Defending Adversarial Attacks on Deep Learning-Based Power Allocation in Massive MIMO Using Denoising Autoencoders

Defending Adversarial Attacks on Deep Learning-Based Power Allocation in Massive MIMO Using Denoising Autoencoders
复制标题

DOI:
10.1109/tccn.2023.3261307
复制
发表时间:
2022-11
影响因子:
8.6
通讯作者:
R. Sahay;M. Zhang;D. Love;Christopher G. Brinton
R. Sahay;M. Zhang;D. Love;Christopher G. Brinton
中科院分区:
计算机科学2区
文献类型:
--
作者:
R. Sahay;M. Zhang;D. Love;Christopher G. Brinton

文献摘要

相似文献

最近的工作提倡使用深度学习在大规模MIMO(maMIMO)网络的下行链路中执行功率分配。然而,这种深度学习模型容易受到对抗性攻击。在maMIMO功率分配的上下文中,对抗性攻击是指在推理期间将细微扰动注入深度学习模型的输入(即,对抗扰动在模型已经被训练之后的部署期间被注入到输入中),其被特别地制作以迫使经训练的回归模型输出不可行的功率分配解。在这项工作中,我们开发了一种基于自动编码器的缓解技术,该技术允许基于深度学习的功率分配模型在存在对手的情况下运行,而无需重新训练。具体来说,我们开发了一个去噪自动编码器(DAE),它学习潜在扰动数据与其相应的未扰动输入之间的映射。我们在多种攻击和多种威胁模型中测试了我们的防御,并证明了它的能力:(i)使用两种常见的预编码方案减轻对抗性攻击对功率分配网络的影响,(ii)优于先前提出的减轻maMIMO网络上基于回归的对抗性攻击的基准,(iii)在没有攻击的情况下保持准确的性能,以及(iv)以低计算开销运行。代码可在https://github.com/Jess-jpg-txt/DAE_for_adv_attacks_in_MIMO上公开获取。
Recent work has advocated for the use of deep learning to perform power allocation in the downlink of massive MIMO (maMIMO) networks. Yet, such deep learning models are vulnerable to adversarial attacks. In the context of maMIMO power allocation, adversarial attacks refer to the injection of subtle perturbations into the deep learning model’s input, during inference (i.e., the adversarial perturbation is injected into inputs during deployment after the model has been trained) that are specifically crafted to force the trained regression model to output an infeasible power allocation solution. In this work, we develop an autoencoder-based mitigation technique, which allows deep learning-based power allocation models to operate in the presence of adversaries without requiring retraining. Specifically, we develop a denoising autoencoder (DAE), which learns a mapping between potentially perturbed data and its corresponding unperturbed input. We test our defense across multiple attacks and in multiple threat models and demonstrate its ability to (i) mitigate the effects of adversarial attacks on power allocation networks using two common precoding schemes, (ii) outperform previously proposed benchmarks for mitigating regression-based adversarial attacks on maMIMO networks, (iii) retain accurate performance in the absence of an attack, and (iv) operate with low computational overhead. Code is publicly available at https://github.com/Jess-jpg-txt/DAE_for_adv_attacks_in_MIMO.