Implementation of Real-Time Adversarial Attacks on DNN-based Modulation Classifier

被引:1
|
作者
Shtaiwi, Eyad [1 ]
Hussein, Ahmed Refaey [2 ]
Khawar, Awais [3 ]
Alkhateeb, Ahmed [4 ]
Abdelhadi, Ahmed [5 ]
Han, Zhu [1 ]
机构
[1] Univ Houston, Elect & Comp Engn Dept, Houston, TX 77204 USA
[2] Univ Guelph, Sch Engn, Guelph, ON, Canada
[3] Federated Wireless, Arlington, VA USA
[4] Arizona State Univ, Sch Elect Comp & Energy Engn, Tempe, AZ USA
[5] Univ Houston, Dept Engn Technol, Houston, TX USA
关键词
Modulation classifications; DNN-based classifier; FSGM; USRPs; SDR;
D O I
10.1109/ICNC57223.2023.10074421
中图分类号
TP3 [计算技术、计算机技术];
学科分类号
0812 ;
摘要
In this paper, we provide a hardware implementation for over-the-air (OTA) adversarial attack on a deep neural network (DNN)-based modulation classifiers. Although Automatic modulation classification (AMC) using the DNN-based method outperforms the traditional classification, it has been proven that the machine learning (ML) approaches lack robustness against adversarial attacks. Therefore, the adversarial attacks cause the loss of accuracy for the DNN-based AMC by injecting a well-designed perturbation to the wireless channels. The case study presented evaluates the adversarial attack performance and its effects on the accuracy of the DNN-classifier OTA using a universal software radio peripheral (USRP) B210. Firstly, we develop an intelligent AMC system using USRPs to classify four digitally modulated signals, namely, BPSK, QPSK, 8PSK, and 16QAM, in real-time. We consider a wireless communication system that consists of three software-defined radios (SDRs), namely, transmitter, receiver, and adversarial attack. While the Rx classifies the received signal, using a DNN-based classifier, the adversarial attack node intends to misclassify the DNN-based classifier by perturbing the input data of with an adversarial example. The developed adversarial node implements the Fast-Gradient Sign method (FGSM) to generate the needed perturbation. The results of the conducted experiment show that the DNN-based classifier achieves 97% accuracy in the absence of an adversarial node. However, after deploying the adversarial attack the classifier accuracy drops to 42%.
引用
收藏
页码:288 / 292
页数:5
相关论文
共 50 条
  • [1] Threats of Adversarial Attacks in DNN-Based Modulation Recognition
    Lin, Yun
    Zhao, Haojun
    Tu, Ya
    Mao, Shiwen
    Dou, Zheng
    [J]. IEEE INFOCOM 2020 - IEEE CONFERENCE ON COMPUTER COMMUNICATIONS, 2020, : 2469 - 2478
  • [2] Evaluating and Improving Adversarial Attacks on DNN-Based Modulation Recognition
    Zhao, Haojun
    Lin, Yun
    Gao, Song
    Yu, Shui
    [J]. 2020 IEEE GLOBAL COMMUNICATIONS CONFERENCE (GLOBECOM), 2020,
  • [3] Resisting DNN-Based Website Fingerprinting Attacks Enhanced by Adversarial Training
    Qiao, Litao
    Wu, Bang
    Yin, Shuijun
    Li, Heng
    Yuan, Wei
    Luo, Xiapu
    [J]. IEEE TRANSACTIONS ON INFORMATION FORENSICS AND SECURITY, 2023, 18 : 5375 - 5386
  • [4] Waveform Manipulation Against DNN-based Modulation Classification Attacks
    Varkatzas, Dimitrios
    Argyriou, Antonios
    [J]. MILCOM 2023 - 2023 IEEE MILITARY COMMUNICATIONS CONFERENCE, 2023,
  • [5] Robust Adversarial Attacks Against DNN-Based Wireless Communication Systems
    Bahramali, Alireza
    Nasr, Milad
    Houmansadr, Amir
    Goeckel, Dennis
    Towsley, Don
    [J]. CCS '21: PROCEEDINGS OF THE 2021 ACM SIGSAC CONFERENCE ON COMPUTER AND COMMUNICATIONS SECURITY, 2021, : 126 - 140
  • [6] DNN-based Direction Finding by Time Modulation
    Kim, Donghyun
    Kim, Sung Hoe
    Cha, Seung Gook
    Yoon, Young Joong
    Jang, Byung-Jun
    [J]. 2020 IEEE INTERNATIONAL SYMPOSIUM ON ANTENNAS AND PROPAGATION AND NORTH AMERICAN RADIO SCIENCE MEETING, 2020, : 439 - 440
  • [7] Real-Time Adversarial Attacks
    Gong, Yuan
    Li, Boyang
    Poellabauer, Christian
    Shi, Yiyu
    [J]. PROCEEDINGS OF THE TWENTY-EIGHTH INTERNATIONAL JOINT CONFERENCE ON ARTIFICIAL INTELLIGENCE, 2019, : 4672 - 4680
  • [8] A DNN-based Metamodeling Techniques for Real-Time Simulations of Flexible Multibody System Dynamics
    Han, Seongji
    Choi, Hee-Sun
    Choi, Juhwan
    Choi, Jin Hwan
    Kim, Jin-Gyun
    [J]. TRANSACTIONS OF THE KOREAN SOCIETY OF MECHANICAL ENGINEERS A, 2021, 45 (10) : 853 - 861
  • [9] A robust and real-time DNN-based multi-baseline stereo accelerator in FPGAs
    Zhang, Yu
    Zheng, Yi
    Ling, Yehua
    Meng, Haitao
    Chen, Gang
    [J]. JOURNAL OF SYSTEMS ARCHITECTURE, 2023, 143
  • [10] Research of real-time corn yield monitoring system with DNN-based prediction model
    Yin, Chaojie
    Zhang, Qi
    Mao, Xu
    Chen, Du
    Huang, Shengcao
    Li, Yutong
    [J]. FRONTIERS IN PLANT SCIENCE, 2024, 15