Adversarial Examples in RF Deep Learning: Detection of the Attack and its Physical Robustness

by   Silvija Kokalj-Filipovic, et al.

While research on adversarial examples in machine learning for images has been prolific, similar attacks on deep learning (DL) for radio frequency (RF) signals and their mitigation strategies are scarcely addressed in the published work, with only one recent publication in the RF domain [1]. RF adversarial examples (AdExs) can cause drastic, targeted misclassification results mostly in spectrum sensing/ survey applications (e.g. BPSK mistaken for 8-PSK) with minimal waveform perturbation. It is not clear if the RF AdExs maintain their effects in the physical world, i.e., when AdExs are delivered over-the-air (OTA). Our research on deep learning AdExs and proposed defense mechanisms are RF-centric, and incorporate physical world, OTA effects. We here present defense mechanisms based on statistical tests. One test to detect AdExs utilizes Peak-to- Average-Power-Ratio (PAPR) of the DL data points delivered OTA, while another statistical test uses the Softmax outputs of the DL classifier, which corresponds to the probabilities the classifier assigns to each of the trained classes. The former test leverages the RF nature of the data, and the latter is universally applicable to AdExs regardless of their origin. Both solutions are shown as viable mitigation methods to subvert adversarial attacks against communications and radar sensing systems.


page 1

page 5


Mitigation of Adversarial Examples in RF Deep Classifiers Utilizing AutoEncoder Pre-training

Adversarial examples in machine learning for images are widely publicize...

Scalable End-to-End RF Classification: A Case Study on Undersized Dataset Regularization by Convolutional-MST

Unlike areas such as computer vision and speech recognition where convol...

Enhancing RF Sensing with Deep Learning: A Layered Approach

In recent years, radio frequency (RF) sensing has gained increasing popu...

Learning Robust Representations for Automatic Target Recognition

Radio frequency (RF) sensors are used alongside other sensing modalities...

Defense against adversarial attacks on deep convolutional neural networks through nonlocal denoising

Despite substantial advances in network architecture performance, the su...

Mitigating Adversarial Attacks in Deepfake Detection: An Exploration of Perturbation and AI Techniques

Deep learning is a crucial aspect of machine learning, but it also makes...

Darknet Traffic Classification and Adversarial Attacks

The anonymous nature of darknets is commonly exploited for illegal activ...

Please sign up or login with your details

Forgot password? Click here to reset