2019/02/16 by Silvija Kokalj-Filipović, Kokalj-Filipovic, Silvija, Robert F. Miller +5 · 2 citations
Computer Science · Engineering · #Advanced SAR Imaging Techniques #Adversarial Robustness in Machine Learning #FOS: Computer and information sciences #FOS: Electrical engineering #Machine Learning (cs.LG) #Machine Learning (stat.ML) #Signal Processing (eess.SP) #Wireless Signal Modulation Classification #electronic engineering #information engineering
paper · pdf · doi:10.48550/arxiv.1902.08034
openalex publication_date 2019/02/16 · openalex created_date 2022/07/29 · openalex updated_date 2026/07/28
Adversarial examples in machine learning for images are widely publicized and\nexplored. Illustrations of misclassifications caused by slightly perturbed\ninputs are abundant and commonly known (e.g., a picture of panda imperceptibly\nperturbed to fool the classifier into incorrectly labeling it as a gibbon).\nSimilar attacks on deep learning (DL) for radio frequency (RF) signals and\ntheir mitigation strategies are scarcely addressed in the published work. Yet,\nRF adversarial examples (AdExs) with minimal waveform perturbations can cause\ndrastic, targeted misclassification results, particularly against spectrum\nsensing/survey applications (e.g. BPSK is mistaken for 8-PSK). Our research on\ndeep learning AdExs and proposed defense mechanisms are RF-centric, and\nincorporate physical world, over-the-air (OTA) effects. We herein present\ndefense mechanisms based on pre-training the target classifier using an\nautoencoder. Our results validate this approach as a viable mitigation method\nto subvert adversarial attacks against deep learning-based communications and\nradar sensing systems.\n