Implementation of Real-Time Adversarial Attacks on DNN-based Modulation Classifier

被引:1
|
作者
Shtaiwi, Eyad [1 ]
Hussein, Ahmed Refaey [2 ]
Khawar, Awais [3 ]
Alkhateeb, Ahmed [4 ]
Abdelhadi, Ahmed [5 ]
Han, Zhu [1 ]
机构
[1] Univ Houston, Elect & Comp Engn Dept, Houston, TX 77204 USA
[2] Univ Guelph, Sch Engn, Guelph, ON, Canada
[3] Federated Wireless, Arlington, VA USA
[4] Arizona State Univ, Sch Elect Comp & Energy Engn, Tempe, AZ USA
[5] Univ Houston, Dept Engn Technol, Houston, TX USA
关键词
Modulation classifications; DNN-based classifier; FSGM; USRPs; SDR;
D O I
10.1109/ICNC57223.2023.10074421
中图分类号
TP3 [计算技术、计算机技术];
学科分类号
0812 ;
摘要
In this paper, we provide a hardware implementation for over-the-air (OTA) adversarial attack on a deep neural network (DNN)-based modulation classifiers. Although Automatic modulation classification (AMC) using the DNN-based method outperforms the traditional classification, it has been proven that the machine learning (ML) approaches lack robustness against adversarial attacks. Therefore, the adversarial attacks cause the loss of accuracy for the DNN-based AMC by injecting a well-designed perturbation to the wireless channels. The case study presented evaluates the adversarial attack performance and its effects on the accuracy of the DNN-classifier OTA using a universal software radio peripheral (USRP) B210. Firstly, we develop an intelligent AMC system using USRPs to classify four digitally modulated signals, namely, BPSK, QPSK, 8PSK, and 16QAM, in real-time. We consider a wireless communication system that consists of three software-defined radios (SDRs), namely, transmitter, receiver, and adversarial attack. While the Rx classifies the received signal, using a DNN-based classifier, the adversarial attack node intends to misclassify the DNN-based classifier by perturbing the input data of with an adversarial example. The developed adversarial node implements the Fast-Gradient Sign method (FGSM) to generate the needed perturbation. The results of the conducted experiment show that the DNN-based classifier achieves 97% accuracy in the absence of an adversarial node. However, after deploying the adversarial attack the classifier accuracy drops to 42%.
引用
收藏
页码:288 / 292
页数:5
相关论文
共 50 条
  • [31] A DNN-based data-driven modeling employing coarse sample data for real-time flexible multibody dynamics simulations
    Han, Seongji
    Choi, Hee-Sun
    Choi, Juhwan
    Choi, Jin Hwan
    Kim, Jin-Gyun
    [J]. COMPUTER METHODS IN APPLIED MECHANICS AND ENGINEERING, 2021, 373
  • [32] Transferable Adversarial Attacks against Automatic Modulation Classifier in Wireless Communications
    Hu, Lin
    Jiang, Han
    Li, Wen
    Han, Hao
    Yang, Yang
    Jiao, Yutao
    Wang, Haichao
    Xu, Yuhua
    [J]. WIRELESS COMMUNICATIONS & MOBILE COMPUTING, 2022, 2022
  • [33] DNN-Based Decoder for Four-Dimensional Modulation Superposition NOMA
    Li, Meng
    Zou, Jun
    Sun, Jiyuan
    [J]. 2020 IEEE 3RD INTERNATIONAL CONFERENCE ON INFORMATION COMMUNICATION AND SIGNAL PROCESSING (ICICSP 2020), 2020, : 454 - 459
  • [34] ReFace: Adversarial Transformation Networks for Real-time Attacks on Face Recognition Systems
    Hussain, Shehzeen
    Huster, Todd
    Mesterharm, Chris
    Neekhara, Paarth
    Koushanfar, Farinaz
    [J]. 2023 53RD ANNUAL IEEE/IFIP INTERNATIONAL CONFERENCE ON DEPENDABLE SYSTEMS AND NETWORKS, DSN, 2023, : 302 - 312
  • [35] REAL-TIME, UNIVERSAL, AND ROBUST ADVERSARIAL ATTACKS AGAINST SPEAKER RECOGNITION SYSTEMS
    Xie, Yi
    Shi, Cong
    Lie, Zhuohang
    Liu, Jian
    Chen, Yingying
    Yuan, Bo
    [J]. 2020 IEEE INTERNATIONAL CONFERENCE ON ACOUSTICS, SPEECH, AND SIGNAL PROCESSING, 2020, : 1738 - 1742
  • [36] AT-BOD: An Adversarial Attack on Fool DNN-Based Blackbox Object Detection Models
    Elaalami, Ilham A.
    Olatunji, Sunday O.
    Zagrouba, Rachid M.
    [J]. APPLIED SCIENCES-BASEL, 2022, 12 (04):
  • [37] Attacking DNN-based Cross-modal Retrieval Hashing Framework with Adversarial Perturbations
    Zhang, Xingwei
    Zheng, Xiaolong
    Mao, Wenji
    [J]. 2021 IEEE INTERNATIONAL CONFERENCE ON INTELLIGENCE AND SECURITY INFORMATICS (ISI), 2021, : 1 - 6
  • [38] Radon transform based real-time weed classifier
    Haq, Muhammad Inam ul
    Naeem, Abdul Muhamin
    Ahmad, Irshad
    Islam, Muhammad
    [J]. COMPUTER GRAPHICS, IMAGING AND VISUALISATION: NEW ADVANCES, 2007, : 245 - +
  • [39] REAL TIME FPGA IMPLEMENTATION OF AN AUTOMATIC MODULATION CLASSIFIER FOR ELECTRONIC WARFARE APPLICATIONS
    Grajal, J.
    Yeste-Ojeda, O.
    Sanchez, M. A.
    Garrido, M.
    Lopez-Vallejo, M.
    [J]. 19TH EUROPEAN SIGNAL PROCESSING CONFERENCE (EUSIPCO-2011), 2011, : 1514 - 1518
  • [40] A Real-Time Neural Network based Color Classifier
    Penharbel, Eder Augusto
    Goncalves, Ben Hur
    Francelin Romero, Roseli Aparecida
    [J]. 2008 5TH LATIN AMERICAN ROBOTICS SYMPOSIUM (LARS 2008), 2008, : 35 - 39