A Neural Rejection System Against Universal Adversarial Perturbations in Radio Signal Classification
Universal adversarial perturbations (UAPs) severely degrade the robustness of deep classifiers for radio-frequency (RF) signals. Method: This paper proposes a neural rejection system that operates without modifying the original classifier. It introduces, for the first time in the RF domain, a neural rejection mechanism leveraging white-box UAP generation, confidence thresholding, and feature consistency verification to construct a lightweight, real-time adversarial sample detection and rejection module. The approach decouples detection from classification while preserving the original model architecture. Contribution/Results: Evaluated on multiple public RF datasets, the system reduces UAP attack success rates by over 60% and improves secure classification accuracy by more than 35%, significantly enhancing both model robustness and practical deployability.