Adversarial Machine Learning and Defense Game for NextG Signal Classification with Deep Learning

被引:0
|
作者
Sagduyu, Yalin E. [1 ]
机构
[1] Natl Secur Inst, Virginia Tech, Arlington, VA USA
关键词
D O I
10.1109/MILCOM55135.2022.10017674
中图分类号
TP [自动化技术、计算机技术];
学科分类号
0812 ;
摘要
This paper presents a game-theoretic framework to study the interactions of attack and defense for deep learningbased NextG signal classification. NextG systems such as the one envisioned for a massive number of IoT devices can employ deep neural networks (DNNs) for various tasks such as user equipment identification, physical layer authentication, and detection of incumbent users (such as in the Citizens Broadband Radio Service (CBRS) band). By training another DNN as the surrogate model, an adversary can launch an inference (exploratory) attack to learn the behavior of the victim model, predict successful operation modes (e.g., channel access), and jam them. A defense mechanism can increase the adversary's uncertainty by introducing controlled errors in the victim model's decisions (i.e., poisoning the adversary's training data). This defense is effective against an attack but reduces the performance when there is no attack. The interactions between the defender and the adversary are formulated as a non-cooperative game, where the defender selects the probability of defending or the defense level itself (i.e., the ratio of falsified decisions) and the adversary selects the probability of attacking. The defender's objective is to maximize its reward (e.g., throughput or transmission success ratio), whereas the adversary's objective is to minimize this reward and its attack cost. The Nash equilibrium strategies are determined as operation modes such that no player can unilaterally improve its utility given the other's strategy is fixed. A fictitious play is formulated for each player to play the game repeatedly in response to the empirical frequency of the opponent's actions. The performance in Nash equilibrium is compared to the fixed attack and defense cases, and the resilience of NextG signal classification against attacks is quantified.
引用
下载
收藏
页数:6
相关论文
共 50 条
  • [1] Adversarial Machine Learning and Defense Game for NextG Signal Classification with Deep Learning
    Sagduyu, Yalin E.
    arXiv, 2022,
  • [2] Self-Supervised RF Signal Representation Learning for NextG Signal Classification With Deep Learning
    Davaslioglu, Kemal
    Boztas, Serdar
    Ertem, Mehmet Can
    Sagduyu, Yalin E.
    Ayanoglu, Ender
    IEEE WIRELESS COMMUNICATIONS LETTERS, 2023, 12 (01) : 65 - 69
  • [3] Machine Learning in NextG Networks via Generative Adversarial Networks
    Ayanoglu, Ender
    Davaslioglu, Kemal
    Sagduyu, Yalin E.
    IEEE TRANSACTIONS ON COGNITIVE COMMUNICATIONS AND NETWORKING, 2022, 8 (02) : 480 - 501
  • [4] Adversarial Deep Learning: A Survey on Adversarial Attacks and Defense Mechanisms on Image Classification
    Khamaiseh, Samer Y.
    Bagagem, Derek
    Al-Alaj, Abdullah
    Mancino, Mathew
    Alomari, Hakam W.
    IEEE ACCESS, 2022, 10 : 102266 - 102291
  • [5] Trojan Attacks on Wireless Signal Classification with Adversarial Machine Learning
    Davaslioglu, Kemal
    Sagduyu, Yalin E.
    2019 IEEE INTERNATIONAL SYMPOSIUM ON DYNAMIC SPECTRUM ACCESS NETWORKS (DYSPAN), 2019, : 515 - 520
  • [6] Adversarial Machine Learning for NextG Covert Communications Using Multiple Antennas
    Kim, Brian
    Sagduyu, Yalin
    Davaslioglu, Kemal
    Erpek, Tugba
    Ulukus, Sennur
    ENTROPY, 2022, 24 (08)
  • [7] Adversarial Attacks on Deep-Learning Based Radio Signal Classification
    Sadeghi, Meysam
    Larsson, Erik G.
    IEEE WIRELESS COMMUNICATIONS LETTERS, 2019, 8 (01) : 213 - 216
  • [8] A Survey on Adversarial Machine Learning for Cyberspace Defense
    Yu, Zheng-Fei
    Yan, Qiao
    Zhou, Yun
    Zidonghua Xuebao/Acta Automatica Sinica, 2022, 48 (07): : 1625 - 1649
  • [9] Defense strategies for Adversarial Machine Learning: A survey
    Bountakas, Panagiotis
    Zarras, Apostolis
    Lekidis, Alexios
    Xenakis, Christos
    COMPUTER SCIENCE REVIEW, 2023, 49
  • [10] Defense Against Adversarial Attacks in Deep Learning
    Li, Yuancheng
    Wang, Yimeng
    APPLIED SCIENCES-BASEL, 2019, 9 (01):