Countermeasures Against Adversarial Examples in Radio Signal Classification

Lu Zhang,Sangarapillai Lambotharan,Gan Zheng,Basil AsSadhan,Fabio Roli
2024-07-09
Abstract:Deep learning algorithms have been shown to be powerful in many communication network design problems, including that in automatic modulation classification. However, they are vulnerable to carefully crafted attacks called adversarial examples. Hence, the reliance of wireless networks on deep learning algorithms poses a serious threat to the security and operation of wireless networks. In this letter, we propose for the first time a countermeasure against adversarial examples in modulation classification. Our countermeasure is based on a neural rejection technique, augmented by label smoothing and Gaussian noise injection, that allows to detect and reject adversarial examples with high accuracy. Our results demonstrate that the proposed countermeasure can protect deep-learning based modulation classification systems against adversarial examples.
Artificial Intelligence
What problem does this paper attempt to address?
The problem that this paper attempts to solve is that in radio signal classification, although deep - learning algorithms are powerful, they are vulnerable to adversarial examples. These adversarial examples mislead the classification results of deep - learning models by adding small and carefully designed perturbations to the original input. This vulnerability poses a serious threat to the security and operation of wireless networks. In particular, in automatic modulation classification (AMC), adversarial examples may cause legitimate receivers to receive the wrong modulation type, thus affecting the normal operation of the communication system. Specifically, the paper focuses on how to defend against the impact of adversarial examples on automatic modulation classification systems in military and civilian scenarios. In military scenarios, the opposing side may add small perturbations to the transmitted signal to prevent opponents from correctly identifying the modulation method they use; in civilian scenarios, malicious third parties may disrupt normal communication services by interfering with the signal. To this end, the paper proposes for the first time a defense measure based on neural rejection technology (Neural Rejection, NR), combined with label smoothing (Label Smoothing, LS) and gaussian noise injection (Gaussian Noise Augmentation, GNA) techniques to improve the accuracy of detecting and rejecting adversarial examples. Experimental results show that the proposed LS - GNA - enhanced NR system can effectively protect deep - learning - based modulation classification systems from adversarial - example attacks.