Intelligent Jamming of Deep Neural Network Based Signal Classification for Shared Spectrum

Intelligent Jamming of Deep Neural Network Based Signal Classification for Shared Spectrum
复制标题

DOI:
10.1109/milcom52596.2021.9653072
复制
发表时间:
2021-11
期刊:
MILCOM 2021 - 2021 IEEE Military Communications Conference (MILCOM)
影响因子:
--
通讯作者:
Wenhan Zhang;M. Krunz;G. Ditzler
Wenhan Zhang;M. Krunz;G. Ditzler
中科院分区:
其他
文献类型:
--
作者:
Wenhan Zhang;M. Krunz;G. Ditzler

文献摘要

被引文献

相似文献

深度神经网络(DNN)最近已被应用于射频(RF)信号的分类。感兴趣的一个用例涉及共享频谱的不同无线技术之间的识别。虽然已经提出了高度准确的DNN分类器,但初步研究表明这些分类器容易受到对抗性机器学习(AML)攻击。在一次这样的攻击中,攻击者训练代理DNN模型,以产生智能制作的低功耗“扰动”,降低合法分类器的分类准确性。在本文中,我们设计了四个基于DNN的分类器,用于识别5 GHz UNII频段上的Wi-Fi,5G NR-未授权(NR-U)和LTE LAA传输。我们的DNN模型包括卷积神经网络(CNN)和几个递归神经网络(RNN)模型,特别是LSTM和双向LSTM(BiLSTM)网络。我们证明了这些模型在“良性”(非对抗性)噪声下的高分类精度。然后,我们研究这些分类器的疗效AML为基础的扰动。具体来说,我们使用快速梯度符号方法(FGSM)来生成对抗扰动。不同的攻击场景进行了研究,这取决于攻击者有多少信息的防御者的分类器。在一个极端的情况下,称为“白盒”攻击,攻击者完全了解防御者的DNN,包括其超参数,其训练数据集,甚至用于训练网络的种子。即使当基于FGSM的扰动是低功率时,这种攻击也会显着降低分类精度,即,接收的SNR相对较高。然后,我们考虑更现实的攻击场景,其中攻击者有部分或没有知识的防御者的分类。即使在有限的知识下,相对于具有相同SNR水平的AWGN下的分类,对抗性扰动仍然可以导致分类准确度的显著降低。
Deep neural networks (DNNs) have recently been applied in the classification of radio frequency (RF) signals. One use case of interest relates to the discernment between different wireless technologies that share the spectrum. Although highly accurate DNN classifiers have been proposed, preliminary research points to the vulnerability of these classifiers to adversarial machine learning (AML) attacks. In one such attack, a surrogate DNN model is trained by the attacker to produce intelligently crafted low-power “perturbations” that degrade the classification accuracy of the legitimate classifier. In this paper, we design four DNN-based classifiers for the identification of Wi-Fi, 5G NR-Unlicensed (NR-U), and LTE LAA transmissions over the 5 GHz UNII bands. Our DNN models include both convolutional neural networks (CNNs) as well as several recurrent neural networks (RNNs) models, particularly LSTM and Bidirectional LSTM (BiLSTM) networks. We demonstrate the high classification accuracy of these models under “benign” (non-adversarial) noise. We then study the efficacy of these classifiers under AML-based perturbations. Specifically, we use the fast gradient sign method (FGSM) to generate adversarial perturbations. Different attack scenarios are studied, depending on how much information the attacker has about the defender's classifier. In one extreme scenario, called “white-box” attack, the attacker has full knowledge of the defender's DNN, including its hyperparameters, its training dataset, and even the seeds used to train the network. This attack is shown to significantly degrade the classification accuracy even when the FGSM-based perturbations are low power, i.e., the received SNR is relatively high. We then consider more realistic attack scenarios, where the attacker has partial or no knowledge of the defender's classifier. Even under limited knowledge, adversarial perturbations can still lead to significant reduction in the classification accuracy, relative to classification under AWGN with the same SNR level.