Adversarial Examples Detection of Electromagnetic Signal Based on GAN

Jiawei Zhu,Jiangpeng Li,Dongwei Xu,Chuntao Gu,Qi Xuan,Shunling Wang
DOI: https://doi.org/10.1109/bigcom57025.2022.00013
2022-01-01
Abstract:In the field of signal modulation classification, deep neural networks (DNNs) perform very well and have good generalization ability. However, the DNN model is extremely vulnerable. The model gives a false output with high confidence from an input example, which formed only by deliberately adding tiny disturbances. Such elaborate examples that make the model misclassify are called adversarial examples. In this paper, for the detection of adversarial examples in electromagnetic signals, we propose a method based on generative adversarial networks (GANs), a novel strategy to defend deep neural networks against such attacks. First of all, by experiment we came to the conclusion that the confidence of the DNN model for normal examples is stable, and the confidence for adversarial examples is unstable. We trained a classifier that performs well in extracting electromagnetic signal features. Then, We feed the normal examples to the generative adversarial network, the generator generates examples with similar data distribution to the clean examples. We send such pairs of examples to the classifier to calculate a threshold T, and the same operations will be performed on the test examples. Finally, the absolute error E of each pair of test examples will be calculated and compared with the threshold T to achieve electromagnetic signal adversarial examples detection. We define the method in the paper as Detect-GAN. The experimental results show that Detect-GAN can effectively defend against common and powerful attack algorithm. Comparing with other detection methods, Detect-GAN achieves more competitive performance.
What problem does this paper attempt to address?