提出一种新防御方法,让信号分类模型更抗攻击且保持高精度。
Filtered Randomized Smoothing: A New Defense for Robust Modulation Classification
- 结合频谱滤波与随机平滑,利用信号频域特性增强防御
- 在RadioML数据集上,对攻击和正常信号的准确率均显著优于现有方法
- 适合需要可证明安全性的无线信号分类场景
基于深度神经网络(DNN)的射频信号调制分类器近年来表现优异,但易受低功率不可察觉的对抗攻击影响。现有防御方法如对抗训练(AT)难以应对未知自适应攻击,而随机平滑(RS)虽能提供可证明的防御,却常牺牲准确率。本文分析了在标准RadioML数据集上常见攻击的频谱特征,发现未受扰信号频谱高度集中,而攻击信号则频域分布广泛。据此提出滤波型随机平滑(FRS),通过引入频谱滤波强化随机平滑。FRS利用调制分类任务中的频谱异质性,既保留可证明防御能力,又显著提升准确率。文中还提供了计算FRS认证准确率的方法,并在RadioML上进行了全面仿真,结果表明FRS在攻击和良性信号上的性能均显著优于AT和RS。
原文摘要 · Abstract (English)
Deep Neural Network (DNN) based classifiers have recently been used for the modulation classification of RF signals. These classifiers have shown impressive performance gains relative to conventional methods, however, they are vulnerable to imperceptible (low-power) adversarial attacks. Some of the prominent defense approaches include adversarial training (AT) and randomized smoothing (RS). While AT increases robustness in general, it fails to provide resilience against previously unseen adaptive attacks. Other approaches, such as Randomized Smoothing (RS), which injects noise into the input, address this shortcoming by providing provable certified guarantees against arbitrary attacks, however, they tend to sacrifice accuracy. In this paper, we study the problem of designing robust DNN-based modulation classifiers that can provide provable defense against arbitrary attacks without significantly sacrificing accuracy. To this end, we first analyze the spectral content of commonly studied attacks on modulation classifiers for the benchmark RadioML dataset. We observe that spectral signatures of un-perturbed RF signals are highly localized, whereas attack signals tend to be spread out in frequency. To exploit this spectral heterogeneity, we propose Filtered Randomized Smoothing (FRS), a novel defense which combines spectral filtering together with randomized smoothing. FRS can be viewed as a strengthening of RS by leveraging the specificity (spectral Heterogeneity) inherent to the modulation classification problem. In addition to providing an approach to compute the certified accuracy of FRS, we also provide a comprehensive set of simulations on the RadioML dataset to show the effectiveness of FRS and show that it significantly outperforms existing defenses including AT and RS in terms of accuracy on both attacked and benign signals.
Thank you to arXiv for use of its open access interoperability. PaperDance 不是 arXiv 官方产品;中文卡片由大模型生成,请以原文为准。