AIセキュリティポータル K Program
Adversarial Robustness of Distilled and Pruned Deep Learning-based Wireless Classifiers
Share
Abstract
Data-driven deep learning (DL) techniques developed for automatic modulation classification (AMC) of wireless signals are vulnerable to adversarial attacks. This poses a severe security threat to the DL-based wireless systems, specifically for edge applications of AMC. In this work, we address the joint problem of developing optimized DL models that are also robust against adversarial attacks. This enables efficient and reliable deployment of DL-based AMC on edge devices. We first propose two optimized models using knowledge distillation and network pruning, followed by a computationally efficient adversarial training process to improve the robustness. Experimental results on five white-box attacks show that the proposed optimized and adversarially trained models can achieve better robustness than the standard (unoptimized) model. The two optimized models also achieve higher accuracy on clean (unattacked) samples, which is essential for the reliability of DL-based solutions at edge applications.
A survey of deep learning: Platforms, applications and emerging research trends
W. G. Hatcher, W. Yu
Published: 2018
Radio machine learning dataset generation with GNU Radio
T. O’Shea, N. West
Published: 2016
Deep architectures for modulation recognition
N. E. West, T. O’shea
Published: 2017
Sensing and classification using massive MIMO: A tensor decomposition-based approach
B. R. Manoj, G. Tian, S. Gunnarsson, F. Tufvesson, E. G. Larsson
Published: 2021
Deep learning power allocation in massive MIMO
L. Sanguinetti, A. Zappone, M. Debbah
Published: 2018
Integrating sensing and communications for ubiquitous IoT: Applications, trends, and challenges
Y. Cui, F. Liu, X. Jing, J. Mu
Published: 2021
Threat is in the air: Machine learning for wireless network applications
L. Pajola, L. Pasa, M. Conti
Published: 2019
Adversarial examples: Attacks and defenses for deep learning
X. Yuan, P. He, Q. Zhu, X. Li
Published: 2019
Adversarial attacks on deep-learning based radio signal classification
M. Sadeghi, E. G. Larsson
Published: 2018
Survey of automatic modulation classification techniques: Classical approaches and new trends
O. A. Dobre, A. Abdi, Y. Bar-Ness, W. Su
Published: 2007
Automatic modulation classification using CNN-LSTM based dual-stream structure
Z. Zhang
Published: 2020
Mcformer: A transformer based deep neural network for automatic modulation classification
S. Hamidi-Rad, S. Jain
Published: 2021
Robust adversarial attacks against DNN-based wireless communication systems
A. Bahramali, M. Nasr, A. Houmansadr, D. Goeckel, D. Towsley
Published: 2021
Toward robust networks against adversarial attacks for radio signal modulation classification
B. R. Manoj, P. M. Santos, M. Sadeghi, E. G. Larsson
Published: 2022
GAN against adversarial attacks in radio signal classification
Z. Wang, W. Liu, H.-M. Wang
Published: 2022
Boosting Adversarial Attacks with Momentum
Yinpeng Dong, Fangzhou Liao, Tianyu Pang, Hang Su, Jun Zhu, Xiaolin Hu, Jianguo Li
Published: 10.17.2017
Distilling the knowledge in a neural network
G. Hinton, O. Vinyals, J. Dean
Published: 2015
Knowledge distillation: A good teacher is patient and consistent
L. Beyer
Published: 2022
Net-trim: Convex pruning of deep neural networks with performance guarantee
A. Aghasi
Published: 2017
Share