AI解码器在小信道扰动下易失效,看似提升实则脆弱。
On the Fragility of AI-Based Channel Decoders under Small Channel Perturbations
- 用对抗扰动测试AI解码器鲁棒性,发现性能大幅下降。
- 统一扰动比随机扰动危害更大,且在不同AI解码器间可迁移。
- 虽在理想信道表现好,但对分布偏移敏感,适合关注安全性的研究者。
深度学习推动了基于AI的纠错解码器发展,在高斯白噪声(AWGN)信道上表现出优于传统置信传播(BP)解码的实证性能。然而,这些改进的来源及其代价仍不明确。本文从信道输出分布偏移的角度考察这一问题,评估了输入相关对抗扰动(如FGM和ℓ₂约束下的投影梯度法)以及作用于所有接收向量的通用对抗扰动。结果表明,近期的AI解码器(包括ECCT和CrossMPT)在这些扰动下会出现显著性能下降,尽管其在独立同分布的AWGN信道下表现优异。此外,对抗扰动在不同AI解码器间具有较强的迁移能力,但对基于BP的解码器影响较弱;统一扰动的危害远超同范数的随机扰动。这些数值结果提示,当前AI解码的优势可能以牺牲鲁棒性为代价,对信道分布变化更为敏感。
原文摘要 · Abstract (English)
Recent advances in deep learning have led to AI-based error correction decoders that report empirical performance improvements over traditional belief-propagation (BP) decoding on AWGN channels. While such gains are promising, a fundamental question remains: where do these improvements come from, and what cost is paid to achieve them? In this work, we study this question through the lens of robustness to distributional shifts at the channel output. We evaluate both input-dependent adversarial perturbations (FGM and projected gradient methods under $\ell_2$ constraints) and universal adversarial perturbations that apply a single norm-bounded shift to all received vectors. Our results show that recent AI decoders, including ECCT and CrossMPT, could suffer significant performance degradation under such perturbations, despite superior nominal performance under i.i.d. AWGN. Moreover, adversarial perturbations transfer relatively strongly between AI decoders but weakly to BP-based decoders, and universal perturbations are substantially more harmful than random perturbations of equal norm. These numerical findings suggest a potential robustness cost and higher sensitivity to channel distribution underlying recent AI decoding gains.
Thank you to arXiv for use of its open access interoperability. PaperDance 不是 arXiv 官方产品;中文卡片由大模型生成,请以原文为准。