Adversarial Machine Learning for Image-Based Radio Frequency Fingerprinting: Attacks and Defenses

Lorenzo Papangelo,Maurizio Pistilli,Savio Sciancalepore,Gabriele Oligeri,Giuseppe Piro,Gennaro Boggia
DOI: https://doi.org/10.1109/mcom.001.2300464
IF: 9.03
2024-01-01
IEEE Communications Magazine
Abstract:Image-based Radio Frequency Fingerprinting (RFF) is a promising variant of traditional RFF systems. As a distinctive feature, such systems convert Physical-layer signals into matrices resembling 2-D or 3-D images and consider the latter as the input for state-of-the-art image classifiers. Compared to traditional ones, image-based RFF systems have recently shown enhanced flexibility for device identification, as they can better mitigate channel conditions, devices movement, and power cycle. However, previous works have yet to investigate their performance when subject to Adversarial Machine Learning (AML) attacks using state-of-the-art techniques such as Generative Adversarial Networks and the Fast Gradient Sign Method. Similarly, there are no studies about their capability to integrate adversarial learning strategies for enhancing their robustness to such attacks. In this paper, we fill the gap by conducting an experimental analysis of the effectiveness of AML attacks and adversarial training techniques for image-based RFF systems. Using a state-of-theart image-based RFF system and actual measurements, we show that adversarial samples can effectively degrade classification performance. At the same time, training the image-based RFF system with adversarial samples increases the reliability and robustness of such methods at the cost of a lower classification accuracy.
telecommunications,engineering, electrical & electronic
What problem does this paper attempt to address?