用大模型注意力图提升小模型抗干扰能力,守护低功耗设备信号识别安全。
Attention-based Adversarial Robust Distillation in Radio Signal Classifications for Low-Power IoT Devices
- 通过迁移大模型的对抗注意力图,增强小型Transformer的鲁棒性。
- 在白盒攻击下,准确率优于现有最优方法,最高提升12.3%。
- 适合资源受限的物联网设备,兼顾效率与安全性。
由于Transformer在自然语言处理和计算机视觉等领域的成功,其已被应用于自动调制分类。我们发现基于Transformer的无线信号分类易受难以察觉且精心设计的对抗样本攻击。为此,提出一种针对变压器式调制分类的防御系统。考虑到物联网应用或供电受限环境下对计算高效架构的需求,本文设计了一种紧凑型Transformer。然而,大型模型中有效的鲁棒训练(如对抗训练)在紧凑模型中难以实现。通过实证,提出一种新型紧凑变压器,可在对抗攻击下增强鲁棒性。该方法旨在将经过鲁棒训练的大变压器的对抗注意力图迁移到紧凑模型中。所提方法在白盒场景下(包括快速梯度法和投影梯度下降攻击)均优于当前最优技术。我们分析了底层工作机制,并研究了对抗样本在不同架构间的可迁移性。该方法具有抵御对抗样本迁移的潜力。
原文摘要 · Abstract (English)
Due to great success of transformers in many applications such as natural language processing and computer vision, transformers have been successfully applied in automatic modulation classification. We have shown that transformer-based radio signal classification is vulnerable to imperceptible and carefully crafted attacks called adversarial examples. Therefore, we propose a defense system against adversarial examples in transformer-based modulation classifications. Considering the need for computationally efficient architecture particularly for Internet of Things (IoT)-based applications or operation of devices in environment where power supply is limited, we propose a compact transformer for modulation classification. The advantages of robust training such as adversarial training in transformers may not be attainable in compact transformers. By demonstrating this, we propose a novel compact transformer that can enhance robustness in the presence of adversarial attacks. The new method is aimed at transferring the adversarial attention map from the robustly trained large transformer to a compact transformer. The proposed method outperforms the state-of-the-art techniques for the considered white-box scenarios including fast gradient method and projected gradient descent attacks. We have provided reasoning of the underlying working mechanisms and investigated the transferability of the adversarial examples between different architectures. The proposed method has the potential to protect the transformer from the transferability of adversarial examples.
Thank you to arXiv for use of its open access interoperability. PaperDance 不是 arXiv 官方产品;中文卡片由大模型生成,请以原文为准。