Stealthy Backdoor Attack on RF Signal Classification

Stealthy Backdoor Attack on RF Signal Classification
复制标题

DOI:
10.1109/icccn58024.2023.10230152
复制
发表时间:
2023-07
期刊:
2023 32nd International Conference on Computer Communications and Networks (ICCCN)
影响因子:
--
通讯作者:
Tianming Zhao;Zijie Tang;Tian-Di Zhang;Huy Phan;Yan Wang;Cong Shi;Bo Yuan;Ying Chen
Tianming Zhao;Zijie Tang;Tian-Di Zhang;Huy Phan;Yan Wang;Cong Shi;Bo Yuan;Ying Chen
中科院分区:
其他
文献类型:
--
作者:
Tianming Zhao;Zijie Tang;Tian-Di Zhang;Huy Phan;Yan Wang;Cong Shi;Bo Yuan;Ying Chen

文献摘要

相似文献

近年来,深度学习已成为支持射频(RF)信号分类应用的关键技术之一。鉴于DL培训要求很高,采用外包培训对RF应用开发人员来说是一个实用的选择。然而,外包过程暴露了一个安全漏洞,使后门攻击。虽然后门攻击已经在计算机视觉领域进行了探索,但很少在RF领域进行探索。在这项工作中,我们提出了一种针对基于DL的RF信号分类的隐形后门攻击。为了实现这样的攻击,我们广泛地探讨了RF数据在不同应用中的特征,包括RF调制分类和基于RF指纹的设备识别。特别是,我们设计了一种基于训练的后门触发生成方法,该方法具有优化过程,不仅可以适应动态应用输入,而且对RF接收机来说是隐身的。在两个RF信号分类数据集上的广泛实验表明,我们的后门攻击的平均攻击成功率超过99.2%,而其对干净数据的分类准确率仍然很高(即,与清洁模型相比,下降小于0.6%)。此外,我们证明了我们的攻击可以绕过现有的防御策略,如神经清洗和STRIP。
Recently, deep learning (DL) has become one of the key technologies supporting radio frequency (RF) signal classification applications. Given the heavy DL training requirement, adopting outsourced training is a practical option for RF application developers. However, the outsourcing process exposes a security vulnerability that enables a backdoor attack. While backdoor attacks have been explored in the computer vision domain, it is rarely explored in the RF domain. In this work, we present a stealthy backdoor attack that targets DL-based RF signal classification. To realize such an attack, we extensively explore the characteristics of the RF data in different applications, which include RF modulation classification and RF fingerprint-based device identification. Particularly, we design a training-based backdoor trigger generation approach with an optimization procedure that not only accommodates dynamic application inputs but also is stealthy to RF receivers. Extensive experiments on two RF signal classification datasets show that the average attack success rate of our backdoor attack is over 99.2%, while its classification accuracy for the clean data remains high (i.e., less than a 0.6% drop compared to the clean model). Additionally, we demonstrate that our attack can bypass existing defense strategies, such as Neural Cleanse and STRIP.