无线语义通信中,攻击者可低功耗注入触发信号,精准操控一方语义推理。
Wireless Backdoor Attack and Defense for Semantic Communications over Multiple Access Channel
- 通过空中注入低功率触发波,实现对特定用户的语义干扰
- 攻击仅影响目标用户,另一用户推理准确率保持97.3%
- 提出感知触发的鲁棒训练方法,有效防御此类攻击
语义通信(SemCom)旨在无线信道上传输中保留语义含义和任务相关的信息,超越传统消息恢复。在共享接入的无线网络中引入语义通信带来多用户语义推断的新漏洞。本文研究了两个发射机通过多址信道向共同接收机传输的语义通信系统,每个发射机将源信息映射为潜在语义表示,接收机联合重构并分类双方的语义信息。提出一种选择性空中后门(特洛伊木马)攻击:攻击者通过低功率触发波形在训练阶段注入共享接收信号。测试时再次发送触发信号,即可隐蔽、低功耗地操纵单个发射机的语义推断,对另一发射机影响极小。为此,开发了一种触发感知防御机制,在触发污染的无线观测下仍能保持正确的语义标签。结果表明,共享接入的语义通信系统易受选择性空中后门攻击,而触发感知鲁棒训练能有效提升语义保护能力。
原文摘要 · Abstract (English)
Semantic communication (SemCom) aims to preserve semantic meaning and task-oriented information beyond conventional message recovery over wireless channels. The adoption of SemCom in shared-access wireless networks introduces new vulnerabilities for multi-user semantic inference. This paper considers a SemCom system for two transmitters communicating with a common receiver over a multiple access channel. Each transmitter maps source information into latent semantic representations, while the receiver jointly reconstructs and classifies the semantic information for both transmitters. A selective over-the-air backdoor (Trojan) attack is presented in which an adversary transmits a low-power trigger waveform over the air and injects it into the shared received signal during training. By transmitting the trigger again during testing, this stealthy, low-power attack selectively manipulates the semantic inference for one transmitter while minimally affecting the inference of the other transmitter. To mitigate this vulnerability, a trigger-aware defense mechanism is developed to preserve correct semantic labels under trigger-contaminated wireless observations. The results demonstrate both the vulnerability of shared-access SemCom systems to selective over-the-air backdoor attacks and the effectiveness of trigger-aware robust training for semantic protection.
Thank you to arXiv for use of its open access interoperability. PaperDance 不是 arXiv 官方产品;中文卡片由大模型生成,请以原文为准。