Mitigation of Adversarial Examples in RF Deep Classifiers Utilizing AutoEncoder Pre-training

02/16/2019
by   Silvija Kokalj-Filipovic, et al.
0

Adversarial examples in machine learning for images are widely publicized and explored. Illustrations of misclassifications caused by slightly perturbed inputs are abundant and commonly known (e.g., a picture of panda imperceptibly perturbed to fool the classifier into incorrectly labeling it as a gibbon). Similar attacks on deep learning (DL) for radio frequency (RF) signals and their mitigation strategies are scarcely addressed in the published work. Yet, RF adversarial examples (AdExs) with minimal waveform perturbations can cause drastic, targeted misclassification results, particularly against spectrum sensing/survey applications (e.g. BPSK is mistaken for 8-PSK). Our research on deep learning AdExs and proposed defense mechanisms are RF-centric, and incorporate physical world, over-the-air (OTA) effects. We herein present defense mechanisms based on pre-training the target classifier using an autoencoder. Our results validate this approach as a viable mitigation method to subvert adversarial attacks against deep learning-based communications and radar sensing systems.

READ FULL TEXT
research
02/16/2019

Adversarial Examples in RF Deep Learning: Detection of the Attack and its Physical Robustness

While research on adversarial examples in machine learning for images ha...
research
03/28/2018

The Effects of JPEG and JPEG2000 Compression on Attacks using Adversarial Examples

Adversarial examples are known to have a negative effect on the performa...
research
10/24/2020

ATRO: Adversarial Training with a Rejection Option

This paper proposes a classification framework with a rejection option t...
research
11/26/2018

Learning Robust Representations for Automatic Target Recognition

Radio frequency (RF) sensors are used alongside other sensing modalities...
research
06/03/2021

A Little Robustness Goes a Long Way: Leveraging Universal Features for Targeted Transfer Attacks

Adversarial examples for neural network image classifiers are known to b...
research
04/25/2021

Scalable End-to-End RF Classification: A Case Study on Undersized Dataset Regularization by Convolutional-MST

Unlike areas such as computer vision and speech recognition where convol...
research
10/28/2021

Enhancing RF Sensing with Deep Learning: A Layered Approach

In recent years, radio frequency (RF) sensing has gained increasing popu...

Please sign up or login with your details

Forgot password? Click here to reset