Robust Adversarial Attacks Against DNN-Based Wireless Communication Systems
Alireza Bahramali, Milad Nasr, Amir Houmansadr, Dennis Goeckel, Don Towsley
Abstract
There is significant enthusiasm for the employment of Deep Neural Networks (DNNs) for important tasks in major wireless communication systems: channel estimation and decoding in orthogonal frequency division multiplexing (OFDM) systems, end-to-end autoencoder system design, radio signal classification, and signal authentication. Unfortunately, DNNs can be susceptible to adversarial examples, potentially making such wireless systems fragile and vulnerable to attack. In this work, by designing robust adversarial examples that meet key criteria, we perform a comprehensive study of the threats facing DNN-based wireless systems. We model the problem of adversarial wireless perturbations as an optimization problem that incorporates domain constraints specific to different wireless systems. This allows us to generate wireless adversarial perturbations that can be applied to wireless signals on-the-fly (i.e., with no need to know the target signals a priori), are undetectable from natural wireless noise, and are robust against removal. We show that even in the presence of significant defense mechanisms deployed by the communicating parties, our attack performs significantly better compared to existing attacks against DNN-based wireless systems. In particular, the results demonstrate that even when employing well-considered defenses, DNN-based wireless communication systems are vulnerable to adversarial attacks and call into question the employment of DNNs for a number of tasks in robust wireless communication.
Ask about this paper
Your agent reads all of it.
Lune indexed this paper to the last equation, along with the top-tier papers that cite it. Ask a question and the answer quotes them.
Your agent calls
Luneget_paper_fulltext
Free to start. No credit card required.
Terminal
Install the CLIlune papers fulltext a2afeda3-5ab9-43c8-b93d-85c5aaf4bd76Cited by top-tier papers8
- Exploring Practical Vulnerabilities of Machine Learning-based Wireless SystemsZikun Liu, Changming Xu, Emerson Sie, Gagandeep Singh et al.NSDI 2023 · 27 citations
- "Get in Researchers; We're Measuring Reproducibility": A Reproducibility Study of Machine Learning Papers in Tier 1 Security ConferencesDaniel Olszewski, Allison Lu, Carson Stillman, Kevin Warren et al.CCS 2023 · 19 citations
- Robust Universal Adversarial PerturbationsChangming Xu, Gagandeep SinghICML 2024 · 3 citations
- Deep Learning Models as Moving Targets to Counter Modulation Classification AttacksNaureen Hoque, Hanif RahbariINFOCOM 2024 · 1 citation
- BARS: Local Robustness Certification for Deep Learning based Traffic Analysis SystemsKai Wang, Zhiliang Wang, Dongqi Han, Wenqi Chen et al.NDSS 2023
Builds on1
Related papers
- Threats of Adversarial Attacks in DNN-Based Modulation RecognitionYun Lin, Haojun Zhao, Ya Tu, Shiwen Mao et al.INFOCOM 2020 · 133 citations
- Magmaw: Modality-Agnostic Adversarial Attacks on Machine Learning-Based Wireless Communication SystemsJung-Woo Chang, Ke Sun, Nasimeh Heydaribeni, Seira Hidano et al.NDSS 2025
- Countering Acoustic Adversarial Attacks in Microphone-equipped Smart Home DevicesSourav Bhattacharya, Dionysis Manousakas, Alberto Gil C. P. Ramos, Stylianos I. Venieris et al.UbiComp 2020 · 19 citations
- WiAdv: Practical and Robust Adversarial Attack against WiFi-based Gesture Recognition SystemYuxuan Zhou, Huangxun Chen, Chenyu Huang, Qian ZhangUbiComp 2022 · 31 citations
- Explanation-Guided Backdoor Attacks on Model-Agnostic RF FingerprintingTianya Zhao, Xuyu Wang, Junqing Zhang, Shiwen MaoINFOCOM 2024 · 24 citations
