Undermining Deep Learning Based Channel Estimation via Adversarial Wireless Signal Fabrication

Undermining Deep Learning Based Channel Estimation via Adversarial Wireless Signal Fabrication
复制标题

DOI:
10.1145/3522783.3529525
复制
发表时间:
2022-05
期刊:
Proceedings of the 2022 ACM Workshop on Wireless Security and Machine Learning
影响因子:
--
通讯作者:
Tao Hou;Tao Wang;Zhuo Lu;Yao-Hong Liu;Y. Sagduyu
Tao Hou;Tao Wang;Zhuo Lu;Yao-Hong Liu;Y. Sagduyu
中科院分区:
其他
文献类型:
--
作者:
Tao Hou;Tao Wang;Zhuo Lu;Yao-Hong Liu;Y. Sagduyu

文献摘要

相似文献

信道估计是无线通信中的关键步骤。估计器识别信号传播期间的无线信道失真,并且该信息进一步用于数据预编码和解码。最近的研究表明,深度学习技术可以提高传统信道估计算法的准确性。然而,这些深度学习算法的可靠性和安全性尚未在无线通信背景下得到很好的研究。无一例外,基于深度学习的信道估计可能容易受到对抗性机器学习攻击。然而,仔细检查表明,我们不能简单地采用传统的对抗性学习机制来有效地操纵信道估计。在本文中,我们提出了一种新颖的攻击策略,该策略通过制作扰动来用错误的信道估计结果来欺骗接收器。这种攻击是在不知道当前输入信号的情况下发起的,并且只需要松散形式的时间同步。通过在我们的多用户 MIMO 测试台中使用软件定义无线电进行的无线实验,我们表明所提出的策略可以有效降低基于深度学习的信道估计的性能。我们还证明,所提出的攻击很难被检测到,检测率为 8% 或更低。
Channel estimation is a crucial step in wireless communications. The estimator identifies the wireless channel distortions during the signal propagation and this information is further used for data precoding and decoding. Recent studies have shown that deep learning techniques can enhance the accuracy of conventional channel estimation algorithms. However, the reliability and security aspects of these deep learning algorithms have not yet been well investigated in the context of wireless communications. With no exceptions, channel estimation based on deep learning may be vulnerable to the adversarial machine learning attacks. However, close examination shows that we cannot simply adapt the traditional adversarial learning mechanisms to effectively manipulate channel estimation. In this paper, we propose a novel attack strategy that crafts a perturbation to fool the receiver with wrong channel estimation results. This attack is launched without knowing the current input signals and by only requiring a loose form of time synchronization. Through the over-the-air experiments with software-defined radios in our multi-user MIMO testbed, we show that the proposed strategy can effectively reduce the performance of deep learning-based channel estimation. We also demonstrate that the proposed attack can hardly be detected with the detection rate of 8% or lower.