paper-with-me

Papers

Trojan Attacks on Wireless Signal Classification with Adversarial Machine Learning

2019-10-23 · Kemal Davaslioglu, Yalin E. Sagduyu

We present a Trojan (backdoor or trapdoor) attack that targets deep learning applications in wireless communications. A deep learning classifier is considered to classify wireless signals using raw (I/Q) samples as features and modulation types as labels. An adversary slightly manipulates training data by inserting Trojans (i.e., triggers) to only few training data samples by modifying their phases and changing the labels of these samples to a target label. This poisoned training data is used to train the deep learning classifier. In test (inference) time, an adversary transmits signals with the same phase shift that was added as a trigger during training. While the receiver can accurately classify clean (unpoisoned) signals without triggers, it cannot reliably classify signals poisoned with triggers. This stealth attack remains hidden until activated by poisoned inputs (Trojans) to bypass a signal classifier (e.g., for authentication). We show that this attack is successful over different channel conditions and cannot be mitigated by simply preprocessing the training and test data with random phase variations. To detect this attack, activation based outlier detection is considered with statistical as well as clustering techniques. We show that the latter one can detect Trojan attacks even if few samples are poisoned.

📄 PDF Abstract BibTeX arXiv:1910.10766

Code (0)

등록된 구현이 없습니다.

Tasks

BIG-bench Machine LearningClassificationClusteringDeep LearningGeneral ClassificationOutlier Detection

Methods 이 논문이 사용한 방법론

Test 설명 없음

Similar Papers 제목 키워드 기반

Task-Oriented Communications for NextG: End-to-End Deep Learning and AI Security Aspects

2022-12-19 · Yalin E. Sagduyu, Sennur Ulukus, Aylin Yener

Communications systems to date are primarily designed with the goal of reliable transfer of digital sequences (bits). Next generation (NextG) communication systems are beginning to explore shifting this design paradigm t…

Decoder

A Deep Ensemble-based Wireless Receiver Architecture for Mitigating Adversarial Attacks in Automatic Modulation Classification

2021-04-08 · Rajeev Sahay, Christopher G. Brinton, David J. Love

Deep learning-based automatic modulation classification (AMC) models are susceptible to adversarial attacks. Such attacks inject specifically crafted wireless interference into transmitted signals to induce erroneous cla…

ClassificationDeep LearningGeneral Classification

Don't Watch Me: A Spatio-Temporal Trojan Attack on Deep-Reinforcement-Learning-Augment Autonomous Driving

2022-11-22 · Yinbo Yu, Jiajia Liu

Deep reinforcement learning (DRL) is one of the most popular algorithms to realize an autonomous driving (AD) system. The key success factor of DRL is that it embraces the perception capability of deep neural networks wh…

Autonomous DrivingDecision MakingDeep Reinforcement Learningimage-classification+2

Towards Effective and Robust Neural Trojan Defenses via Input Filtering

2022-02-24 · Kien Do, Haripriya Harikumar, Hung Le, Dung Nguyen 외

Trojan attacks on deep neural networks are both dangerous and surreptitious. Over the past few years, Trojan attacks have advanced from using only a single input-agnostic trigger and targeting only one class to using mul…

Data Compressioninput filteringVariational Inference

Adversarial Attacks on Deep-Learning Based Radio Signal Classification

2018-08-23 · Meysam Sadeghi, Erik G. Larsson

Deep learning (DL), despite its enormous success in many computer vision and language processing applications, is exceedingly vulnerable to adversarial attacks. We consider the use of DL for radio signal (modulation) cla…

ClassificationDeep LearningGeneral Classification