Adversarial Deep Learning for Indoor Localization With Channel State Information Tensors

Adversarial Deep Learning for Indoor Localization With Channel State Information Tensors
复制标题

DOI:
10.1109/jiot.2022.3155562
复制
发表时间:
2022-10
影响因子:
10.6
通讯作者:
Xiangyu Wang;Xuyu Wang;S. Mao;Jian Zhang;Senthilkumar C. G. Periaswamy;J. Patton
Xiangyu Wang;Xuyu Wang;S. Mao;Jian Zhang;Senthilkumar C. G. Periaswamy;J. Patton
中科院分区:
计算机科学1区
文献类型:
--
作者:
Xiangyu Wang;Xuyu Wang;S. Mao;Jian Zhang;Senthilkumar C. G. Periaswamy;J. Patton

文献摘要

被引文献

相似文献

基于指纹的室内定位技术在GPS无法定位的地区一直是研究的热点。神经网络的发展极大地促进了其在室内定位系统中的应用。然而,最近的研究表明,机器学习模型,包括最先进的神经网络,容易受到对抗性的例子,因此,基于神经网络的室内定位系统也受到对抗性攻击的威胁。为了研究对抗性攻击对室内定位系统的影响,并使此类系统能够抵御对抗性攻击,我们提出了AdvLoc,这是一种用于室内定位系统的对抗性深度学习。利用所提出的AdvLoc系统,在黑盒攻击和白盒攻击两种场景下,研究了六种对抗性攻击方法对室内定位的影响.此外,对抗性训练被用于所提出的AdvLoc系统的离线训练中,该系统有效地对抗一阶对抗性攻击。建议的AdvLoc系统实现与商品WiFi设备,并在两个代表性的室内环境中进行了广泛的实验评估。实验结果验证了所提出的系统对一阶对抗性攻击的鲁棒性在典型的室内环境。
Fingerprinting-based indoor localization has been a research focus for GPS denied areas. The development of neural networks has greatly promoted its application in indoor localization systems. However, recent studies showed that the machine learning models, including state-of-the-art neural networks, are vulnerable to adversarial examples, and thus, neural network-based indoor localization systems are also under the threat of adversarial attacks. To investigate the effect of adversarial attacks on indoor localization systems and to make such systems resilient to adversarial attacks, we propose AdvLoc, an adversarial deep learning for indoor localization system. With the proposed AdvLoc system, the effect of adversarial attacks on indoor localization is studied under six types of adversarial attack methods in both black-box attack and white-box attack scenarios. Furthermore, adversarial training is utilized in offline training of the proposed AdvLoc system, which is effective against first-order adversarial attacks. The proposed AdvLoc system is implemented with commodity WiFi devices and evaluated with extensive experiments in two representative indoor environments. The experimental results verify the robustness of the proposed system against first-order adversarial attacks in representative indoor environments.