A Neural Rejection System Against Universal Adversarial Perturbations in Radio Signal Classification

πŸ“… 2021-12-01
πŸ›οΈ Global Communications Conference
πŸ“ˆ Citations: 2
✨ Influential: 1
πŸ“„ PDF
πŸ€– AI Summary
Universal adversarial perturbations (UAPs) severely degrade the robustness of deep classifiers for radio-frequency (RF) signals. Method: This paper proposes a neural rejection system that operates without modifying the original classifier. It introduces, for the first time in the RF domain, a neural rejection mechanism leveraging white-box UAP generation, confidence thresholding, and feature consistency verification to construct a lightweight, real-time adversarial sample detection and rejection module. The approach decouples detection from classification while preserving the original model architecture. Contribution/Results: Evaluated on multiple public RF datasets, the system reduces UAP attack success rates by over 60% and improves secure classification accuracy by more than 35%, significantly enhancing both model robustness and practical deployability.

Technology Category

Application Category

πŸ“ Abstract
Advantages of deep learning over traditional methods have been demonstrated for radio signal classification in the recent years. However, various researchers have discovered that even a small but intentional feature perturbation known as adversarial examples can significantly deteriorate the performance of the deep learning based radio signal classification. Among various kinds of adversarial examples, universal adversarial perturbation has gained considerable attention due to its feature of being data independent, hence as a practical strategy to fool the radio signal classification with a high success rate. Therefore, in this paper, we investigate a defense system called neural rejection system to propose against universal adversarial perturbations, and evaluate its performance by generating white-box universal adversarial perturbations. We show that the proposed neural rejection system is able to defend universal adversarial perturbations with significantly higher accuracy than the undefended deep neural network.
Problem

Research questions and friction points this paper is trying to address.

Defends against universal adversarial perturbations in radio signal classification
Improves accuracy of deep learning models under adversarial attacks
Proposes neural rejection system to counter data-independent perturbations
Innovation

Methods, ideas, or system contributions that make the work stand out.

Neural rejection system defends adversarial perturbations
White-box universal adversarial perturbations evaluated
Higher accuracy than undefended deep neural network
πŸ”Ž Similar Papers
No similar papers found.
πŸ’Ό Related Jobs
No related jobs found.
L
Lu Zhang
Wolfson School of Mechanical, Electrical and Manufacturing Engineering, Loughborough University, Loughborough, UK
S
S. Lambotharan
Wolfson School of Mechanical, Electrical and Manufacturing Engineering, Loughborough University, Loughborough, UK
G
G. Zheng
Wolfson School of Mechanical, Electrical and Manufacturing Engineering, Loughborough University, Loughborough, UK
F
F. Roli
Dept. of Electrical and Electronic Engineering, University of Cagliari, Piazza d’Armi, 09123 Cagliari, Italy