Poisoning Attacks on Deep Learning based Wireless Traffic Prediction
Tianhang Zheng, Baochun Li
Abstract
Big client data and deep learning bring a new level of accuracy to wireless traffic prediction in non-adversarial environments. However, in a malicious client environment, the training-stage vulnerability of deep learning (DL) based wireless traffic prediction remains under-explored. In this paper, we conduct the first systematic study on training-stage poisoning attacks against DL-based wireless traffic prediction in both centralized and distributed training scenarios. In contrast to previous poisoning attacks on computer vision, we consider a more practical threat model, specific to wireless traffic prediction, to design these poisoning attacks. In particular, we assume that potential malicious clients do not collude or have any additional knowledge about the other clients' data. We propose a perturbation masking strategy and a tuning-and-scaling method to fit data and model poisoning attacks into the practical threat model. We also explore potential defenses against these poisoning attacks and propose two defense methods. Through extensive evaluations, we show the mean square error (MSE) can be increased by over 50% to 10 8 times with our proposed poisoning attacks. We also demonstrate the effectiveness of our data sanitization approach and anomaly detection method against our poisoning attacks in centralized and distributed scenarios.
Ask about this paper
Your agent reads all of it.
Lune indexed this paper to the last equation, along with the top-tier papers that cite it. Ask a question and the answer quotes them.
Cited by top-tier papers3
- Explanation-Guided Backdoor Attacks on Model-Agnostic RF FingerprintingTianya Zhao, Xuyu Wang, Junqing Zhang, Shiwen MaoINFOCOM 2024 · 24 citations
- Spotting Deep Neural Network Vulnerabilities in Mobile Traffic Forecasting with an Explainable AI LensSerly Moghadas, Claudio Fiandrino, Alan Collet, Giulia Attanasio et al.INFOCOM 2023 · 9 citations
- Protocol-Agnostic and Data-Free Backdoor Attacks on Pre-Trained Models in RF FingerprintingTianya Zhao, Ningning Wang, Junqing Zhang, Xuyu WangINFOCOM 2025 · 7 citations
Builds on11
- Manipulating Machine Learning: Poisoning Attacks and Countermeasures for Regression LearningMatthew Jagielski, Alina Oprea, Battista Biggio, Chang Liu et al.S&P 2018 · 867 citations
- Witches' Brew: Industrial Scale Data Poisoning via Gradient MatchingJonas Geiping, Liam H. Fowl, W. Ronny Huang, Wojciech Czaja et al.ICLR 2021 · 268 citations
- MetaPoison: Practical General-purpose Clean-label Data PoisoningW. Ronny Huang, Jonas Geiping, Liam Fowl, Gavin Taylor et al.NeurIPS 2020 · 242 citations
- You Autocomplete Me: Poisoning Vulnerabilities in Neural Code CompletionRoei Schuster, Congzheng Song, Eran Tromer, Vitaly ShmatikovUSENIX Security 2021 · 199 citations
- Certified Robustness to Label-Flipping Attacks via Randomized SmoothingElan Rosenfeld, Ezra Winston, Pradeep Ravikumar, J. Zico KolterICML 2020 · 182 citations
Related papers
- Deep Learning Models as Moving Targets to Counter Modulation Classification AttacksNaureen Hoque, Hanif RahbariINFOCOM 2024 · 1 citation
- First-Order Efficient General-Purpose Clean-Label Data PoisoningTianhang Zheng, Baochun LiINFOCOM 2021 · 8 citations
- Prediction Poisoning: Towards Defenses Against DNN Model Stealing AttacksTribhuvanesh Orekondy, Bernt Schiele, Mario FritzICLR 2020 · 194 citations
- Manipulating the Byzantine: Optimizing Model Poisoning Attacks and Defenses for Federated LearningVirat Shejwalkar, Amir HoumansadrNDSS 2021
- Practical Adversarial Attack on WiFi Sensing Through Unnoticeable Communication Packet PerturbationChangming Li, Mingjing Xu, Yicong Du, Limin Liu et al.MobiCom 2024 · 22 citations
