Countermeasures Against Adversarial Examples in Radio Signal Classification

被引:22
作者
Zhang, Lu [1 ]
Lambotharan, Sangarapillai [1 ]
Zheng, Gan [1 ]
AsSadhan, Basil [2 ]
Roli, Fabio [3 ]
机构
[1] Loughborough Univ, Wolfson Sch Mech Elect & Mfg Engn, Loughborough LE11 3TU, Leics, England
[2] King Saud Univ, Dept Comp Sci, Riyadh 11421, Saudi Arabia
[3] Univ Cagliari, Dept Elect & Elect Engn, I-09123 Cagliari, Italy
基金
英国工程与自然科学研究理事会;
关键词
Modulation; Perturbation methods; Receivers; Training; Smoothing methods; Radio transmitters; Noise measurement; Deep learning; adversarial examples; radio modulation classification; neural rejection; label smoothing;
D O I
10.1109/LWC.2021.3083099
中图分类号
TP [自动化技术、计算机技术];
学科分类号
0812 ;
摘要
Deep learning algorithms have been shown to be powerful in many communication network design problems, including that in automatic modulation classification. However, they are vulnerable to carefully crafted attacks called adversarial examples. Hence, the reliance of wireless networks on deep learning algorithms poses a serious threat to the security and operation of wireless networks. In this letter, we propose for the first time a countermeasure against adversarial examples in modulation classification. Our countermeasure is based on a neural rejection technique, augmented by label smoothing and Gaussian noise injection, that allows to detect and reject adversarial examples with high accuracy. Our results demonstrate that the proposed countermeasure can protect deep-learning based modulation classification systems against adversarial examples.
引用
收藏
页码:1830 / 1834
页数:5
相关论文
共 8 条
[1]   A Survey on Machine-Learning Techniques in Cognitive Radios [J].
Bkassiny, Mario ;
Li, Yang ;
Jayaweera, Sudharman K. .
IEEE COMMUNICATIONS SURVEYS AND TUTORIALS, 2013, 15 (03) :1136-1159
[2]  
Goodfellow I. J., 2014, 3 INT C LEARNING REP
[3]   Over-the-Air Deep Learning Based Radio Signal Classification [J].
O'Shea, Timothy James ;
Roy, Tamoghna ;
Clancy, T. Charles .
IEEE JOURNAL OF SELECTED TOPICS IN SIGNAL PROCESSING, 2018, 12 (01) :168-179
[4]   Adversarial Attacks on Deep-Learning Based Radio Signal Classification [J].
Sadeghi, Meysam ;
Larsson, Erik G. .
IEEE WIRELESS COMMUNICATIONS LETTERS, 2019, 8 (01) :213-216
[5]  
Scholl S., 2019, CLASSIFICATION RADIO
[6]  
Shafahi Ali, 2019, Label smoothing and logit squeezing: A replacement for adversarial training?
[7]   Deep neural rejection against adversarial examples [J].
Sotgiu, Angelo ;
Demontis, Ambra ;
Melis, Marco ;
Biggio, Battista ;
Fumera, Giorgio ;
Feng, Xiaoyi ;
Roli, Fabio .
EURASIP JOURNAL ON INFORMATION SECURITY, 2020, 2020 (01)
[8]   Hierarchical digital modulation classification using cumulants [J].
Swami, A ;
Sadler, BM .
IEEE TRANSACTIONS ON COMMUNICATIONS, 2000, 48 (03) :416-429