Channel-Aware Adversarial Attacks Against Deep Learning-Based Wireless Signal Classifiers
arXiv:2005.05321
Abstract
This paper presents channel-aware adversarial attacks against deep learning-based wireless signal classifiers. There is a transmitter that transmits signals with different modulation types. A deep neural network is used at each receiver to classify its over-the-air received signals to modulation types. In the meantime, an adversary transmits an adversarial perturbation (subject to a power budget) to fool receivers into making errors in classifying signals that are received as superpositions of transmitted signals and adversarial perturbations. First, these evasion attacks are shown to fail when channels are not considered in designing adversarial perturbations. Then, realistic attacks are presented by considering channel effects from the adversary to each receiver. After showing that a channel-aware attack is selective (i.e., it affects only the receiver whose channel is considered in the perturbation design), a broadcast adversarial attack is presented by crafting a common adversarial perturbation to simultaneously fool classifiers at different receivers. The major vulnerability of modulation classifiers to over-the-air adversarial attacks is shown by accounting for different levels of information available about the channel, the transmitter input, and the classifier model. Finally, a certified defense based on randomized smoothing that augments training data with noise is introduced to make the modulation classifier robust to adversarial perturbations.
Submitted for publication. arXiv admin note: substantial text overlap with arXiv:2002.02400
References in corpus (8)
- Certified Adversarial Robustness via Randomized Smoothing
- On Evaluating Adversarial Robustness
- When Wireless Security Meets Machine Learning: Motivation, Challenges, and Research Directions
- Adversarial Examples in RF Deep Learning: Detection of the Attack and its Physical Robustness
- When Attackers Meet AI: Learning-empowered Attacks in Cooperative Spectrum Sensing
- Adversarial Attack on DL-based Massive MIMO CSI Feedback
- Adversarial Attacks on Deep Learning Based Power Allocation in a Massive MIMO Network
- Adversarial Attacks on Deep Learning Based mmWave Beam Prediction in 5G and Beyond
Cited by in corpus (13)
- The RFML Ecosystem: A Look at the Unique Challenges of Applying Deep Learning to Radio Frequency Applications
- Adversarial Machine Learning in Wireless Communications using RF Data: A Review
- When Attackers Meet AI: Learning-empowered Attacks in Cooperative Spectrum Sensing
- Adversarial Machine Learning for 5G Communications Security
- How to Make 5G Communications "Invisible": Adversarial Machine Learning for Wireless Privacy
- Generative Adversarial Network in the Air: Deep Adversarial Learning for Wireless Signal Spoofing
- Robust Adversarial Attacks Against DNN-Based Wireless Communication Systems
- Adversarial Attacks with Multiple Antennas Against Deep Learning-Based Modulation Classifiers
- Adversarial Attacks on Deep Learning Based mmWave Beam Prediction in 5G and Beyond
- Channel Effects on Surrogate Models of Adversarial Attacks against Wireless Signal Classifiers
- Adversarial Machine Learning based Partial-model Attack in IoT
- Adversarial Machine Learning for Flooding Attacks on 5G Radio Access Network Slicing
- Over-the-Air Membership Inference Attacks as Privacy Threats for Deep Learning-based Wireless Signal Classifiers