Is Semantic Communications Secure? A Tale of Multi-Domain Adversarial Attacks

12/20/2022
by   Yalin E. Sagduyu, et al.
0

Semantic communications seeks to transfer information from a source while conveying a desired meaning to its destination. We model the transmitter-receiver functionalities as an autoencoder followed by a task classifier that evaluates the meaning of the information conveyed to the receiver. The autoencoder consists of an encoder at the transmitter to jointly model source coding, channel coding, and modulation, and a decoder at the receiver to jointly model demodulation, channel decoding and source decoding. By augmenting the reconstruction loss with a semantic loss, the two deep neural networks (DNNs) of this encoder-decoder pair are interactively trained with the DNN of the semantic task classifier. This approach effectively captures the latent feature space and reliably transfers compressed feature vectors with a small number of channel uses while keeping the semantic loss low. We identify the multi-domain security vulnerabilities of using the DNNs for semantic communications. Based on adversarial machine learning, we introduce test-time (targeted and non-targeted) adversarial attacks on the DNNs by manipulating their inputs at different stages of semantic communications. As a computer vision attack, small perturbations are injected to the images at the input of the transmitter's encoder. As a wireless attack, small perturbations signals are transmitted to interfere with the input of the receiver's decoder. By launching these stealth attacks individually or more effectively in a combined form as a multi-domain attack, we show that it is possible to change the semantics of the transferred information even when the reconstruction loss remains low. These multi-domain adversarial attacks pose as a serious threat to the semantics of information transfer (with larger impact than conventional jamming) and raise the need of defense methods for the safe adoption of semantic communications.

READ FULL TEXT
research
12/21/2022

Vulnerabilities of Deep Learning-Driven Semantic Communications to Backdoor (Trojan) Attacks

This paper highlights vulnerabilities of deep learning-driven semantic c...
research
02/05/2020

Over-the-Air Adversarial Attacks on Deep Learning Based Modulation Classifier over Wireless Channels

We consider a wireless communication system that consists of a transmitt...
research
01/11/2023

Age of Information in Deep Learning-Driven Task-Oriented Communications

This paper studies the notion of age in task-oriented communications tha...
research
12/08/2021

Autoencoder-based Communications with Reconfigurable Intelligent Surfaces

This paper presents a novel approach for the joint design of a reconfigu...
research
09/16/2021

Adversarial Attacks against Deep Learning Based Power Control in Wireless Communications

We consider adversarial machine learning based attacks on power allocati...
research
07/03/2018

Deep Learning for Launching and Mitigating Wireless Jamming Attacks

An adversarial machine learning approach is introduced to launch jamming...
research
12/21/2021

Covert Communications via Adversarial Machine Learning and Reconfigurable Intelligent Surfaces

By moving from massive antennas to antenna surfaces for software-defined...

Please sign up or login with your details

Forgot password? Click here to reset