Deterrence of Adversarial Perturbations: Moving Target Defense for Automatic Modulation Classification in Wireless Communication Systems

Wei Dong,Zan Zhou,Xiping Li,Shujie Yang,Zhenhui Yuan,Changqiao Xu
DOI: https://doi.org/10.1109/icc51166.2024.10622631
2024-01-01
Abstract:Automatic modulation classification (AMC) plays an indispensable role in wireless communication systems. Deep learning-based AMC has become the mainstream solution due to its high accuracy and no need for manual feature engineering. However, every coin has two sides. DL-based AMC is susceptible to adversarial perturbations, which are carefully crafted to be superimposed on the transmitted signals in an iteratively try-and-error manner, resulting in incorrect classification. In this paper, we propose a model diversity-based moving target defense mechanism (MD-MTD), which employs multiple classifiers and switches periodically, preventing intelligent attackers from deducing universal adversarial perturbations (UAP). Besides, to jointly optimize the robustness and accuracy of different AMC models to be trained, we design a novel multi-agent reinforcement learning (MARL) module. It is worth mentioning that the proposed algorithm significantly mitigates the curse of dimensionality during the large-scale training process via integrating value-decomposition networks and illegal action masking, improving the feasibility of our solution in real-world wireless communication systems. Experimental results on the GNU radio dataset also exhibit the remarkable advantages of our method in terms of convergence and defense performance.
What problem does this paper attempt to address?