提出神经拒收系统,有效防御无线信号分类中的通用对抗扰动。
A Neural Rejection System Against Universal Adversarial Perturbations in Radio Signal Classification
- 设计神经拒收机制,识别并拒绝潜在的对抗性干扰信号。
- 在白盒攻击下仍保持显著高于普通网络的分类准确率。
- 适合用于高可靠无线通信系统的安全防护场景。
近年来,深度学习在无线信号分类中展现出优于传统方法的优势。然而,研究发现,即使微小但故意设计的对抗样本(如对抗扰动)也能显著降低基于深度学习的分类性能。其中,通用对抗扰动因其数据无关性而备受关注,可高效欺骗无线信号分类系统。为此,本文提出一种名为神经拒收系统的防御机制,并通过生成白盒通用对抗扰动进行评估。结果表明,所提系统在面对通用对抗扰动时,分类准确率显著优于未防御的深度神经网络。
原文摘要 · Abstract (English)
Advantages of deep learning over traditional methods have been demonstrated for radio signal classification in the recent years. However, various researchers have discovered that even a small but intentional feature perturbation known as adversarial examples can significantly deteriorate the performance of the deep learning based radio signal classification. Among various kinds of adversarial examples, universal adversarial perturbation has gained considerable attention due to its feature of being data independent, hence as a practical strategy to fool the radio signal classification with a high success rate. Therefore, in this paper, we investigate a defense system called neural rejection system to propose against universal adversarial perturbations, and evaluate its performance by generating white-box universal adversarial perturbations. We show that the proposed neural rejection system is able to defend universal adversarial perturbations with significantly higher accuracy than the undefended deep neural network.
Thank you to arXiv for use of its open access interoperability. PaperDance 不是 arXiv 官方产品;中文卡片由大模型生成,请以原文为准。