arXiv:2509.15170cs.CRcs.AI2025-09被引 1

为LoRa无线设备指纹设计防拷贝认证系统,兼顾版权保护与异常检测。

Watermarking and Anomaly Detection in Machine Learning Models for LORA RF Fingerprinting

  • 用ResNet-34在对数梅尔谱上嵌入三类水印,增强模型版权可验证性。
  • 在LoRa数据集上实现94.6%识别准确率、98%水印成功率和0.94 AUROC异常检测性能。
  • 适合需要高可信度设备认证的物联网安全场景,尤其抗噪声与篡改。

射频指纹识别(RFFI)通过模拟电路微小差异区分无线设备,无需复杂加密认证。尽管基于谱图的深度学习提升了识别精度,但模型仍易被复制、篡改或绕过。本文提出一个强化的RFFI系统,结合版权水印与异常检测。采用ResNet-34处理对数梅尔谱图,嵌入三类水印:简单触发器、对抗训练增强的鲁棒触发器,以及隐藏的梯度/权重签名。同时使用带KL热身和自由位机制的卷积变分自编码器(VAE)检测分布外输入。在LoRa数据集上,系统达到94.6%识别准确率、98%水印成功恢复率和0.94 AUROC异常检测表现,实现可验证、抗篡改的身份认证。

原文摘要 · Abstract (English)

Radio frequency fingerprint identification (RFFI) distinguishes wireless devices by the small variations in their analog circuits, avoiding heavy cryptographic authentication. While deep learning on spectrograms improves accuracy, models remain vulnerable to copying, tampering, and evasion. We present a stronger RFFI system combining watermarking for ownership proof and anomaly detection for spotting suspicious inputs. Using a ResNet-34 on log-Mel spectrograms, we embed three watermarks: a simple trigger, an adversarially trained trigger robust to noise and filtering, and a hidden gradient/weight signature. A convolutional Variational Autoencoders (VAE) with Kullback-Leibler (KL) warm-up and free-bits flags off-distribution queries. On the LoRa dataset, our system achieves 94.6% accuracy, 98% watermark success, and 0.94 AUROC, offering verifiable, tamper-resistant authentication.

射频指纹水印技术异常检测物联网安全

Thank you to arXiv for use of its open access interoperability. PaperDance 不是 arXiv 官方产品;中文卡片由大模型生成,请以原文为准。