When Attackers Meet AI: Learning-Empowered Attacks in Cooperative Spectrum Sensing

When Attackers Meet AI: Learning-Empowered Attacks in Cooperative Spectrum Sensing
复制标题

DOI:
10.1109/tmc.2020.3030061
复制
发表时间:
2022-05-01
影响因子:
7.9
通讯作者:
Sagduyu, Yalin E.
Sagduyu, Yalin E.
中科院分区:
计算机科学2区
文献类型:
--
作者:
Luo, Zhengping;Zhao, Shangqing;Sagduyu, Yalin E.

文献摘要

被引文献

相似文献

对国防策略进行了充分的研究,以对抗拜占庭式攻击,旨在通过将伪造版本的频谱传感数据发送到融合中心来破坏合作频谱感测。但是,现有研究通常假设网络或攻击者为被动实体,例如,假设攻击的先验知识是已知或固定的。实际上,攻击者可以积极采用任意行为,并避免国防策略使用的预先提出的模式或假设。在本文中,我们将这种安全漏洞重新审视是一种对抗机器学习问题,并提出了一个新颖的学习授权攻击框架,名为Learning-beatuation-Beating(LEB),以误导融合中心。基于合作频谱感知中融合中心的黑盒性质,我们的新观点是使对机器学习的对抗性使用构建融合中心决策模型的替代模型。我们提出了一种通用算法,以使用此替代模型创建恶意传感数据。我们的现实实验表明,LEB攻击有效地击败了多种现有的防御策略,最多占成功率的82%。考虑到拟议的LEB攻击与现有防御措施之间的差距,我们引入了一种非侵入性方法,称为“影响力限制防御”,该方法可以与现有的防御措施共存,以防止LEB攻击或其他类似的攻击。我们表明,这种防御是非常有效的,并将LEB攻击的总体干扰比降低了80%。
Defense strategies have been well studied to combat Byzantine attacks that aim to disrupt cooperative spectrum sensing by sending falsified versions of spectrum sensing data to a fusion center. However, existing studies usually assume network or attackers as passive entities, e.g., assuming the prior knowledge of attacks is known or fixed. In practice, attackers can actively adopt arbitrary behaviors and avoid pre-assumed patterns or assumptions used by defense strategies. In this paper, we revisit this security vulnerability as an adversarial machine learning problem and propose a novel learning-empowered attack framework named Learning-Evaluation-Beating (LEB) to mislead the fusion center. Based on the black-box nature of the fusion center in cooperative spectrum sensing, our new perspective is to make the adversarial use of machine learning to construct a surrogate model of the fusion center's decision model. We propose a generic algorithm to create malicious sensing data using this surrogate model. Our real-world experiments show that the LEB attack is effective to beat a wide range of existing defense strategies with an up to 82 percent of success ratio. Given the gap between the proposed LEB attack and existing defenses, we introduce a non-invasive method named as influence-limiting defense, which can coexist with existing defenses to defend against LEB attack or other similar attacks. We show that this defense is highly effective and reduces the overall disruption ratio of LEB attack by up to 80 percent.