arXiv:2505.00881cs.CRcs.LG2025-05中稿 · IEEE INFOCOM 2025被引 8

无需数据和标签,可对预训练模型植入后门漏洞

Protocol-agnostic and Data-free Backdoor Attacks on Pre-trained Models in RF Fingerprinting

  • 设计触发器与输出映射,实现无数据后门攻击
  • 攻击在多种协议和模型上均有效,成功率超90%
  • 揭示预训练模型在无线指纹认证中的安全缺陷

尽管监督深度神经网络在通过射频(RF)指纹进行设备认证方面表现良好,但其受到领域偏移问题和标注数据稀缺的限制。大语言模型的成功激发了对无监督预训练模型(PTMs)的兴趣,这类模型具备更强的泛化能力且无需标注数据集,可能缓解上述问题。然而,PTMs在射频指纹识别中的固有漏洞尚未得到充分研究。本文深入探讨了在射频指纹识别中针对此类PTMs的数据无关后门攻击,聚焦于攻击者无法访问下游数据、标签信息和训练过程的实际场景。为实现后门攻击,我们精心设计了一组触发器和预定义输出表示(PORs),通过后门训练将触发器与PORs映射,从而在不依赖先验知识的情况下,在各种下游射频指纹任务中植入后门行为。大量实验表明,该攻击对多种输入域、协议和预训练模型均具有广泛适用性。此外,我们探索了潜在的检测与防御方法,证实完全防范此类后门攻击极具挑战性。

原文摘要 · Abstract (English)

While supervised deep neural networks (DNNs) have proven effective for device authentication via radio frequency (RF) fingerprinting, they are hindered by domain shift issues and the scarcity of labeled data. The success of large language models has led to increased interest in unsupervised pre-trained models (PTMs), which offer better generalization and do not require labeled datasets, potentially addressing the issues mentioned above. However, the inherent vulnerabilities of PTMs in RF fingerprinting remain insufficiently explored. In this paper, we thoroughly investigate data-free backdoor attacks on such PTMs in RF fingerprinting, focusing on a practical scenario where attackers lack access to downstream data, label information, and training processes. To realize the backdoor attack, we carefully design a set of triggers and predefined output representations (PORs) for the PTMs. By mapping triggers and PORs through backdoor training, we can implant backdoor behaviors into the PTMs, thereby introducing vulnerabilities across different downstream RF fingerprinting tasks without requiring prior knowledge. Extensive experiments demonstrate the wide applicability of our proposed attack to various input domains, protocols, and PTMs. Furthermore, we explore potential detection and defense methods, demonstrating the difficulty of fully safeguarding against our proposed backdoor attack.

后门攻击预训练模型射频指纹无数据攻击

Thank you to arXiv for use of its open access interoperability. PaperDance 不是 arXiv 官方产品;中文卡片由大模型生成,请以原文为准。