Signal Adversarial Examples Generation for Signal Detection Network via White-Box Attack

Fuente: arXiv
Saved in:
Bibliographic Details
Main Authors: Li, Dongyang, Wang, Linyuan, Xiong, Guangwei, Yan, Bin, Ma, Dekui, Peng, Jinxian
Format: Preprint
Published: 2024
Subjects:
Online Access:
Tags: Add Tag
No Tags, Be the first to tag this record!
_version_ 1866929524209352704
author Li, Dongyang
Wang, Linyuan
Xiong, Guangwei
Yan, Bin
Ma, Dekui
Peng, Jinxian
author_facet Li, Dongyang
Wang, Linyuan
Xiong, Guangwei
Yan, Bin
Ma, Dekui
Peng, Jinxian
contents With the development and application of deep learning in signal detection tasks, the vulnerability of neural networks to adversarial attacks has also become a security threat to signal detection networks. This paper defines a signal adversarial examples generation model for signal detection network from the perspective of adding perturbations to the signal. The model uses the inequality relationship of L2-norm between time domain and time-frequency domain to constrain the energy of signal perturbations. Building upon this model, we propose a method for generating signal adversarial examples utilizing gradient-based attacks and Short-Time Fourier Transform. The experimental results show that under the constraint of signal perturbation energy ratio less than 3%, our adversarial attack resulted in a 28.1% reduction in the mean Average Precision (mAP), a 24.7% reduction in recall, and a 30.4% reduction in precision of the signal detection network. Compared to random noise perturbation of equivalent intensity, our adversarial attack demonstrates a significant attack effect.
format Preprint
id arxiv_https___arxiv_org_abs_2410_01393
institution arXiv
publishDate 2024
record_format arxiv
spellingShingle Signal Adversarial Examples Generation for Signal Detection Network via White-Box Attack
Li, Dongyang
Wang, Linyuan
Xiong, Guangwei
Yan, Bin
Ma, Dekui
Peng, Jinxian
Computer Vision and Pattern Recognition
Cryptography and Security
With the development and application of deep learning in signal detection tasks, the vulnerability of neural networks to adversarial attacks has also become a security threat to signal detection networks. This paper defines a signal adversarial examples generation model for signal detection network from the perspective of adding perturbations to the signal. The model uses the inequality relationship of L2-norm between time domain and time-frequency domain to constrain the energy of signal perturbations. Building upon this model, we propose a method for generating signal adversarial examples utilizing gradient-based attacks and Short-Time Fourier Transform. The experimental results show that under the constraint of signal perturbation energy ratio less than 3%, our adversarial attack resulted in a 28.1% reduction in the mean Average Precision (mAP), a 24.7% reduction in recall, and a 30.4% reduction in precision of the signal detection network. Compared to random noise perturbation of equivalent intensity, our adversarial attack demonstrates a significant attack effect.
title Signal Adversarial Examples Generation for Signal Detection Network via White-Box Attack
topic Computer Vision and Pattern Recognition
Cryptography and Security
url https://arxiv.org/abs/2410.01393