π€ AI Summary
Universal adversarial perturbations (UAPs) severely degrade the robustness of deep classifiers for radio-frequency (RF) signals. Method: This paper proposes a neural rejection system that operates without modifying the original classifier. It introduces, for the first time in the RF domain, a neural rejection mechanism leveraging white-box UAP generation, confidence thresholding, and feature consistency verification to construct a lightweight, real-time adversarial sample detection and rejection module. The approach decouples detection from classification while preserving the original model architecture. Contribution/Results: Evaluated on multiple public RF datasets, the system reduces UAP attack success rates by over 60% and improves secure classification accuracy by more than 35%, significantly enhancing both model robustness and practical deployability.
π Abstract
Advantages of deep learning over traditional methods have been demonstrated for radio signal classification in the recent years. However, various researchers have discovered that even a small but intentional feature perturbation known as adversarial examples can significantly deteriorate the performance of the deep learning based radio signal classification. Among various kinds of adversarial examples, universal adversarial perturbation has gained considerable attention due to its feature of being data independent, hence as a practical strategy to fool the radio signal classification with a high success rate. Therefore, in this paper, we investigate a defense system called neural rejection system to propose against universal adversarial perturbations, and evaluate its performance by generating white-box universal adversarial perturbations. We show that the proposed neural rejection system is able to defend universal adversarial perturbations with significantly higher accuracy than the undefended deep neural network.