Fading-Invariant Adversarial Attacks on Neural Modulation Recognition
Xinze Zhang, Dengao Zhu, Xiyao Dong, Kun He
Abstract
Despite significant advances in Deep Neural Networks (DNNs) for Neural Modulation Recognition (NMR) in wireless communications, recent research highlights their vulnerability to adversarial attacks. However, in practical wireless communication scenarios, adversarial signals transmitted by attackers are subject to channel effects, resulting in random fading at the receiver, which diminishes attack effectiveness. To address this challenge, we propose a novel Fading-Invariant Method (FIM) for adversarial attacks on NMR under wireless channel effects. FIM leverages a Neural Inverse Model (NIM) to counteract the random transformations introduced by channel effects, ensuring that the received adversarial signals closely resemble the originally crafted waveform. Additionally, we devise a Transmit Power Estimation (TPE) method to appropriately amplify the transmitted perturbation power, mitigating the fading effect while maintaining the imperceptibility of received adversarial signals. Extensive experiments demonstrate that our method outperforms all baselines in attacking state-of-the-art NMR models under channel effects.
BibTeX
@inproceedings{icassp2025_fadinginvarianta,
title = {Fading-Invariant Adversarial Attacks on Neural Modulation Recognition},
author = {Xinze Zhang and Dengao Zhu and Xiyao Dong and Kun He},
booktitle = {ICASSP 2025},
year = {2025}
}