Adversarial Robustness of Bottleneck Injected Deep Neural Networks for Task-Oriented Communication

Fuente: arXiv
Saved in:
Bibliographic Details
Main Authors: Furutanpey, Alireza, Frangoudis, Pantelis A., Szabo, Patrik, Dustdar, Schahram
Format: Preprint
Published: 2024
Subjects:
Online Access:
Tags: Add Tag
No Tags, Be the first to tag this record!
_version_ 1866929629044932608
author Furutanpey, Alireza
Frangoudis, Pantelis A.
Szabo, Patrik
Dustdar, Schahram
author_facet Furutanpey, Alireza
Frangoudis, Pantelis A.
Szabo, Patrik
Dustdar, Schahram
contents This paper investigates the adversarial robustness of Deep Neural Networks (DNNs) using Information Bottleneck (IB) objectives for task-oriented communication systems. We empirically demonstrate that while IB-based approaches provide baseline resilience against attacks targeting downstream tasks, the reliance on generative models for task-oriented communication introduces new vulnerabilities. Through extensive experiments on several datasets, we analyze how bottleneck depth and task complexity influence adversarial robustness. Our key findings show that Shallow Variational Bottleneck Injection (SVBI) provides less adversarial robustness compared to Deep Variational Information Bottleneck (DVIB) approaches, with the gap widening for more complex tasks. Additionally, we reveal that IB-based objectives exhibit stronger robustness against attacks focusing on salient pixels with high intensity compared to those perturbing many pixels with lower intensity. Lastly, we demonstrate that task-oriented communication systems that rely on generative models to extract and recover salient information have an increased attack surface. The results highlight important security considerations for next-generation communication systems that leverage neural networks for goal-oriented compression.
format Preprint
id arxiv_https___arxiv_org_abs_2412_10265
institution arXiv
publishDate 2024
record_format arxiv
spellingShingle Adversarial Robustness of Bottleneck Injected Deep Neural Networks for Task-Oriented Communication
Furutanpey, Alireza
Frangoudis, Pantelis A.
Szabo, Patrik
Dustdar, Schahram
Machine Learning
Distributed, Parallel, and Cluster Computing
Networking and Internet Architecture
Image and Video Processing
This paper investigates the adversarial robustness of Deep Neural Networks (DNNs) using Information Bottleneck (IB) objectives for task-oriented communication systems. We empirically demonstrate that while IB-based approaches provide baseline resilience against attacks targeting downstream tasks, the reliance on generative models for task-oriented communication introduces new vulnerabilities. Through extensive experiments on several datasets, we analyze how bottleneck depth and task complexity influence adversarial robustness. Our key findings show that Shallow Variational Bottleneck Injection (SVBI) provides less adversarial robustness compared to Deep Variational Information Bottleneck (DVIB) approaches, with the gap widening for more complex tasks. Additionally, we reveal that IB-based objectives exhibit stronger robustness against attacks focusing on salient pixels with high intensity compared to those perturbing many pixels with lower intensity. Lastly, we demonstrate that task-oriented communication systems that rely on generative models to extract and recover salient information have an increased attack surface. The results highlight important security considerations for next-generation communication systems that leverage neural networks for goal-oriented compression.
title Adversarial Robustness of Bottleneck Injected Deep Neural Networks for Task-Oriented Communication
topic Machine Learning
Distributed, Parallel, and Cluster Computing
Networking and Internet Architecture
Image and Video Processing
url https://arxiv.org/abs/2412.10265