Journal Article10.1109/TR.2020.3032744
Adversarial Attacks in Modulation Recognition With Convolutional Neural Networks
200
TL;DR: The results indicate that the accuracy of the target model reduce significantly by adversarial attacks, when the perturbation factor is 0.001, and iterative methods show greater attack performances than that of one-step method.
read more
Abstract: Deep learning (DL) models are vulnerable to adversarial attacks, by adding a subtle perturbation which is imperceptible to the human eye, a convolutional neural network (CNN) can lead to erroneous results, which greatly reduces the reliability and security of the DL tasks. Considering the wide application of modulation recognition in the communication field and the rapid development of DL, by adding a well-designed adversarial perturbation to the input signal, this article explores the performance of attack methods on modulation recognition, measures the effectiveness of adversarial attacks on signals, and provides the empirical evaluation of the reliabilities of CNNs. The results indicate that the accuracy of the target model reduce significantly by adversarial attacks, when the perturbation factor is 0.001, the accuracy of the model could drop by about 50 ${\%}$ on average. Among them, iterative methods show greater attack performances than that of one-step method. In addition, the consistency of the waveform before and after the perturbation is examined, to consider whether the added adversarial examples are small enough (i.e., hard to distinguish by human eyes). This article also aims at inspiring researchers to further promote the CNNs reliabilities against adversarial attacks.
read more
Chat with Paper
AI Agents for this Paper
Find similar papers on Google Scholar, PubMed and Arxiv
Write a critical review of this paper
Analyze citations of this paper to find unaddressed research gaps
Citations
•Posted Content
Channel-Aware Adversarial Attacks Against Deep Learning-Based Wireless Signal Classifiers
TL;DR: Channel-aware adversarial attacks against deep learning-based wireless signal classifiers are presented and a certified defense based on randomized smoothing that augments training data with noise is introduced to make modulation classifier robust to adversarial perturbations.
91
Channel-Aware Adversarial Attacks Against Deep Learning-Based Wireless Signal Classifiers
TL;DR: In this article , channel-aware adversarial attacks against deep learning-based wireless signal classifiers are presented by considering channel effects from the adversary to each receiver, and a certified defense based on randomized smoothing that augments training data with noise is introduced to make the modulation classifier robust to adversarial perturbations.
•Posted Content
Adversarial Attacks on Deep-Learning Based Radio Signal Classification
Meysam Sadeghi,Erik G. Larsson +1 more
TL;DR: This work considers the use of DL for radio signal (modulation) classification tasks, and presents practical methods for the crafting of white-box and universal black-box adversarial attacks in that application.
63
A Reliable Sample Selection Strategy for Weakly Supervised Visual Tracking
01 Mar 2023
TL;DR: Zhang et al. as discussed by the authors proposed an optimal sample selection strategy and applied it to the visual tracking system, where the unreliable pseudolabels are replaced by reliable ground truth or discarded to overcome the degraded modeling problem by filtering low quality samples.
53
Adversarial Attacks and Defenses in Machine Learning-Empowered Communication Systems and Networks: A Contemporary Survey
Yulong Wang,Tong Sun,Shenghong Li,Xinnan Yuan,W. Ni,Ekram Hossain,H. Vincent Poor +6 more
TL;DR: A comprehensive classification of recent adversarial attack methods and state-of-the-art adversarial defense techniques based on attack principles are conducted, and they are presented in visually appealing tables and tree diagrams.
43
References
•Proceedings Article
ImageNet Classification with Deep Convolutional Neural Networks
Alex Krizhevsky,Ilya Sutskever,Geoffrey E. Hinton +2 more
- 03 Dec 2012
TL;DR: The state-of-the-art performance of CNNs was achieved by Deep Convolutional Neural Networks (DCNNs) as discussed by the authors, which consists of five convolutional layers, some of which are followed by max-pooling layers, and three fully-connected layers with a final 1000-way softmax.
Fully convolutional networks for semantic segmentation
Jonathan Long,Evan Shelhamer,Trevor Darrell +2 more
- 07 Jun 2015
TL;DR: The key insight is to build “fully convolutional” networks that take input of arbitrary size and produce correspondingly-sized output with efficient inference and learning.
•Posted Content
Explaining and Harnessing Adversarial Examples
TL;DR: The authors argue that the primary cause of neural networks' vulnerability to adversarial perturbation is their linear nature, which is supported by new quantitative results while giving the first explanation of the most intriguing fact about adversarial examples: their generalization across architectures and training sets.
15.9K
•Proceedings Article
Intriguing properties of neural networks
Christian Szegedy,Wojciech Zaremba,Ilya Sutskever,Joan Bruna,Dumitru Erhan,Ian Goodfellow,Rob Fergus,Rob Fergus +7 more
- 01 Jan 2014
TL;DR: It is found that there is no distinction between individual highlevel units and random linear combinations of high level units, according to various methods of unit analysis, and it is suggested that it is the space, rather than the individual units, that contains of the semantic information in the high layers of neural networks.
13K
Fully Convolutional Networks for Semantic Segmentation
TL;DR: Fully convolutional networks (FCN) as mentioned in this paper were proposed to combine semantic information from a deep, coarse layer with appearance information from shallow, fine layer to produce accurate and detailed segmentations.
10.6K