针对在线学习的深度接收机,提出一种无需目标信息的迁移式投毒攻击方法。
Transfer-based Adversarial Poisoning Attacks for Online (MIMO-)Deep Receviers
- 利用迁移学习生成对抗性扰动,污染导频信号以干扰接收机自适应能力。
- 在多种信道环境下,攻击使在线接收机性能显著下降,尤其在快速变化场景中。
- 适用于研究无线通信系统安全性的研究人员,关注深度接收机防御机制者必读。
近年来,基于深度神经网络(DNN)设计的深度接收机因其在复杂信道环境中的可靠通信潜力而受到广泛关注。为快速适应动态信道,已有研究采用在线学习方式,利用空中传输数据(如导频)更新接收机权重。然而,神经模型的脆弱性与无线信道的开放性使其面临恶意攻击风险。为此,理解攻击方法对提升接收机鲁棒性至关重要。本文提出一种基于迁移的对抗性投毒攻击方法,针对在线深度接收机。无需目标模型知识,通过向导频注入对抗性扰动,污染在线学习过程,破坏接收机对时变信道和非线性效应的自适应能力。特别地,该攻击针对采用在线元学习的深度软干扰消除(DeepSIC)模型。作为经典的模型驱动型深度接收机,DeepSIC将无线领域知识嵌入架构,仅需少量导频即可高效适应时变信道,在多输入多输出(MIMO)场景下表现优异。我们通过在合成线性、合成非线性、静态及COST 2100信道上的仿真验证了攻击的有效性。结果表明,所提投毒攻击在快速变化场景中显著降低在线接收机性能。
原文摘要 · Abstract (English)
Recently, the design of wireless receivers using deep neural networks (DNNs), known as deep receivers, has attracted extensive attention for ensuring reliable communication in complex channel environments. To adapt quickly to dynamic channels, online learning has been adopted to update the weights of deep receivers with over-the-air data (e.g., pilots). However, the fragility of neural models and the openness of wireless channels expose these systems to malicious attacks. To this end, understanding these attack methods is essential for robust receiver design. In this paper, we propose a transfer-based adversarial poisoning attack method for online receivers. Without knowledge of the attack target, adversarial perturbations are injected to the pilots, poisoning the online deep receiver and impairing its ability to adapt to dynamic channels and nonlinear effects. In particular, our attack method targets Deep Soft Interference Cancellation (DeepSIC)[1] using online meta-learning. As a classical model-driven deep receiver, DeepSIC incorporates wireless domain knowledge into its architecture. This integration allows it to adapt efficiently to time-varying channels with only a small number of pilots, achieving optimal performance in a multi-input and multi-output (MIMO) scenario. The deep receiver in this scenario has a number of applications in the field of wireless communication, which motivates our study of the attack methods targeting it. Specifically, we demonstrate the effectiveness of our attack in simulations on synthetic linear, synthetic nonlinear, static, and COST 2100 channels. Simulation results indicate that the proposed poisoning attack significantly reduces the performance of online receivers in rapidly changing scenarios.
Thank you to arXiv for use of its open access interoperability. PaperDance 不是 arXiv 官方产品;中文卡片由大模型生成,请以原文为准。