Robust Adversarial Attacks Against DNN-Based Wireless Communication Systems

被引:29
作者
Bahramali, Alireza [1 ]
Nasr, Milad [1 ]
Houmansadr, Amir [1 ]
Goeckel, Dennis [1 ]
Towsley, Don [1 ]
机构
[1] Univ Massachusetts, Amherst, MA 01003 USA
来源
CCS '21: PROCEEDINGS OF THE 2021 ACM SIGSAC CONFERENCE ON COMPUTER AND COMMUNICATIONS SECURITY | 2021年
关键词
Wireless Communication Systems; Adversarial Examples; Universal Perturbations; Deep Neural Networks; CHANNEL ESTIMATION; DEEP;
D O I
10.1145/3460120.3484777
中图分类号
TP [自动化技术、计算机技术];
学科分类号
0812 ;
摘要
There is significant enthusiasm for the employment of Deep Neural Networks (DNNs) for important tasks in major wireless communication systems: channel estimation and decoding in orthogonal frequency division multiplexing (OFDM) systems, end-to-end autoencoder system design, radio signal classification, and signal authentication. Unfortunately, DNNs can be susceptible to adversarial examples, potentially making such wireless systems fragile and vulnerable to attack. In this work, by designing robust adversarial examples that meet key criteria, we perform a comprehensive study of the threats facing DNN-based wireless systems. We model the problem of adversarial wireless perturbations as an optimization problem that incorporates domain constraints specific to different wireless systems. This allows us to generate wireless adversarial perturbations that can be applied to wireless signals on-the-fly (i.e., with no need to know the target signals a priori), are undetectable from natural wireless noise, and are robust against removal. We show that even in the presence of significant defense mechanisms deployed by the communicating parties, our attack performs significantly better compared to existing attacks against DNN-based wireless systems. In particular, the results demonstrate that even when employing well-considered defenses, DNN-based wireless communication systems are vulnerable to adversarial attacks and call into question the employment of DNNs for a number of tasks in robust wireless communication.
引用
收藏
页码:126 / 140
页数:15
相关论文
共 48 条
[41]  
Restuccia Francesco., 2020, P 2 ACM WORKSH WIR S
[42]   Physical Adversarial Attacks Against End-to-End Autoencoder Communication Systems [J].
Sadeghi, Meysam ;
Larsson, Erik G. .
IEEE COMMUNICATIONS LETTERS, 2019, 23 (05) :847-850
[43]   Adversarial Attacks on Deep-Learning Based Radio Signal Classification [J].
Sadeghi, Meysam ;
Larsson, Erik G. .
IEEE WIRELESS COMMUNICATIONS LETTERS, 2019, 8 (01) :213-216
[44]   Generative Adversarial Network in the Air: Deep Adversarial Learning for Wireless Signal Spoofing [J].
Shi, Yi ;
Davaslioglu, Kemal ;
Sagduyu, Yalin E. .
IEEE TRANSACTIONS ON COGNITIVE COMMUNICATIONS AND NETWORKING, 2021, 7 (01) :294-303
[45]  
Tram`er Florian, 2017, Ensemble adversarial training: Attacks and defenses
[46]  
Usama Muhammad, 2019, 2019 UK CHINA EMERGI
[47]   Power of Deep Learning for Channel Estimation and Signal Detection in OFDM Systems [J].
Ye, Hao ;
Li, Geoffrey Ye ;
Juang, Biing-Hwang .
IEEE WIRELESS COMMUNICATIONS LETTERS, 2018, 7 (01) :114-117
[48]  
Zhao Z., 2018, arXiv preprint arXiv: 1807. 05511