深度学习的射频指纹识别存在可被利用的漏洞,易遭攻击者伪装入侵。
An Adversarial-Driven Experimental Study on Deep Learning for RF Fingerprinting
- 通过对抗性实验分析,发现模型在域偏移下会持续误判设备身份。
- 真实环境实验表明,攻击者可利用此误判行为构建有效后门。
- 原始信号训练导致指纹与环境特征混淆,仅靠阈值无法防御。
射频(RF)指纹识别通过提取无线设备的独特硬件缺陷,已成为零信任架构和5G以上网络中极具前景的物理层设备识别方法。深度学习(DL)方法在此领域已展现顶尖性能。然而,现有研究多关注系统对无线环境时变与空变的鲁棒性,而忽视了基于DL方法的安全隐患。本文通过对抗性驱动的实验分析,系统研究了基于DL的RF指纹识别系统的安全风险。大量真实世界实验表明,模型在域偏移下存在一致的误分类行为,即某设备常被错误识别为特定另一设备。这一现象可被外部攻击者利用,作为有效后门侵入系统。此外,我们发现使用原始接收信号训练模型会使RF指纹与环境及信号模式特征纠缠,产生无法仅通过置信度阈值等后处理手段缓解的额外攻击面。
原文摘要 · Abstract (English)
Radio frequency (RF) fingerprinting, which extracts unique hardware imperfections of radio devices, has emerged as a promising physical-layer device identification mechanism in zero trust architectures and beyond 5G networks. In particular, deep learning (DL) methods have demonstrated state-of-the-art performance in this domain. However, existing approaches have primarily focused on enhancing system robustness against temporal and spatial variations in wireless environments, while the security vulnerabilities of these DL-based approaches have often been overlooked. In this work, we systematically investigate the security risks of DL-based RF fingerprinting systems through an adversarial-driven experimental analysis. We observe a consistent misclassification behavior for DL models under domain shifts, where a device is frequently misclassified as another specific one. Our analysis based on extensive real-world experiments demonstrates that this behavior can be exploited as an effective backdoor to enable external attackers to intrude into the system. Furthermore, we show that training DL models on raw received signals causes the models to entangle RF fingerprints with environmental and signal-pattern features, creating additional attack vectors that cannot be mitigated solely through post-processing security methods such as confidence thresholds.
Thank you to arXiv for use of its open access interoperability. PaperDance 不是 arXiv 官方产品;中文卡片由大模型生成,请以原文为准。