conference-paper

Fading-Invariant Adversarial Attacks on Neural Modulation Recognition

Research footprint

At a glance

Citations
2
References
18
Comments
0
Paper overview

Abstract

Despite significant advances in Deep Neural Networks (DNNs) for Neural Modulation Recognition (NMR) in wireless communications, recent research highlights their vulnerability to adversarial attacks. However, in practical wireless communication scenarios, adversarial signals transmitted by attackers are subject to channel effects, resulting in random fading at the receiver, which diminishes attack effectiveness. To address this challenge, we propose a novel Fading-Invariant Method (FIM) for adversarial attacks on NMR under wireless channel effects. FIM leverages a Neural Inverse Model (NIM) to counteract the random transformations introduced by channel effects, ensuring that the received adversarial signals closely resemble the originally crafted waveform. Additionally, we devise a Transmit Power Estimation (TPE) method to appropriately amplify the transmitted perturbation power, mitigating the fading effect while maintaining the imperceptibility of received adversarial signals. Extensive experiments demonstrate that our method outperforms all baselines in attacking state-of-the-art NMR models under channel effects.

Record transparency

Publication details

DOI
10.1109/icassp49660.2025.10890846
OpenAlex
W4408345833
Document type
conference-paper
Language
EN
Last metadata update
Community

Comments

Log in to join the discussion.

  1. No comments yet. Start the discussion.