Adversarial Robust ViT-Based Automatic Modulation Recognition in Practical Deep Learning-Based Wireless Systems
Gen Li, ChunChih Lin, Xiaonan Zhang, Xiaolong Ma, Linke Guo
Abstract
Advanced wireless communication systems adopt deep learning (DL) approaches to achieve automatic modulation recognition (AMR) for spectrum monitoring and management, especially in the spectrum bands supporting diverse co-existing wireless protocols. In practical wireless environments, wireless signals can easily get compromised by malicious noise, intentional interference, and adversarial attacks, reducing the effectiveness of AMR. By exploiting DL model vulnerabilities, an undetectable perturbation added to the wireless signal can cause misclassification, resutling in serious consequences including decoding errors, throughput degradation, and communication disruption. Facing the limitations of existing works on defending against wireless adversarial attacks, this work innovates the Transformer model to design an adversarial robust AMR driven by exploring temporal correlation in time-sequence wireless signals. Instead of directly applying the Vision Transformer (ViT), we first innovate a feature extraction module specifically for radio frequency (RF) signals from both the time and frequency domains, together with an adaptive positional embedding to the Transformer encoder for enhancing AMR accuracy. To mitigate the noise effect in practical wireless communication, we then propose a noise-adaptive adversarial training scheme on the developed Transformer-based model using adversarial examples crafted by white-box attackers. To show the scheme's efficiency, effectiveness, and robustness, our proposed design has been thoroughly evaluated via a self-collected real-world dataset consisting of over 30 million wireless signal data samples with 21 modulation schemes in both indoor and outdoor scenarios. Our results reach a maximum accuracy of 94.17% in AMR classification and 71.2 % under adversarial attacks. Besides, for the first time, we demonstrate the robustness of our design under a real wireless adversarial attack in real-time. Datasets and code available in https://github.com/coulsonlee/Robust-ViT-for-AMR-SP2025.
Ask about this paper
Your agent reads all of it.
Lune indexed this paper to the last equation, along with the top-tier papers that cite it. Ask a question and the answer quotes them.
Your agent calls
Luneget_paper_fulltext
Free to start. No credit card required.
Terminal
Install the CLIlune papers fulltext c8d70862-298d-492f-aba0-1839741c0203Builds on9
- An Image is Worth 16x16 Words: Transformers for Image Recognition at ScaleAlexey Dosovitskiy, Lucas Beyer, Alexander Kolesnikov, Dirk Weissenborn et al.ICLR 2021 · 21,477 citations
- Towards Evaluating the Robustness of Neural NetworksNicholas Carlini, David A. WagnerS&P 2017 · 9,786 citations
- Reliable evaluation of adversarial robustness with an ensemble of diverse parameter-free attacksFrancesco Croce, Matthias HeinICML 2020 · 2,337 citations
- Fast is better than free: Revisiting adversarial trainingEric Wong, Leslie Rice, J. Zico KolterICLR 2020 · 1,352 citations
- Vision Transformers Are Robust LearnersSayak Paul, Pin-Yu ChenAAAI 2022 · 372 citations
Related papers
- Threats of Adversarial Attacks in DNN-Based Modulation RecognitionYun Lin, Haojun Zhao, Ya Tu, Shiwen Mao et al.INFOCOM 2020 · 133 citations
- Robust Adversarial Attacks Against DNN-Based Wireless Communication SystemsAlireza Bahramali, Milad Nasr, Amir Houmansadr, Dennis Goeckel et al.CCS 2021 · 80 citations
- Learning the unknown: Improving modulation classification performance in unseen scenariosErma Perenda, Sreeraj Rajendran, Gérôme Bovet, Sofie Pollin et al.INFOCOM 2021 · 44 citations
- A Unified Framework for Detecting Audio Adversarial ExamplesXia Du, Chi-Man Pun, Zheng ZhangACM MM 2020 · 18 citations
- Contrastive learning with self-reconstruction for channel-resilient modulation classificationErma Perenda, Sreeraj Rajendran, Gérôme Bovet, Mariya Zheleva et al.INFOCOM 2023 · 16 citations
