UAP Attack for Radio Signal Modulation Classification Based on Deep Learning

Weiguo Shen,Jiangpeng Li,Chuntao Gu,Qi Xuan,Dongwei Xu,Xiaoniu Yang
DOI: https://doi.org/10.1109/icct59356.2023.10419687
2023-01-01
Abstract:Automatic Modulation Classification (AMC), which is based on deep learning, has been extensively implemented in wireless communication systems. Universal adversarial perturbation (UAP), which is a type of sample-agnostic adversarial attack, can add to all natural samples to change most of their predicted labels. In this paper, we aim to achieve universal adversarial attacks on AMC models, and thus we proposed a method based on AutoEncoder, a novel strategy that takes advantage of the feature extraction capability and dimensionality reduction of AutoEncoder to generate UAP. Firstly, we used white-box and black-box methods to generate universal adversarial perturbations. Secondly, we proved that small perturbations to the original input can significantly reduce the accuracy of the model. Moreover, once the UAP generated, the adversarial attack will no longer depend on their input and only a small number of samples are needed to generate a powerful UAP. This property eases the attack procedure for real-time applications. Finally, the UAP generated by our method can attack across models with similar structures, exhibiting strong transferability.
What problem does this paper attempt to address?