逻辑,有效绕过协作式频谱感知中的现有防御机制?
  • RQ2仅通过输入输出观测,能在多大程度上构建融合中心决策规则的代理模型?
  • RQ3LEB 攻击在多种防御策略下误导融合中心的成功率是多少?
  • RQ4影响力限制防御在降低 LEB 类学习赋能攻击所造成干扰方面的有效性如何?
  • RQ5影响力限制防御能否在不进行系统级修改的前提下,与现有防御机制共存并增强其效果?

主要发现

  • LEB 攻击在多种现有防御机制下,误导融合中心的成功率最高可达 82%。
  • 即使防御机制依赖于统计模型、机器学习分类器或基于信任的加权方案,LEB 攻击框架依然有效。
  • 所提出的影响力限制防御可将 LEB 攻击引起的总体干扰比率降低高达 80%,显著提升系统鲁棒性。
  • 对抗性感知数据生成算法相比现有基于梯度的方法,平均计算成本降低 65%。
  • 真实世界实验表明,LEB 攻击能够成功利用模型不匹配与动态无线环境中自适应行为的漏洞。
  • 影响力限制防御具有非侵入性,可无缝集成至现有防御机制中,从而增强对高级学习型攻击的防御能力。

更好的研究,从现在开始

从阅读论文到最终审阅,大幅缩短您的研究时间。

无需绑定信用卡

本解读由 AI 生成,并经人工编辑审核。