White-Box Adversarial Attacks on Deep Learning-Based Radio Frequency Fingerprint Identification

White-Box Adversarial Attacks on Deep Learning-Based Radio Frequency Fingerprint Identification
复制标题

DOI:
10.1109/icc45041.2023.10278927
复制
发表时间:
2023-05
期刊:
ICC 2023 - IEEE International Conference on Communications
影响因子:
--
通讯作者:
Jie Ma;Junqing Zhang;Guanxiong Shen;A. Marshall;Chip-Hong Chang
Jie Ma;Junqing Zhang;Guanxiong Shen;A. Marshall;Chip-Hong Chang
中科院分区:
其他
文献类型:
--
作者:
Jie Ma;Junqing Zhang;Guanxiong Shen;A. Marshall;Chip-Hong Chang

文献摘要

相似文献

射频指纹识别(RFFI)是一种新兴的无线物联网(IoT)设备轻量级认证技术。RFFI利用独特的硬件缺陷作为设备标识符,深度学习作为RFFI的特征提取器和分类器被广泛部署。然而,深度学习容易受到对抗性攻击,对抗性示例是通过在干净数据中添加扰动来生成的,从而导致分类器做出错误的预测。基于深度学习的RFFI已被证明容易受到此类攻击,然而,目前还没有针对各种RFFI分类器的有效对抗性攻击的探索。本文报告了使用快速梯度符号法(FGSM)和投影梯度下降法(PGD)两种方法对白盒攻击(非目标攻击和目标攻击)的研究。搭建了LoRa测试平台,并采集了实际数据集。这些对抗性示例已被实验证明对卷积神经网络(cnn)、长短期记忆(LSTM)网络和门控循环单元(GRU)有效。
Radio frequency fingerprint identification (RFFI) is an emerging technique for the lightweight authentication of wireless Internet of things (IoT) devices. RFFI exploits unique hardware impairments as device identifiers, and deep learning is widely deployed as the feature extractor and classifier for RFFI. However, deep learning is vulnerable to adversarial attacks, where adversarial examples are generated by adding perturbation to clean data for causing the classifier to make wrong predictions. Deep learning-based RFFI has been shown to be vulnerable to such attacks, however, there is currently no exploration of effective adversarial attacks against a diversity of RFFI classifiers. In this paper, we report on investigations into white-box attacks (non-targeted and targeted) using two approaches, namely the fast gradient sign method (FGSM) and projected gradient descent (PGD). A LoRa testbed was built and real datasets were collected. These adversarial examples have been experimentally demonstrated to be effective against convolutional neural networks (CNNs), long short-term memory (LSTM) networks, and gated recurrent units (GRU).