通过白盒攻击生成信号对抗样本,有效降低检测网络性能。
Signal Adversarial Examples Generation for Signal Detection Network via White-Box Attack
- 基于时域与时频域L2范数不等式约束扰动能量。
- 扰动能量比低于3%时,mAP下降28.1%。
- 适合研究信号检测安全性的研究人员。
随着深度学习在信号检测任务中的应用发展,神经网络对对抗攻击的脆弱性已成为信号检测网络的安全隐患。本文从向信号添加扰动的角度,定义了一种面向信号检测网络的对抗样本生成模型。该模型利用时域与时频域间L2范数的不等式关系,约束信号扰动的能量。基于此模型,提出一种结合梯度攻击与短时傅里叶变换的信号对抗样本生成方法。实验结果表明,在信号扰动能量比小于3%的约束下,所提对抗攻击使信号检测网络的平均精度均值(mAP)下降28.1%,召回率下降24.7%,精确率下降30.4%。相较于同等强度的随机噪声扰动,本方法展现出显著的攻击效果。
原文摘要 · Abstract (English)
With the development and application of deep learning in signal detection tasks, the vulnerability of neural networks to adversarial attacks has also become a security threat to signal detection networks. This paper defines a signal adversarial examples generation model for signal detection network from the perspective of adding perturbations to the signal. The model uses the inequality relationship of L2-norm between time domain and time-frequency domain to constrain the energy of signal perturbations. Building upon this model, we propose a method for generating signal adversarial examples utilizing gradient-based attacks and Short-Time Fourier Transform. The experimental results show that under the constraint of signal perturbation energy ratio less than 3%, our adversarial attack resulted in a 28.1% reduction in the mean Average Precision (mAP), a 24.7% reduction in recall, and a 30.4% reduction in precision of the signal detection network. Compared to random noise perturbation of equivalent intensity, our adversarial attack demonstrates a significant attack effect.
Thank you to arXiv for use of its open access interoperability. PaperDance 不是 arXiv 官方产品;中文卡片由大模型生成,请以原文为准。