Physical Adversarial Attacks Against End-to-End Autoencoder Communication Systems

被引:107
作者
Sadeghi, Meysam [1 ]
Larsson, Erik G. [1 ]
机构
[1] Linkoping Univ, Dept Elect Engn ISY, S-58183 Linkoping, Sweden
关键词
Adversarial attacks; autoencoder systems; deep learning; wireless security; end-to-end learning;
D O I
10.1109/LCOMM.2019.2901469
中图分类号
TN [电子技术、通信技术];
学科分类号
0809 ;
摘要
We show that end-to-end learning of communication systems through deep neural network autoencoders can be extremely vulnerable to physical adversarial attacks. Specifically, we elaborate how an attacker can craft effective physical black-box adversarial attacks. Due to the openness (broadcast nature) of the wireless channel, an adversary transmitter can increase the block-error-rate of a communication system by orders of magnitude by transmitting a well-designed perturbation signal over the channel. We reveal that the adversarial attacks are more destructive than the jamming attacks. We also show that classical coding schemes are more robust than the autoencoders against both adversarial and jamming attacks.
引用
收藏
页码:847 / 850
页数:4
相关论文
共 9 条
[1]  
[Anonymous], 2016, ADVERSARIAL EXAMPLES
[2]  
Goodfellow I., 2016, TRANSFERABILITY MACH
[3]  
Goodfellow I J, 2015, P INT C LEARN REPR I
[4]  
Goodfellow I, 2016, ADAPT COMPUT MACH LE, P1
[5]   Anti-Jamming Communications Using Spectrum Waterfall: A Deep Reinforcement Learning Approach [J].
Liu, Xin ;
Xu, Yuhua ;
Jia, Luliang ;
Wu, Qihui ;
Anpalagan, Alagan .
IEEE COMMUNICATIONS LETTERS, 2018, 22 (05) :998-1001
[6]   Universal adversarial perturbations [J].
Moosavi-Dezfooli, Seyed-Mohsen ;
Fawzi, Alhussein ;
Fawzi, Omar ;
Frossard, Pascal .
30TH IEEE CONFERENCE ON COMPUTER VISION AND PATTERN RECOGNITION (CVPR 2017), 2017, :86-94
[7]   An Introduction to Deep Learning for the Physical Layer [J].
O'Shea, Timothy ;
Hoydis, Jakob .
IEEE TRANSACTIONS ON COGNITIVE COMMUNICATIONS AND NETWORKING, 2017, 3 (04) :563-575
[8]   Adversarial Attacks on Deep-Learning Based Radio Signal Classification [J].
Sadeghi, Meysam ;
Larsson, Erik G. .
IEEE WIRELESS COMMUNICATIONS LETTERS, 2019, 8 (01) :213-216
[9]  
Szegedy C., 2014, PROC 2 INT C LEARN R, P1