FA-GAN: Defense Against Adversarial Attacks in Automatic Modulation Recognition
Shilong Zhang, Yu Song, Shubin Wang
Abstract
Deep neural networks (DNNs) offer intelligent solutions for communications’ automatic modulation recognition (AMR) tasks. However, DNNs are vulnerable to adversarial attacks, which can lead to incorrect predictions. To address this critical challenge, this paper proposes a feature-alignment generative adversarial network (FA-GAN) to defend against adversarial attacks targeting DNNs. FA-GAN employs a bidirectional mapping mechanism to iteratively update and learn the feature differences between original and adversarial signals. It quantifies these differences using a self-attention feature alignment (SAFA) encoder, eliminating abnormal perturbations in adversarial signals. Black-box and white-box attack-defense experiments conducted on the publicly available RML2016.10a dataset demonstrate that the proposed FA-GAN not only significantly enhances the model’s defense against adversarial perturbations but also preserves the classifier’s original performance.
BibTeX
@inproceedings{icassp2025_fagandefenseagai,
title = {FA-GAN: Defense Against Adversarial Attacks in Automatic Modulation Recognition},
author = {Shilong Zhang and Yu Song and Shubin Wang},
booktitle = {ICASSP 2025},
year = {2025}
}