arXiv:2512.24452cs.NIcs.AI2025-12被引 2

让语义通信更安全,防窃听且不降性能。

Privacy-Preserving Semantic Communications via Multi-Task Learning and Adversarial Perturbations

  • 用多任务学习与对抗扰动联合优化,保护语义信息
  • 在噪声信道中,窃听者语义识别准确率下降超60%
  • 无需额外训练,即可有效抑制信息泄露,适合实际通信系统

语义通信通过传输任务相关含义而非完整消息,提升了下一代无线系统的带宽效率和鲁棒性。然而,学习到的语义表示仍可能向未授权接收方泄露敏感信息。本文提出一种基于深度学习的语义通信框架,支持多个合法接收端任务,同时显式限制对窃听者的语义泄漏。合法链路在发送端使用学习编码器,接收端训练用于语义推理和数据重建的解码器。安全问题通过迭代极小极大优化建模:窃听者被训练以提升其语义推理能力,而合法收发双方则被训练以维持任务性能的同时降低窃听者成功率。此外,引入辅助层,在传输波形上叠加协作式、对抗性构造的扰动,以削弱语义泄漏。在瑞利衰落信道加高斯白噪声环境下,使用MNIST和CIFAR-10数据集评估性能。随着潜在维度增加,语义准确率和重建质量均提升;极小极大机制显著降低窃听者推断性能,而不损害合法接收方表现。即使合法链路仅针对自身任务训练,扰动层仍能有效减少语义泄漏。该综合框架为现实无线环境中可调、端到端隐私保护的语义通信设计提供了新思路。

原文摘要 · Abstract (English)

Semantic communications conveys task-relevant meaning rather than focusing solely on message reconstruction, improving bandwidth efficiency and robustness for next-generation wireless systems. However, learned semantic representations can still leak sensitive information to unintended receivers (eavesdroppers). This paper presents a deep learning-based semantic communication framework that jointly supports multiple receiver tasks while explicitly limiting semantic leakage to an eavesdropper. The legitimate link employs a learned encoder at the transmitter, while the receiver trains decoders for semantic inference and data reconstruction. The security problem is formulated via an iterative min-max optimization in which an eavesdropper is trained to improve its semantic inference, while the legitimate transmitter-receiver pair is trained to preserve task performance while reducing the eavesdropper's success. We also introduce an auxiliary layer that superimposes a cooperative, adversarially crafted perturbation on the transmitted waveform to degrade semantic leakage to an eavesdropper. Performance is evaluated over Rayleigh fading channels with additive white Gaussian noise using MNIST and CIFAR-10 datasets. Semantic accuracy and reconstruction quality improve with increasing latent dimension, while the min-max mechanism reduces the eavesdropper's inference performance significantly without degrading the legitimate receiver. The perturbation layer is successful in reducing semantic leakage even when the legitimate link is trained only for its own task. This comprehensive framework motivates semantic communication designs with tunable, end-to-end privacy against adaptive adversaries in realistic wireless settings.

语义通信隐私保护对抗扰动多任务学习

Thank you to arXiv for use of its open access interoperability. PaperDance 不是 arXiv 官方产品;中文卡片由大模型生成,请以原文为准。