IS-WARS: Intelligent and Stealthy Adversarial Attack to Wi-Fi-Based Human Activity Recognition Systems

IS-WARS: Intelligent and Stealthy Adversarial Attack to Wi-Fi-Based Human Activity Recognition Systems
复制标题

DOI:
10.1109/tdsc.2021.3110480
复制
发表时间:
2022-11
影响因子:
7.3
通讯作者:
Pei Huang;Xiaonan Zhang;Sihan Yu;Linke Guo
Pei Huang;Xiaonan Zhang;Sihan Yu;Linke Guo
中科院分区:
计算机科学2区
文献类型:
--
作者:
Pei Huang;Xiaonan Zhang;Sihan Yu;Linke Guo

文献摘要

相似文献

非侵入性人类活动识别已被设想为许多需要人类与计算系统之间交互的新兴应用程序的关键使能器。为了准确地识别不同的人类行为,普遍采用了无线信号,例如Wi-Fi信号,其信道状态信息(CSI)可以准确地反映人体的运动。不幸的是,几乎所有基于Wi-Fi的识别系统都假设有一个干净的无线环境,即任何干扰都不会影响所开发的算法,这显然在实践中是不可行的。更糟糕的是,对于使用Wi-Fi 2.4 GHz信号的系统,来自共存协议(如ZigBee、蓝牙和未经许可的LTE)的广泛存在的干扰很容易危及识别过程,对进一步提高准确性构成硬限制。因此,这项工作发现了一种针对基于Wi-Fi的人类活动识别系统的新的信号对抗性攻击,通过故意使用共存的协议信号注入干扰。受污染的Wi-Fi信号会扭曲CSI估计,最终输出错误的识别结果。与传统的干扰攻击不同,这种新的对抗性攻击在避免被流量分析检测方面具有智能性和隐蔽性。结合理论分析和大量的真实世界实验,我们已经证明,这种新识别的攻击可以轻松地危害许多现有的基于Wi-Fi的人类识别系统,同时仍然绕过现有的恶意信号检测方案。
The non-intrusive human activity recognition has been envisioned as a key enabler for many emerging applications requiring interactions between humans and computing systems. To accurately recognize different human behaviors, ubiquitous wireless signals are widely adopted, e.g., Wi-Fi signals, whose Channel State Information (CSI) can precisely reflect human movements. Unfortunately, nearly all Wi-Fi-based recognition systems assume a clean wireless environment, i.e., no interference will compromise the developed algorithms, which, apparently, is not feasible in practice. Even worse, for systems using Wi-Fi 2.4GHz signals, the widely existing interference from coexisting protocols, such as ZigBee, Bluetooth, and LTE-Unlicensed, can easily compromise the recognition process, posing a hard limit on further enhancing the accuracy. Therefore, this work uncovers a new signal adversarial attack against Wi-Fi-based human activity recognition systems, by intentionally injecting interference using coexisting protocol signals. The contaminated Wi-Fi signal will distort CSI estimation and finally output a false recognition result. Different from traditional jamming attacks, this new adversarial attack is intelligent and stealthy in terms of avoiding being detected from traffic analysis. Along with both theoretical analysis and extensive real-world experiments, we have shown this newly-identified attack can easily compromise many existing Wi-Fi-based human recognition systems while still bypassing existing schemes for malicious signal detection.